Analysis of wechataccount.com as of July 31 2026 indicates that the domain is currently active and is being used for credential phishing. The domain was registered on 12 January 2025 through Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn). DNS resolution points to the IPv4 address 2.57.91.116 and the authoritative nameservers are ns1.dns-parking.com and ns2.dns-parking.com, a pair commonly associated with parked or disposable domains.
Threat intelligence shows that the domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy filtering service. VirusTotal data reveal that one out of ninety‑one security‑vendor scans returned a positive flag, confirming at least one independent detection of malicious activity. No additional public threat feeds, such as OTX or Google Safe Browsing, are referenced in the supplied intelligence, and no SSL certificate details or HTTP response codes have been disclosed, leaving the surface‑level web interaction characteristics unverified.
The limited detection footprint—one blocklist entry and a single vendor flag—suggests either a nascent campaign or low‑visibility hosting, but the confirmed phishing intent aligns with the credential‑theft classification. Defenders should proactively add wechataccount.com to local blocklists, monitor DNS queries for the 2.57.91.116 address, and enforce outbound traffic controls to prevent credential submission to this host. Continuous re‑evaluation is advised, as additional detections or blocklist listings may emerge as the campaign matures.