Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is lzr547@sina.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
web[.]whatsapp[.]jo[.]hl[.]cn
“WhatsApp Web”
web.whatsapp.jo.hl.cn — No verificado. Tipo de estafa: Social Media Phishing. Resumen de las pruebas: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 3 alerts; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Registrador: 成都垦派科技有限公司.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, web.whatsapp.jo.hl.cn, is flagged as a generic phishing site specifically designed to impersonate WhatsApp Web. Analysis indicates the infrastructure was established to harvest user credentials, session tokens, or other sensitive information by mimicking the legitimate WhatsApp Web interface. The page title, 'WhatsApp Web,' further confirms the intent to deceive users into believing they are interacting with the official WhatsApp service. No evidence of a drainer kit or cryptocurrency wallet interaction was identified in this instance, focusing instead on traditional credential theft. Infrastructure analysis reveals multiple technical indicators of compromise. The domain resolves to the IP address 168.76.144.218, hosted under AS137951 (ASLINE LIMITED) in Hong Kong. It was registered through 成都垦派科技有限公司 on February 28, 2026, an unusually future-dated registration likely intended to evade immediate detection. The domain appears on one security blocklist and is flagged by 24 out of 95 security vendors on VirusTotal, indicating a moderate to high level of detection. The SSL certificate, issued by Let's Encrypt (R12), provides basic encryption but does not validate the legitimacy of the site. No Google Safe Browsing (GSB) listing was observed at the time of analysis, though this may change as the domain ages. Currently, web.whatsapp.jo.hl.cn is offline, reducing immediate risk to end users. However, the infrastructure remains registered and could be reactivated or repurposed for similar phishing campaigns. Users who may have interacted with this domain should immediately revoke any active sessions, reset passwords, and enable multi-factor authentication on their accounts. Organizations are advised to block the domain and associated IP address (168.76.144.218) at the network level to prevent potential re-emergence. Despite its offline status, the domain's registration details and hosting provider suggest a persistent threat, warranting continued monitoring.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | web.whatsapp.jo.hl.cn |
phishing | Phishing Block |
| Cloudflare DNS | web.whatsapp.jo.hl.cn |
malicious | Sinkholed |
| DNS4EU | web.whatsapp.jo.hl.cn |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 10 identified
Utility-first CSS framework for rapid custom UI development.
Popular CSS framework for responsive, mobile-first web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comLegacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Datos y informes externos
PD-20260318-9CB42D Recipient: lzr547@sina.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.