ns2[.]whatscvpp[.]top
“ns2.whatscvpp.top”
A domain analysis of ns2.whatscvpp.top reveals a site that attempts to impersonate the WhatsApp messaging brand through a deceptive domain name. The page title is identical to the domain name, providing no further content. The primary threat is social engineering, as flagged by Google Safe Browsing, which indicates the site is designed to trick users into revealing sensitive information or performing actions that compromise their security.
Technical evidence shows the domain was flagged by 24 out of 95 VirusTotal vendors. Specific detections include ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, and CSIS Security Group. The domain is registered through Gname.com Pte. Ltd. and was created on 2026-03-09. It resolves to IP address 47.82.180.14, hosted in Singapore by AS45102 Alibaba (US) Technology Co., Ltd. No SSL certificate is present. The nameservers are a12.share-dns.com and b12.share-dns.net. The domain is listed on one blocklist.
The site is currently down or offline. Based on the domain risk score of 83, the overall risk level is high. The combination of social engineering flags, multiple security vendor detections, and a recent creation date indicates this domain poses a significant threat, primarily for credential theft or phishing attacks.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Registration: whatscvpp.top
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain whatscvpp.top behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive