worldlibertefinancial[.]com
worldlibertefinancial.com — 内容不可用 (HTTP 502). 品牌冒充:LinkedIn; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/93 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 92/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of worldlibertefinancial.com shows that the domain was registered on February 21, 2026 and is presently taken offline. The sole resolved address is 46.30.44.7, which belongs to the NL‑based AS216139 operated by Iron Hosting Centre LTD. The infrastructure is associated with a known crypto‑scam campaign that impersonates LinkedIn, as indicated by the brand target field. VirusTotal has recorded 14 positive detections out of 93 scanned security vendors, confirming malicious classification across multiple engines. The domain is listed on four independent blocklists, including PhishDestroy, Polkadot, Enkrypt and Codeesura, reinforcing the consensus that it is being used for fraudulent activity.
The TLS certificate carries an R13 rating, which is typically considered low trust. While the exact page content has not been captured, the combined evidence—registration date, hosting ASN, detection count, blocklist presence, SSL rating and brand impersonation—strongly suggests a high‑risk crypto‑scam operation. The presence on multiple blocklists indicates that the domain has been observed by distinct anti‑phishing communities, reducing the likelihood of a false positive. Iron Hosting Centre LTD has been previously linked to other financial fraud operations, though no additional domains from the same ASN appear in the current dataset.
Uncertainty remains regarding any residual infrastructure that may be re‑activated if the domain is re‑registered. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for re‑use of the IP address 46.30.44.7, and consider adding the associated ASN to threat‑intel feeds. Any future queries to the domain should be denied, and security teams should update detection signatures to include the R13 certificate fingerprint and observed host‑header patterns once they become available. Security operations should also audit internal logs for prior connections to 46.30.44.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。