yrs-wswhatsapp[.]cc
“whatsapp web login- 如何设置语音通话的优先级:优化通话体验”
yrs-wswhatsapp.cc — Contenido no disponible (HTTP 502). Suplantación de marca: Google; Tipo de estafa: Social Media Phishing. Resumen de las pruebas: VirusTotal 15/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrador: Dominet (HK).
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis indicates that the domain yrs-wswhatsapp.cc was registered on 2025-10-02 through Dominet (HK) Limited and resolves to IP 103.80.133.94, which is announced in ASN 205960 and geolocated to South Korea under HDTIDC LIMITED. No TLS certificate is present, so connections are unencrypted. The page title observed during a brief fetch reads “whatsapp web login- 如何设置语音通话的优先级:优化通话体验”, implying a lure that mixes WhatsApp Web login language with a Google impersonation angle. The campaign is categorized as social media phishing targeting the Google brand.
Detection data show that 15 of 95 VirusTotal scanners flagged the domain as malicious, the Gridinsoft trust score is 0 / 100, and the domain appears on one external security blocklist. AlienVault OTX has recorded the domain in 17 threat‑intel pulses, and the PhishDestroy sinkhole has blocked it. Authoritative name servers are ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, and ns4.domainname, a pattern often associated with disposable hosting. The current status is offline, likely due to takedown actions.
Uncertainty remains about the specific phishing kit used and whether credential‑stealing forms were served before the shutdown, as only the page title is available. Defenders should block the IP address 103.80.133.94 and the associated name servers, add yrs-wswhatsapp.cc to URL filtering and blocklists, and monitor for future domains registered via the same registrar or hosted in the same ASN. Enrich threat‑intel feeds with these indicators and advise users to treat unsolicited WhatsApp Web login prompts that reference Google as malicious.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.