wechatcorp[.]xyz
“WeChat - 全球10億用戶選擇的聊天通話應用程式”
Resumen de las pruebas
Analysis of the domain wechatcorp.xyz indicates a confirmed phishing operation targeting Google's brand identity, despite the domain name suggesting an affiliation with WeChat. The site was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with high-risk domains. Infrastructure analysis reveals the domain resolves to the IP address 43.159.94.110, hosted on Cloudflare's network (AS13335) in the United States, with nameservers justin.ns.cloudflare.com and margot.ns.cloudflare.com. The use of Cloudflare and HTTP/3 suggests an attempt to obscure the origin server and enhance delivery speed, tactics commonly observed in phishing campaigns. The page title, 'WeChat - 全球10億用戶選擇的聊天通話應用程式,' explicitly references WeChat, a messaging platform, which creates a discrepancy with the stated brand target of Google.
This inconsistency may indicate an effort to exploit multiple brands or a misdirection tactic. As of the report date, the domain has been flagged by four of the 95 security vendors on VirusTotal, a detection rate that, while modest, aligns with the early stages of a phishing campaign before broader vendor coverage is achieved. The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, further corroborating its malicious classification. Gridinsoft's trust score of 0/100 provides additional confirmation of the domain's high-risk status. The SSL certificate, issued by Google Trust Services (WE1), may have been leveraged to lend an appearance of legitimacy, though such certificates are routinely obtained by threat actors to bypass basic security checks.
The domain is currently offline, which could indicate takedown action or a temporary suspension by the threat actor to evade detection. Defenders are advised to treat this domain as a confirmed phishing threat. Network-level blocking of the IP 43.159.94.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260203-C0A2DE- Artefacto PDF
- Evidencia en PDF
Texto completo de la evidencia
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 12/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías
2 tecnologías identificadas con alta confianza
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of wechatcorp.xyz · checked Apr 30, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.