सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 20। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

627web[.]whatsapwcox[.]com

“Whatsapp Web”

धमकी भरा फैसला गंभीर 95/100 साक्ष्य स्कोर
उपलब्धता सामग्री अनुपलब्ध नवीनतम अवलोकन में सामग्री अनुपलब्ध थी
वायरस का कुल पता लगाना: 20/93 Spamhaus DBL: DBL_PHISH URLQuery threat systems: 3 alerts ब्रांड प्रतिरूपण: WhatsApp
31/01/2026 WhatsApp 1 Report Sent CDN
रिपोर्ट सारांश

627web.whatsapwcox.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: WhatsApp; घोटाले का प्रकार: Social Media Phishing. साक्ष्य सारांश: VirusTotal 20/93 (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); URLQuery 3 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. रजिस्ट्रार: Gname.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
6003B66F
स्कोर
95/100

627web.whatsapwcox.com is currently resolved to IP 38.55.19.51, an address owned by AS8796 FASTNET DATA INC and located in the United States. The domain was created on 21 February 2026 via the registrar Gname.com Pte. Ltd. and is delegated to the Cloudflare name servers elsa.ns.cloudflare.com and javier.ns.cloudflare.com. No TLS certificate is presented, meaning the service is delivered over plain HTTP only. The HTTP response includes a page title of "Whatsapp Web", directly matching the declared brand target "whatsapp" and confirming the intent to impersonate the messaging platform. VirusTotal analysis shows that 20 of 93 scanning engines flag the domain as malicious, and the site appears on a single external blocklist. PhishDestroy has already taken the domain offline, and the Gridinsoft trust score is 0 out of 100, reinforcing the malicious classification. The observed scam type is listed as "Social Media Phishing", indicating that the infrastructure was likely used to harvest WhatsApp credentials or other personal data.

Infrastructure analysis suggests the attacker used a short‑lived domain, a reputable registrar, and Cloudflare DNS to mask the true hosting environment while still exposing the underlying IP address. The lack of an SSL certificate reduces the credibility of any login interface that may have been served, but the specific "Whatsapp Web" title is a concrete indicator of brand impersonation. The modest number of VirusTotal detections and the presence on only one blocklist imply a brief operational window before the takedown.

Defenders should immediately add 627web.whatsapwcox.com to DNS and proxy blocklists, enforce HTTPS‑only policies to prevent fallback to insecure HTTP, and monitor traffic to the associated IP range (38.55.19.0/24) for any residual connections.

VirusTotal
VirusTotal
20 det.
URLQuery
यूआरएलक्वेरी
3 threat alerts
URLScan
यूआरएलस्कैन
देखी गई स्थिति
सामग्री अनुपलब्ध 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 20 / 93 यूआरएलक्वेरी 3 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict malicious डीएनएस ब्लॉक जाँच नहीं की गई TLS कोई प्रमाणपत्र डेटा नहीं कौन है not parsed स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
DNS4EU 627web.whatsapwcox.com malicious Sinkholed
OpenDNS 627web.whatsapwcox.com phishing Phishing Block
Cloudflare DNS 627web.whatsapwcox.com malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
14/14
Sent Report Recorded
Stored sent-report record for registrar Gname.com Pte. Ltd., hosting provider, 2 abuse contacts
abuse@kurun.comcomplaint@gname.com
31/01/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Whatsapp Web
Impersonates
WhatsApp

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict दुर्भावनापूर्ण score 100 Phishing brand: Whatsapp report ↗
सर्वर / ASN nginx · AS8796 FD-298-8796 - FASTNET DATA INC, US
IP Context CDN shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
Registrar (base domain) Gname SG(SG)
दुरुपयोग संपर्कabuse@kurun.com, complaint@gname.com
IP पता 38.55.19.51 CDN
भौगोलिक स्थानUS Los Angeles, US
नेटवर्कAS8796 · FASTNET DATA INC
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
Registration (base domain)whatsapwcox.com · Expires 30/01/2027
HTTP स्थिति502 Error
पहली अनुपलब्धता तक का समय 100 days
हम क्या मापते हैं पहली संग्रहीत दुरुपयोग रिपोर्ट से लेकर पहली बार अवलोकन तक कि सामग्री अनुपलब्ध थी, बीता हुआ समय। इससे कारण स्थापित नहीं होता.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला31/01/2026
DOM Analysisanalyzed 23/04/2026score 10/1001 brand signal
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://627web.whatsapwcox.com/
नेमसर्वरelsa.ns.cloudflare.comjavier.ns.cloudflare.com
TLS Observationvalid from 30/01/2026scanned 15/03/2026
Case ID
ICANN OVERSIGHT Registration: whatsapwcox.com

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For the registrable domain whatsapwcox.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

20 / 93 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
ADMINUSLabs
Criminal IP
BitDefender
Cluster25
CRDF
साइरेडार
ईएसईटी
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
MalwareURL
Mimecast
Seclookup
SOCRadar
सोफोस
Trustwave
VIPRE
वेबरूट

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260131-0231F5 Recipient: complaint@gname.com
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 36.0 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/627web.whatsapwcox.com"
  title="PhishDestroy threat report for 627web.whatsapwcox.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।