whats-zms[.]vip
Domain Security & Threat Intelligence Report
The domain whats-zms.vip is identified as a phishing site impersonating WhatsApp to capture user credentials. It received a score of 14 out of 95 from VirusTotal, indicating a high likelihood of malicious intent. This domain was flagged for its ability to deceive users into providing sensitive information, making it a considerable threat during its operation.
Registered 139 days ago through Gname.com Pte. Ltd., the domain was associated with an IP address of 20.2.208.17. With a blocklist count of 2, its presence was confirmed across security platforms, highlighting its malicious nature and recent activity. The domain's relatively short lifespan and the nature of its registration raise concerns about its operational tactics.
Currently, the domain is taken down, and PhishDestroy has reported it to relevant authorities. Continuous monitoring will ensure that similar threats are identified and mitigated promptly, safeguarding users from potential phishing attacks.
Threat Response Pipeline
Public Blocklist Status
Forensic Evidence Capture
Domain Intelligence
a6.share-dns.com
b.share-dns.net
b6.share-dns.net
master@share-dns.com
complaint@gname.com
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
Other Domains on 20.2.208.17
More Domains at Gname.com Pte. Ltd.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive
URLScan Report