tpg-wswhatsapp[.]cc
“whatsapp web login| 如何进行文件分享:支持多种文件格式”
tpg-wswhatsapp.cc — Contenido no disponible (HTTP 502). Suplantación de marca: Facebook; Tipo de estafa: Social Media Phishing. Resumen de las pruebas: VirusTotal 18/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrador: Dominet (HK).
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain is flagged as an elevated-risk brand impersonation threat targeting WhatsApp Web login credentials. Analysis indicates the infrastructure is designed to deceive users into submitting authentication details through a fabricated login interface, while also promoting file-sharing capabilities in Chinese-language text. The specific threat involves credential theft, likely followed by unauthorized account access or further social engineering attacks. Infrastructure analysis reveals multiple high-risk indicators. The domain tpg-wswhatsapp.cc was registered on October 02, 2025, through Dominet (HK) Limited, a registrar frequently associated with fraudulent activity. It resolves to the IP address 103.99.210.145, hosted in South Korea under AS205960 (HDTIDC LIMITED), an autonomous system with a history of malicious traffic. VirusTotal detection rates show 18 out of 95 security vendors flagging the domain, while it appears on two security blocklists: PhishDestroy and PhishingDB. The absence of an SSL certificate further undermines trust, as encrypted connections are standard for legitimate authentication portals. The page title, 'whatsapp web login| 如何进行文件分享:支持多种文件格式,' explicitly targets Chinese-speaking users, suggesting a localized phishing campaign. Mitigation steps for this threat type include immediate domain blocking at the network level, particularly for endpoints resolving to 103.99.210.145 or associated autonomous systems. Organizations should update email and web filtering rules to quarantine messages containing links to tpg-wswhatsapp.cc or similar impersonation domains. End-user education should emphasize verifying SSL certificates and domain authenticity before entering credentials, especially for services like WhatsApp Web. Security teams are advised to monitor for unauthorized access attempts from the IP range 103.99.210.0/24 and investigate any connections to the registrar Dominet (HK) Limited for potential fraudulent domain registrations. Given the domain's current offline status, continuous monitoring for reactivation or domain squatting variants is recommended.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.