whats-xrz[.]vip
Domain Security & Threat Intelligence Report
Analyst Security Overview
AI-GeneratedThe domain whats-xrz.vip was identified as a phishing site impersonating WhatsApp, aimed at stealing user credentials. With a VirusTotal score of 18/95, it poses a significant risk to those misled into visiting it, as it mimics the legitimate WhatsApp login interface.
Registered with Gname.com Pte. Ltd., this domain is relatively new at just 131 days old but has already been flagged for phishing attempts. It uses an IP address of 20.2.67.40 and is currently listed on one blocklist, indicating its malicious nature was recognized shortly after registration.
As of now, the domain has been taken down and is no longer active. PhishDestroy reported this domain and monitored its status, contributing to efforts to mitigate further phishing activities targeting unsuspecting users of WhatsApp.
Threat Response Pipeline
Public Blocklist Status
Website Screenshot
Domain Intelligence
a2.share-dns.com
b.share-dns.net
b2.share-dns.net
complaint@gname.com
abuse@microsoft.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 20.2.67.40
More Domains at Gname.com Pte. Ltd.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report