webfresh[.]wheelnwater[.]com
“webfresh – Just another WordPress site”
webfresh.wheelnwater.com — No verificado. Suplantación de marca: Facebook; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, SOCRadar, Webroot); PhishDestroy score 65/100. Registrador: Enartia Single Member.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain webfresh.wheelnwater.com was identified as a brand‑impersonation infrastructure targeting Facebook users. The site is hosted on the IPv4 address 185.146.22.243, which belongs to ASN 55293 (A2 Hosting, Inc.) and is geolocated in the Netherlands. Registration data show the domain was created on 22 November 2019 through the registrar Enartia Single Member S.A., and the authoritative name servers are ns1‑ns4.a2hosting.com. No TLS certificate is presented; the service was reachable via HTTP only, and the current HTTP status is offline as of the report date. A passive web scan retrieved the page title “webfresh – Just another WordPress site”, which does not contain overt branding but confirms the site is powered by a default WordPress installation.
The infrastructure received a Gridinsoft trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal analysis recorded six detections out of ninety‑five scanners, confirming that multiple security engines consider the domain suspicious. The domain appears on a single public blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the classification as a phishing vector. Evidence confirms the campaign’s objective is brand impersonation of Facebook, although the exact payload or credential‑harvesting page has not been captured. The absence of an SSL certificate and the reliance on a generic WordPress title suggest a low‑effort deployment, yet the presence on multiple detection platforms indicates active abuse.
Uncertainty remains regarding the specific phishing page content, any associated malware, and whether the domain has been reused in other campaigns. Defenders should add 185.146.22.243 and webfresh.wheelnwater.com to network‑level deny lists, monitor DNS queries for the domain and its A2 Hosting name servers, and enforce TLS inspection to block any clear‑text HTTP attempts.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: wheelnwater.com
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wheelnwater.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.