webfresh[.]wheelnwater[.]com
“webfresh – Just another WordPress site”
Zusammenfassung der Beweislage
The domain webfresh.wheelnwater.com was identified as a brand‑impersonation infrastructure targeting Facebook users. The site is hosted on the IPv4 address 185.146.22.243, which belongs to ASN 55293 (A2 Hosting, Inc.) and is geolocated in the Netherlands. Registration data show the domain was created on 22 November 2019 through the registrar Enartia Single Member S.A., and the authoritative name servers are ns1‑ns4.a2hosting.com. No TLS certificate is presented; the service was reachable via HTTP only, and the current HTTP status is offline as of the report date. A passive web scan retrieved the page title “webfresh – Just another WordPress site”, which does not contain overt branding but confirms the site is powered by a default WordPress installation.
The infrastructure received a Gridinsoft trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal analysis recorded six detections out of ninety‑five scanners, confirming that multiple security engines consider the domain suspicious. The domain appears on a single public blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the classification as a phishing vector. Evidence confirms the campaign’s objective is brand impersonation of Facebook, although the exact payload or credential‑harvesting page has not been captured. The absence of an SSL certificate and the reliance on a generic WordPress title suggest a low‑effort deployment, yet the presence on multiple detection platforms indicates active abuse.
Uncertainty remains regarding the specific phishing page content, any associated malware, and whether the domain has been reused in other campaigns. Defenders should add 185.146.22.243 and webfresh.wheelnwater.com to network‑level deny lists, monitor DNS queries for the domain and its A2 Hosting name servers, and enforce TLS inspection to block any clear‑text HTTP attempts.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Registration: wheelnwater.com
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For the registrable domain wheelnwater.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt