web[.]whatsapps[.]hl[.]cn
“WhatsApp Web”
ملخص الأدلة
This domain, web.whatsapps.hl.cn, was identified as a fake WhatsApp Web portal designed to harvest user credentials. The site impersonated the legitimate WhatsApp Web interface, presenting a login page that closely mimicked the official design. Visitors entering their credentials would unknowingly transmit sensitive information directly to threat actors, enabling account takeover, unauthorized access to personal communications, or further social engineering attacks. The domain did not host malware but relied on deception to exploit trust in the WhatsApp brand, a tactic commonly used in credential phishing campaigns targeting both personal and corporate users. Analysis indicates the domain was registered on February 22, 2026, through Alibaba Cloud (China) and resolved to the IP address 168.76.144.217, hosted under AS137951 (ASLINE LIMITED) in Hong Kong. At the time of detection, 25 out of 95 security vendors on VirusTotal flagged the domain as malicious, with the page title explicitly set to 'WhatsApp Web' to reinforce the deception. The SSL certificate was issued by Let's Encrypt (R12), providing a false sense of security to visitors. The domain appeared on one security blocklist and was subsequently taken offline, though similar infrastructure may still be active. If you visited web.whatsapps.hl.cn and entered any credentials, immediate action is required. First, change the password for your WhatsApp account and enable two-step verification in the app settings. Review recent login activity for any unauthorized sessions and log out of all devices if suspicious activity is detected. Monitor linked accounts, such as email or cloud services, for signs of compromise. If financial or sensitive personal data was exposed, consider reporting the incident to relevant authorities or identity protection services. Avoid reusing passwords across platforms and verify the authenticity of any login portal by checking the URL and SSL certificate details before entering credentials.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of web.whatsapps.hl.cn · checked Mar 1, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب