whats-xwy[.]vip
“whats-xwy.vip”
whats-xwy.vip — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: WhatsApp; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 17/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 100 det.; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Gname.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain whats-xwy.vip was registered on 11 October 2025 through Gname.com Pte. Ltd. and currently resolves to the Microsoft‑owned IP address 20.205.130.221, which is situated in Hong Kong under ASN 8075. No TLS certificate is presented, meaning any traffic to the site would be unencrypted. Its page title is exactly "whats-xwy.vip" and the domain is categorized as a brand‑impersonation campaign targeting WhatsApp. It appears on a single public security blocklist and is specifically listed by PhishDestroy as a malicious entry. Gridinsoft has assigned a trust score of 0 out of 100, indicating extreme suspicion.
VirusTotal analysis records that 17 of 95 scanning engines flag the domain as malicious, reinforcing the blocklist evidence. AlienVault OTX references the domain in sixteen separate threat‑intel pulses, showing that the indicator has been circulated widely among security communities. Authoritative name servers are a.share-dns.com, a12.share-dns.com, b.share-dns.net, and b12.share-dns.net, which are commonly associated with disposable hosting services. Although the domain’s current status is offline, the underlying hosting infrastructure remains reachable. Uncertainties remain because no content snapshot or phishing‑kit details are publicly available, and the absence of SSL prevents verification of any credential‑harvesting mechanisms.
Nonetheless, the combination of blocklist inclusion, low trust score, and multiple vendor detections provides sufficient confidence that the domain was used for malicious impersonation. Defenders should block the domain and its resolving IP address, enforce DNS sinkholing, and monitor for new subdomains that resolve to the same Microsoft IP range. Given the shared DNS infrastructure, related hostnames using the same name servers should be reviewed. Continuous monitoring of threat‑intel feeds such as OTX and vendor‑specific feeds is recommended to capture any emerging activity associated with this indicator.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب