whatap[.]eu[.]cc
“WhatsApp Security Testing Center”
The domain whatap.eu.cc has been assessed as having an elevated risk level due to its involvement in brand impersonation. This specific threat type involves the domain impersonating Fibank, potentially misleading users into sharing sensitive information such as login credentials or financial data.
Infrastructure analysis reveals that whatap.eu.cc was registered through Gname.com Pte. Ltd. and is currently offline. The domain resolves to the IP address 154.12.25.51, which is located in Hong Kong and belongs to the AS401696 cognetcloud INC. It was created on February 21, 2026, and appears on one security blocklist. Additionally, it has been flagged by 22 out of 95 security vendors on VirusTotal, indicating a moderate level of suspicion among the security community. The domain does not have an SSL certificate, which is a common indicator of a lack of legitimate security measures. The page title found is 'WhatsApp Security Testing Center', which further suggests an attempt to deceive users by mimicking a trusted service.
To mitigate the risks associated with brand impersonation, users are advised to exercise caution when interacting with any website or service that claims to be related to Fibank. Verifying the URL and checking for the presence of a valid SSL certificate can help identify fraudulent sites. Organizations should also monitor their brand's online presence and report any suspicious domains to their respective registrars and security authorities. Implementing multi-factor authentication and educating users about phishing tactics can further reduce the likelihood of successful impersonation attacks.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | compx.pw |
phishing | Phishing Block |
| Hagezi Threat Feed | whatap.eu.cc |
malicious | Sinkholed |
| DNS4EU | whatap.eu.cc |
malicious | Sinkholed |
| Cloudflare DNS | whatap.eu.cc |
malicious | Sinkholed |
| OpenDNS | whatap.eu.cc |
phishing | Phishing Block |
Threat Response Pipeline
Public Blocklist Status
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
PD-20260218-1B4C43 Recipient: abuse@cogentco.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive