chat.ring-whatapp.com.cn was registered on July 28, 2026 through the Chinese registrar 成都垦派科技有限公司. The domain is delegated to the authoritative name servers ns1.kenpains.com and ns2.kenpains.com, both of which are associated with the same registrar. DNS resolution returns the IPv4 address 192.197.113.111, indicating a single‑host deployment that is currently reachable on the public Internet. The domain appears on one security blocklist and is actively listed by the PhishDestroy mitigation service, confirming that it is being treated as malicious by at least one reputable anti‑phishing organization.
VirusTotal analysis shows that 13 of 91 scanned security vendors have flagged the domain, providing independent corroboration of its suspicious nature. No additional public reputation scores, Safe Browsing verdicts, or Open Threat Exchange (OTX) entries were supplied in the available intelligence. The rapid creation date, combined with the lack of a long‑standing presence and the presence of multiple detections, suggests the domain was purpose‑built for a phishing campaign launched shortly after registration. Because the site’s content, SSL certificate details, HTTP response codes, and page title have not been disclosed, the exact lure and credential‑capture mechanism remain unknown.
Defenders should block traffic to the domain at the network perimeter, add the IP address 192.197.113.111 to blacklists, and ensure that any email filtering rules flag messages containing the domain or its sub‑domains. Continuous monitoring of the associated name servers and periodic re‑scans with VirusTotal or similar services are advised to capture any changes in detection coverage. Organizations should also consider sharing the indicator set with information‑sharing platforms to improve community‑wide detection of this high‑risk phishing infrastructure.