wetransfer0[.]uk
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
PhishDestroy identifies wetransfer0.uk as an elevated-risk domain engaged in brand impersonation phishing, specifically targeting users of the legitimate file-sharing service WeTransfer. The domain exploits the trusted WeTransfer name to trick visitors into entering credentials or downloading malicious content, posing a direct threat to personal and corporate data security.
This domain was flagged by 20 out of 95 security vendors on VirusTotal, indicating widespread detection across the security community. It is currently active and appears on at least one security blocklist. The domain was created on April 9, 2026, which is suspiciously recent, and is registered through Cloudflare, Inc., a common registrar for both legitimate and malicious sites. The domain resolves to IP address 35.157.26.135, and its SSL certificate is issued by Let's Encrypt (E8), which is frequently abused by phishing operations. Cloudflare itself has flagged the site, displaying a warning page titled "Suspected phishing site | Cloudflare." These combined indicators strongly confirm the domain's malicious intent.
To protect against this specific brand impersonation phishing threat, users should never enter any personal information, passwords, or payment details on wetransfer0.uk. Avoid clicking any links or downloading files from the site. If you have already interacted with the domain, change passwords for any accounts that may have been compromised and monitor for suspicious activity. Report the domain to your email provider or security team. Always verify URLs by checking for subtle misspellings or unusual domain extensions like .uk instead of the official .com. Implement web filtering to block this domain and similar impersonation attempts. PhishDestroy recommends treating all unsolicited file transfer requests with caution and directly navigating to the official WeTransfer website when needed.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | wetransfer0.uk/ |
malware | Detects file containing Telegram Bot API |
| DigiCert UltraDNS | wetransfer0.uk |
malicious | Sinkholed |
| Cloudflare DNS | wetransfer0.uk |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | wetransfer0.uk |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of wetransfer0.uk · checked Apr 9, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب