# whatscnus.cyou — MALICIOUS > Whatscnus.cyou is a high-risk phishing site mimicking Rakuten login. Avoid interaction and report suspicious activity immediately. ## Summary PhishDestroy identifies whatscnus.cyou as an active phishing domain targeting users with fake Rakuten login pages, posing significant risk of credential theft. This generic phishing threat is classified as high risk due to its deceptive tactics and potential financial harm. The domain was registered recently on February 21, 2026, via Gname.com Pte. Ltd. It resolves to IP 104.21.29.230 and is flagged by 16 out of 95 security vendors on VirusTotal. It also appears on a security blocklist and has been observed in two AlienVault OTX threat pulses, confirming ongoing malicious activity. Users are strongly advised to avoid visiting whatscnus.cyou or entering any personal information. If encountered, report the site to your security team or use browser phishing report features. Maintaining vigilance and using updated security software helps prevent compromise from this active phishing threat. ## Threat Details - Verdict: MALICIOUS - Site status: alive (HTTP 530) - Page title: 楽天会員 ログイン ## Domain Intelligence - Registered: 2026-02-21 07:01:08 - Registrar: Gname.com Pte. Ltd. - Country: SG - IP: 104.21.29.230 - Nameservers: ["A.SHARE-DNS.COM", "B.SHARE-DNS.NET"] - SSL Issuer: WE1 ## Detection Status - VirusTotal: 16 vendors flagged Vendors: ["Criminal IP", "alphaMountain.ai", "BitDefender", "CyRadar", "ESET", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Kaspersky", "Lionic", "Seclookup", "SOCRadar", "Sophos", "Trustwave", "VIPRE", "Webroot"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019a473d-e064-74e9-af83-9591399a9fbd.png - PhishDestroy: https://phishdestroy.io/domain/whatscnus.cyou/ - LLM endpoint: https://phishdestroy.io/domain/whatscnus.cyou/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/whatscnus.cyou/ Last updated: 2026-03-19