whatsappwa[.]com[.]cn
“WhatsApp网页版- 全功能指南与使用技巧”
whatsappwa.com.cn — No verificado. Suplantación de marca: Google; Tipo de estafa: Social Media Phishing. Resumen de las pruebas: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrador: 四川域趣网络科技有限公司.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, whatsappwa.com.cn, is flagged for elevated-risk brand impersonation activity targeting Google, despite its misleading page title suggesting affiliation with WhatsApp. Analysis indicates the domain was designed to deceive users into believing they were interacting with legitimate Google services, a tactic commonly employed to harvest credentials or distribute malicious payloads. The discrepancy between the page title (WhatsApp网页版- 全功能指南与使用技巧) and the actual brand target (Google) underscores the deceptive nature of this campaign, which may exploit user trust in both platforms to maximize compromise success rates. Infrastructure analysis reveals the domain was registered through 四川域趣网络科技有限公司, a registrar frequently associated with high-risk domains. It resolves to the IP address 156.252.40.3, hosted under AS9294 (GNET INC.) in Hong Kong, a region often leveraged for bulletproof hosting due to lenient enforcement policies. The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 19 out of 95 security vendors on VirusTotal, with detections including phishing, brand impersonation, and malicious content. Notably, the domain lacks an SSL certificate, a red flag for modern web security standards, further increasing its risk profile. While currently offline, historical data suggests this domain may re-emerge under altered infrastructure or similar naming conventions. Mitigation against brand impersonation threats of this nature requires a multi-layered approach. Organizations should implement domain monitoring to detect newly registered lookalike domains, particularly those mimicking high-value brands like Google. End-users should be trained to scrutinize page titles, URLs, and SSL certificate presence, as these are common indicators of fraudulent sites. Security teams are advised to block the IP address 156.252.40.3 at the network perimeter and update detection rules to include domains registered via 四川域趣网络科技有限公司. Additionally, enforcing strict email filtering policies to quarantine messages containing links to newly registered or untrusted domains can reduce exposure to such campaigns. Given the elevated risk level, affected organizations should conduct retrospective log analysis to identify any prior interactions with this domain or its associated infrastructure.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.