hyper-lend[.]fi
hyper-lend.fi 网络钓鱼与安全检查
“HyperLend - Decentralized Lending & Borrowing | HyperEVM DeFi Protocol”
hyper-lend.fi — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Crypto Scam. 证据摘要: VT 2/93 (Gridinsoft, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_SPAM; BL 2 (MetaMask, SEAL); PD 81/100. 注册商: Immaterialism.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed hyper-lend.fi on Feb 4, 2026. Positive findings were recorded by VirusTotal, MetaMask, SEAL, and Spamhaus DBL. Evidence score: 81/100.
VirusTotal recorded 2 detections among 93 engines: Gridinsoft, SOCRadar on Jul 10, 2026 at 14:59 UTC. The external blocklist snapshot contained 2 matches (MetaMask, SEAL) on Aug 7, 2026 at 10:20 UTC. Spamhaus DBL: DBL_SPAM on Jul 14, 2026 at 10:36 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 2, 2026 at 20:35 UTC. URLScan completed without a malicious verdict (score 0) on Feb 4, 2026 at 11:38 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 10:15 UTC. Registration records list Immaterialism Ltd as the registrar. At collection time, the domain resolved to 104.21.0.218. Captured page title: “HyperLend - Decentralized Lending & Borrowing | HyperEVM DeFi Protocol”. PhishDestroy classified the observed content as Crypto Scam. DOM analysis completed on Apr 23, 2026 at 07:20 UTC; stored DOM score 0/100. IoC extraction completed on Jul 29, 2026 at 02:37 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis2026年7月22日
Analysis of hyper-lend.fi, registered on 21 February 2026 through Immaterialism Ltd, shows it is currently active and serves HTTP 200 responses over Cloudflare’s network (ASN 13335) from IP 104.21.0.218 located in the United States. The site uses a Let’s Encrypt certificate (E8) and supports HTTP/3, indicating a modern web stack but also the typical obfuscation layer provided by Cloudflare. The page title advertised as “HyperLend – Decentralized Lending & Borrowing | HyperEVM DeFi Protocol” aligns with the classified threat type of a crypto scam.
Infrastructure checks reveal the domain appears on three independent security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal scans report that two out of ninety‑three AV engines flag the domain, and Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. Nameservers aida.ns.cloudflare.com and damien.ns.cloudflare.com confirm Cloudflare DNS usage, a common choice for abuse‑hosting operators.
While the HTTP status code of 200 suggests the site is reachable, no additional content analysis is available, leaving the exact phishing mechanics unverified. Defenders should treat hyper‑lend.fi as high‑risk, enforce network‑level blocking, monitor DNS resolutions for the listed IP and nameservers, and consider adding the domain to internal blocklists. Continuous re‑scanning with multi‑engine services is advised to capture any evolving payloads or credential‑stealing components.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of hyper-lend.fi · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。