whatsappwa[.]com[.]cn
“WhatsApp网页版- 全功能指南与使用技巧”
whatsappwa.com.cn — Nicht bestätigt. Markenidentität: Google; Betrugstyp: Social Media Phishing. Zusammenfassung der Beweislage: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: 四川域趣网络科技有限公司.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, whatsappwa.com.cn, is flagged for elevated-risk brand impersonation activity targeting Google, despite its misleading page title suggesting affiliation with WhatsApp. Analysis indicates the domain was designed to deceive users into believing they were interacting with legitimate Google services, a tactic commonly employed to harvest credentials or distribute malicious payloads. The discrepancy between the page title (WhatsApp网页版- 全功能指南与使用技巧) and the actual brand target (Google) underscores the deceptive nature of this campaign, which may exploit user trust in both platforms to maximize compromise success rates. Infrastructure analysis reveals the domain was registered through 四川域趣网络科技有限公司, a registrar frequently associated with high-risk domains. It resolves to the IP address 156.252.40.3, hosted under AS9294 (GNET INC.) in Hong Kong, a region often leveraged for bulletproof hosting due to lenient enforcement policies. The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 19 out of 95 security vendors on VirusTotal, with detections including phishing, brand impersonation, and malicious content. Notably, the domain lacks an SSL certificate, a red flag for modern web security standards, further increasing its risk profile. While currently offline, historical data suggests this domain may re-emerge under altered infrastructure or similar naming conventions. Mitigation against brand impersonation threats of this nature requires a multi-layered approach. Organizations should implement domain monitoring to detect newly registered lookalike domains, particularly those mimicking high-value brands like Google. End-users should be trained to scrutinize page titles, URLs, and SSL certificate presence, as these are common indicators of fraudulent sites. Security teams are advised to block the IP address 156.252.40.3 at the network perimeter and update detection rules to include domains registered via 四川域趣网络科技有限公司. Additionally, enforcing strict email filtering policies to quarantine messages containing links to newly registered or untrusted domains can reduce exposure to such campaigns. Given the elevated risk level, affected organizations should conduct retrospective log analysis to identify any prior interactions with this domain or its associated infrastructure.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt