whatsapp-vip[.]chat-whatsapps[.]hi[.]cn
“WhatsApp网页版 - 解锁WhatsApp企业档案的WhatsApp网页版”
whatsapp-vip.chat-whatsapps.hi.cn — Contenu indisponible. Usurpation de l'identité de la marque : WhatsApp; Type d'arnaque : Impersonation. Résumé des preuves: VirusTotal 19/91 (Criminal IP, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 3 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Bureau d’enregistrement: 北京新网数码信息技术有限公司.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis as of July 21, 2026 indicates that the domain whatsapp-vip.chat-whatsapps.hi.cn is actively being used for a generic phishing campaign. The domain was registered on July 01, 2026 through Beijing Xinwang Digital Information Technology Co., Ltd. and is served by the authoritative name servers dm1.longmingdns.com and dm2.longmingdns.com. DNS resolution points to the IPv4 address 156.239.9.106, which is currently listed by PhishDestroy as a malicious host. Independent scanning on VirusTotal shows that 11 of 91 security vendors have flagged the domain as malicious, and the domain appears on at least one external blocklist, confirming its reputation as a threat. No public page title or content analysis is available, so the exact brand being spoofed cannot be confirmed. The lack of a disclosed SSL certificate or HTTP status code in the available data prevents assessment of transport-level security, but the presence of multiple detections and an active blocklist entry suggests the site is being used to harvest credentials or deliver malicious payloads. Defenders should immediately block the domain and its resolved IP address at perimeter firewalls, DNS resolvers, and endpoint protection solutions. Continuous monitoring of the hosting provider and name-server changes is recommended, as the infrastructure could be pivoted to additional malicious sites. Adding the domain to internal threat intelligence feeds and sharing the indicator set with industry-wide platforms will help accelerate detection across the broader security community. Organizations that rely on WhatsApp or related messaging services should be cautioned that unsolicited messages referencing the domain are likely fraudulent, and users should be instructed to verify URLs through official channels before providing any personal information.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | whatsapp-vip.chat-whatsapps.hi.cn |
malicious | Sinkholed |
| OpenDNS | whatsapp-vip.chat-whatsapps.hi.cn |
phishing | Phishing Block |
| DNS4EU | whatsapp-vip.chat-whatsapps.hi.cn |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of whatsapp-vip.chat-whatsapps.hi.cn · checked Jul 21, 2026
Données factuelles et rapports externes
PD-20260721-6B0A26 Recipient: wwdengdai4@gmail.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif