whastappa.cn
“whastappa.cn/”
Evidence Summary
This domain, whastappa.cn, poses a significant threat as a brand impersonation site designed to deceive users into believing it is affiliated with Telegram. The site mimics legitimate messaging platforms to harvest sensitive information such as login credentials, personal details, or financial data. Users who interact with the site may unknowingly expose themselves to identity theft, account compromise, or malware distribution. The domain’s design and structure are crafted to exploit trust in the targeted brand, making it particularly dangerous for unsuspecting visitors. Analysis indicates that whastappa.cn is flagged by 23 out of 95 security vendors on VirusTotal, a clear indicator of its malicious nature. The domain was registered on February 21, 2026, through GoDaddy.com, LLC, a registrar commonly used for both legitimate and malicious domains. It resolves to the IPv6 address 2606:4700:20::681a:a0, hosted on infrastructure belonging to Cloudflare, Inc. (AS13335), which is frequently leveraged to obscure the true origin of malicious sites. Additionally, the domain appears on one security blocklist, and its SSL certificate, issued by Let’s Encrypt, does not mitigate the risk, as such certificates are often used to lend a false sense of legitimacy to phishing sites. If you visited whastappa.cn or interacted with its content, immediate action is required to mitigate potential risks. First, cease all interaction with the site and avoid entering any personal or financial information. If credentials were entered, change passwords for the affected accounts and any other platforms where the same credentials may have been reused. Enable multi-factor authentication where available to add an additional layer of security. Monitor accounts for unusual activity, such as unauthorized logins or transactions, and report any suspicious behavior to the relevant platform. Additionally, consider running a scan on your device to detect and remove any potential malware that may have been downloaded. Users should also report the domain to their security software provider to aid in broader threat mitigation efforts.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www.whastappa.cn |
malicious | Sinkholed |
| OpenDNS | www.whastappa.cn |
phishing | Phishing Block |
| DNS4EU | www.whastappa.cn |
malicious | Sinkholed |
| Cloudflare DNS | www.whastappa.cn |
malicious | Sinkholed |
| DigiCert UltraDNS | www.whastappa.cn |
malicious | Sinkholed |
| DigiCert UltraDNS | whastappa.cn |
malicious | Sinkholed |
| Cloudflare DNS | whastappa.cn |
malicious | Sinkholed |
| OpenDNS | whastappa.cn |
phishing | Phishing Block |
| DNS4EU | whastappa.cn |
malicious | Sinkholed |
| Hagezi Threat Feed | whastappa.cn |
malicious | Sinkholed |
Detection timeline
Threat Response Pipeline
Public Blocklist Status
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260214-582789- Captured page title
- whastappa.cn/
Blocklist coverage
11 monitored external feeds · stored snapshot Sep 10, 2026
Technologies · 6 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of whastappa.cn · checked Apr 23, 2026
Technologies
6 high-confidence technologies identified
Evidence & External Reports
PD-20260214-582789 Recipient: maj86030@gmail.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive