Analysis of whatsapp-correo.webcindario.com indicates an active high-risk phishing domain targeting WhatsApp user credentials. The domain was registered on February 28, 2001, through TUCOWS.COM, CO., and currently resolves to IP address 5.57.226.202. Google Safe Browsing has flagged the site for social engineering, and it appears on two security blocklists, including PhishDestroy and OpenPhish. As of August 1, 2026, 18 of 91 security vendors on VirusTotal detect the domain as malicious, reinforcing its classification as a phishing threat.
Infrastructure analysis reveals the domain uses Google Cloud nameservers (ns-cloud-d1.googledomains.com, ns-cloud-d2.googledomains.com, ns-cloud-d3.googledomains.com), which may provide some resilience against takedowns. The domain remains active, and no evidence of SSL certificate anomalies or HTTP status errors has been reported. The exact content of the phishing page is not yet analysed, but the domain name and detection context strongly suggest an intent to harvest WhatsApp login credentials. Defenders should treat this domain as a confirmed phishing threat.
Network-level blocking of 5.57.226.202 and the domain itself is recommended. Security teams should monitor for connections to this infrastructure, particularly from corporate or mobile devices where WhatsApp is in use. If internal access is detected, credentials potentially exposed via this domain should be reset immediately. Further investigation into the hosting provider and registrar may assist in mitigation efforts.