web-whatsapp[.]co
“TK Store | buy, sell and discover on TK”
Zusammenfassung der Beweislage
This domain, web-whatsapp.co, is flagged as a high-risk phishing infrastructure designed to impersonate WhatsApp Web, a widely used messaging platform. Analysis indicates the domain was likely engineered to harvest user credentials through fraudulent login portals, mimicking the legitimate WhatsApp Web interface. The page title, 'TK Store | buy, sell and discover on TK,' suggests an attempt to disguise the malicious intent under a generic e-commerce facade, though the primary objective remains credential theft. No specific drainer kit signatures were identified in the available intelligence, but the domain aligns with known phishing tactics targeting communication platforms. Infrastructure analysis reveals the domain was registered on August 10, 2025, through GoDaddy.com, LLC, and resolves to the IP address 45.135.237.33, hosted under AS153656 (OWGELS INTERNATIONAL CO., LIMITED) in Hong Kong. Google Safe Browsing explicitly flags this domain as phishing, while VirusTotal reports 19 out of 95 security vendors detecting it as malicious. The domain appears on two security blocklists, including PhishDestroy and PhishingDB. The SSL certificate, issued by Let's Encrypt (serial number E8), provides minimal assurance, as phishing domains frequently leverage free certificates to appear legitimate. As of the latest assessment, web-whatsapp.co has been taken offline, likely due to suspension by the registrar or hosting provider following abuse reports. However, the residual risk remains elevated due to the domain's recent creation and the potential for threat actors to re-establish infrastructure under similar naming conventions. Organizations and users are advised to block the domain and its associated IP (45.135.237.33) at the network level, monitor for credential leakage, and validate any WhatsApp Web sessions against the official domain (web.whatsapp.com). Proactive hunting for related domains using the seed '8d4780' in threat intelligence feeds may uncover additional malicious infrastructure.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
VirusTotal
19 → 18
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
-
VirusTotal
18 → 22
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of web-whatsapp.co · checked Mar 1, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt