wswhts[.]one
“WhatsApp”
ملخص الأدلة
This domain, wswhts.one, was registered on 21 February 2026 and is currently offline. Passive DNS shows it resolves to the IPv4 address 192.163.167.170, which belongs to an Antbox Networks Limited network (AS138995) hosted in Hong Kong. The server presents an SSL certificate identified as R13, indicating a low‑trust rating. The only visible HTML element retrieved before takedown was a page title of “WhatsApp”, suggesting a possible attempt to lure users familiar with the messaging service. Threat intelligence categorises the site as a brand‑impersonation campaign targeting the financial services brand Argent.
The campaign’s primary vector appears to be a malicious domain that mimics a legitimate service to harvest credentials or redirect victims, consistent with the “Brand Impersonation” label. Reputation checks show the domain appears on a single public blocklist, PhishDestroy, which has already flagged it as malicious. VirusTotal analysis recorded nine detections out of ninety‑five scanners, confirming that multiple security vendors consider the host suspicious. No additional public blocklists or safe‑browsing services have reported the domain, and no open‑source threat‑intel feeds (OTX, etc.) currently reference it, leaving the broader visibility of the infrastructure uncertain.
Given the limited exposure, defenders should prioritize adding the domain to local deny‑list rules and monitoring outbound DNS queries for the resolved IP address 192.163.167.170. Correlation of network traffic against the Antbox Networks ASN may reveal related campaigns or shared infrastructure. Continuous re‑evaluation of the domain’s status on VirusTotal and other scanning services is advised, as additional detections could emerge. Organizations that use Argent services should educate users about unsolicited requests referencing WhatsApp or similar messaging platforms, and enforce multi‑factor authentication to reduce the impact of potential credential compromise.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | wswhts.one |
phishing | Phishing Block |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب