e-b-whatsapp[.]com[.]cn
“WhatsApp 网页版”
e-b-whatsapp.com.cn — Nicht bestätigt. Betrugstyp: Social Media Phishing. Zusammenfassung der Beweislage: VirusTotal 16/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, ESET); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. Registrar: 厦门三五互联信息有限公司.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain e-b-whatsapp.com.cn is classified as a generic phishing infrastructure impersonating WhatsApp Web services, currently associated with credential harvesting attempts targeting messaging platform users. Although the domain is now offline, it previously hosted a fake login interface mimicking WhatsApp 网页版 to deceive end users into submitting sensitive authentication data.
Technical analysis shows the domain was created on February 21, 2026 and registered through 厦门三五互联信息有限公司. It resolved to IP 154.221.8.150 hosted in Hong Kong under AS137951 (ASLINE LIMITED). The domain has no SSL certificate deployed, increasing interception risk during active operation. It appears on 1 security blocklist and is flagged by 23 out of 95 VirusTotal security vendors, indicating a strong multi-engine consensus of malicious behavior. The page title recorded as WhatsApp 网页版 confirms explicit brand impersonation designed to increase user trust and engagement.
At present, the domain is taken offline, reducing immediate exposure risk. However, historical infrastructure and detection signals indicate it was actively used for phishing campaigns prior to shutdown. The absence of SSL, combined with high VirusTotal detection volume and brand impersonation tactics, suggests a high-confidence malicious classification. Recommended actions include maintaining DNS-level blocking, preserving forensic indicators for threat intelligence correlation, and monitoring for infrastructure reuse under similar naming patterns. Users previously exposed to the domain should be advised to change credentials and enable multi-factor authentication to mitigate potential compromise.
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | e-b-whatsapp.com.cn |
phishing | Phishing Block |
| Cloudflare DNS | e-b-whatsapp.com.cn |
malicious | Sinkholed |
| Hagezi Threat Feed | e-b-whatsapp.com.cn |
malicious | Sinkholed |
| DNS4EU | e-b-whatsapp.com.cn |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Technologien · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt