uao-wswhatsapp[.]cc
“whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具”
uao-wswhatsapp.cc — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Google; Type d'arnaque : Social Media Phishing. Résumé des preuves: VirusTotal 16/95 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Bureau d’enregistrement: Dominet (HK).
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
On July 23, 2026, the domain uao-wswhatsapp.cc was observed as an offline infrastructure used to impersonate Google in a social‑media phishing campaign. The site was registered on 02 Oct 2025 through Dominet (HK) Limited and resolves to the IPv4 address 103.80.133.70, which belongs to AS205960 operated by HDTIDC LIMITED in South Korea. Four authoritative name servers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname) are configured, but the site lacks an SSL/TLS certificate, indicating that any traffic would be transmitted unencrypted. The page title returned by the server is "whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具", a Chinese phrase unrelated to Google, suggesting that the content has not yet been publicly analyzed.
Gridinsoft assigned a trust score of 0 / 100, and the domain is listed on at least one public blocklist and has been blocked by PhishDestroy. Threat intelligence aggregation services have recorded the domain in 16 AlienVault OTX pulses, and VirusTotal reports 16 of 95 scanning engines flagging the domain as malicious. The combination of a newly created domain, low‑reputation hosting, absence of TLS, and multiple detections points to a high likelihood of credential‑harvesting activity targeting Google users via a purported WhatsApp login interface. However, the exact payload, phishing kit, or compromised accounts remain unknown because the site is offline and no forensic capture of the landing page is available.
Defenders should add uao-wswhatsapp.cc to URL filtering and endpoint allow‑list exclusion rules, monitor DNS queries for the four associated name servers, and enforce strict TLS inspection for outbound traffic to the IP 103.80.133.70. Incident response teams should also correlate any recent Google authentication failures with requests to this domain and consider user‑education campaigns that clarify the mismatch between the Chinese page title and the alleged Google impersonation.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif