wlfi-eth[.]world
“World Liberty Fi”
wlfi-eth.world — 内容不可用 (HTTP 502). 品牌冒充:LinkedIn; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 14/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 92/100. 注册商: NameCheap.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
wlfi-eth.world is a newly registered domain, created on February 21, 2026, that has been identified as a crypto‑focused phishing operation. The only page title observed by crawlers is "World Liberty Fi", which matches the listed scam type of a crypto scam. DNS resolution points to the address 76.76.21.61, an Amazon Web Services host located in the United States and advertised under ASN 16509 (Amazon.com, Inc.). The hosting environment is reported to use Vercel and to enforce HTTP Strict Transport Security, indicating an attempt to present a legitimate‑looking HTTPS service.
The SSL certificate is recorded as "R12", confirming that TLS was active at the time of observation. Registration was performed through NameCheap, Inc., with authoritative nameservers dns1.registrar-servers.com and dns2.registrar-servers.com. Google Safe Browsing has flagged the domain for social engineering, and PhishDestroy lists it as blocked. The domain also appears on a single external security blocklist, and VirusTotal analysis shows that 14 of 93 scanning engines returned a positive detection, providing multiple independent confirmations of malicious intent.
Although the site has been taken offline, the infrastructure artifacts—IP address, hosting provider, TLS configuration, and registrar details—remain actionable for defenders. Recommended mitigation steps include adding wlfi-eth.world and its resolving IP to deny‑list rules, monitoring for reuse of the same AWS IP range or Vercel deployment patterns, and applying outbound filtering for known crypto‑phishing signatures. Continuous telemetry should be collected on any DNS queries for the domain, and any resurgence attempts should be investigated promptly, as threat actors often recycle similar infrastructure after takedown.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of wlfi-eth.world · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。