Analysis of the domain msg-whatapp.hk.cn indicates that it is actively being used for a high‑risk generic phishing campaign. The domain was registered on July 28, 2026 by 万商云集(成都)科技股份有限公司 and is currently resolved to the IPv4 address 192.197.113.111. Infrastructure inspection shows the domain is served from nameservers ns1.kenpains.com and ns2.kenpains.com, both of which are associated with the same hosting provider that supplies the address 192.197.113.111. The domain appears on a single security blocklist and has been flagged by the PhishDestroy mitigation service, confirming that defensive controls have already identified it as malicious.
VirusTotal scans report that four of ninety‑one security vendors have flagged the domain, providing independent confirmation of its malicious nature. No public page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts are available in the current intelligence set, leaving the exact content of the hosted page unknown. Defenders should prioritize immediate blocking of both the domain and its resolved IP address at network perimeter devices, DNS resolvers, and endpoint protection solutions. Continuous monitoring of the associated nameservers and the hosting provider is recommended to detect any additional domains that may be provisioned using the same infrastructure.
Because the registrar is a Chinese‑based entity, threat‑intel teams should also consider cross‑checking other domains registered by the same organization for similar patterns. Organizations that rely on email or messaging services should educate users about unsolicited messages that reference unfamiliar URLs, especially those that incorporate terms resembling popular communication apps, as attackers may attempt to leverage the domain name to increase credibility. Regular updates to URL filtering lists and periodic re‑scans of the IP address are advised to capture any changes in the threat posture.