worldllibertyfinance[.]xyz
worldllibertyfinance.xyz — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 7/93 (ChainPatrol, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 71/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain worldllibertyfinance.xyz was registered on February 21, 2026 and currently resolves to the IP address 172.67.150.13. This address belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The site presented a page titled “Just a moment…” and served an SSL certificate labeled WE1. VirusTotal analysis recorded seven positive detections out of ninety‑three scanners, indicating that multiple security engines have flagged the domain as malicious.
The domain is listed on a single public blocklist, PhishDestroy, which also confirms that the site is presently taken offline. The recorded threat type is generic phishing and the risk level has been assigned as elevated based on the observed indicators. Defenders should add worldllibertyfinance.xyz to URL filtering and web‑gateway blocklists, and consider blocking traffic to the associated Cloudflare IP range after a risk assessment, acknowledging that shared hosting may host unrelated benign services.
Continuous re‑scanning on aggregators such as VirusTotal is advised to capture any changes in detection counts. Email security solutions should treat any messages containing links to this domain as malicious and quarantine them. Although the site is offline, the infrastructure could be reactivated, so threat‑intel feeds should be updated with the observed indicators of compromise and monitored for future activity.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。