whats-xtq[.]vip
Domain Security & Threat Intelligence Report
The domain whats-xtq.vip was identified as a phishing site impersonating WhatsApp, which is particularly dangerous given its potential to steal user credentials. With a VirusTotal score of 16 out of 95, the site was flagged by multiple security vendors, indicating a significant level of threat.
This domain was registered with Gname.com Pte. Ltd. and has been active for approximately 130 days. It was hosted on the IP address 20.2.67.40. The domain had also been included in two blocklists, suggesting that it was recognized as malicious shortly after becoming active.
As of now, the domain is confirmed to be taken down. PhishDestroy has reported this phishing site and actively monitored its status to prevent further use of the domain for malicious purposes.
Threat Response Pipeline
Public Blocklist Status
Forensic Evidence Capture
Domain Intelligence
a2.share-dns.com
b.share-dns.net
b2.share-dns.net
complaint@gname.com
abuse@microsoft.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 20.2.67.40
More Domains at Gname.com Pte. Ltd.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report