uao-wswhatsapp[.]cc
“whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具”
uao-wswhatsapp.cc — Inhalt nicht verfügbar (HTTP 502). Markenidentität: Google; Betrugstyp: Social Media Phishing. Zusammenfassung der Beweislage: VirusTotal 16/95 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrar: Dominet (HK).
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
On July 23, 2026, the domain uao-wswhatsapp.cc was observed as an offline infrastructure used to impersonate Google in a social‑media phishing campaign. The site was registered on 02 Oct 2025 through Dominet (HK) Limited and resolves to the IPv4 address 103.80.133.70, which belongs to AS205960 operated by HDTIDC LIMITED in South Korea. Four authoritative name servers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname) are configured, but the site lacks an SSL/TLS certificate, indicating that any traffic would be transmitted unencrypted. The page title returned by the server is "whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具", a Chinese phrase unrelated to Google, suggesting that the content has not yet been publicly analyzed.
Gridinsoft assigned a trust score of 0 / 100, and the domain is listed on at least one public blocklist and has been blocked by PhishDestroy. Threat intelligence aggregation services have recorded the domain in 16 AlienVault OTX pulses, and VirusTotal reports 16 of 95 scanning engines flagging the domain as malicious. The combination of a newly created domain, low‑reputation hosting, absence of TLS, and multiple detections points to a high likelihood of credential‑harvesting activity targeting Google users via a purported WhatsApp login interface. However, the exact payload, phishing kit, or compromised accounts remain unknown because the site is offline and no forensic capture of the landing page is available.
Defenders should add uao-wswhatsapp.cc to URL filtering and endpoint allow‑list exclusion rules, monitor DNS queries for the four associated name servers, and enforce strict TLS inspection for outbound traffic to the IP 103.80.133.70. Incident response teams should also correlate any recent Google authentication failures with requests to this domain and consider user‑education campaigns that clarify the mismatch between the Chinese page title and the alleged Google impersonation.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt