# wechath5-nonprod.westernunion.cloud — MALICIOUS > Beware of phishing threats from wechath5-nonprod.westernunion.cloud. Act now to protect your data from this active scam domain. ## Summary PhishDestroy identifies wechath5-nonprod.westernunion.cloud as a high-risk phishing domain actively targeting users. The threat type is generic phishing, aiming to steal sensitive information by impersonating trusted services. The domain was created recently on February 21, 2026, and remains active. It is flagged by 12 out of 95 security vendors on VirusTotal and appears on at least one security blocklist, confirming its malicious intent. The domain's name mimics legitimate services, increasing the likelihood of successful deception. Users and organizations should exercise caution and avoid interacting with this domain. Mitigation includes blocking the domain on network firewalls, educating users about phishing tactics, and monitoring for related suspicious activity. PhishDestroy continues to track this domain’s status to provide timely alerts. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 200) - Page title: Western Union ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: DNSPod, Inc. - Nameservers: ["hugh.dnspod.net", "dolores.dnspod.net"] ## Detection Status - VirusTotal: 12 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "BitDefender", "CRDF", "CyRadar", "ESET", "Fortinet", "G-Data", "Gridinsoft", "MalwareURL", "SOCRadar", "VIPRE"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Live Page Content ### Page Text Western Union Wechat western union application ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/4487acd8-0bc7-4fe9-b786-87eeb769b8e5 - PhishDestroy: https://phishdestroy.io/domain/wechath5-nonprod.westernunion.cloud/ ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/wechath5-nonprod.westernunion.cloud/ Last updated: 2026-03-14