123[.]bmt-whatsapp[.]com[.]cn
“WhatsApp Web”
123.bmt-whatsapp.com.cn — Konten tidak tersedia. Peniruan identitas merek: WhatsApp; Jenis penipuan: Social Media Phishing. Ringkasan bukti: VirusTotal 21/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 5 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: 成都垦派科技有限公司.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain 123.bmt-whatsapp.com.cn was registered on February 27, 2026 through 成都垦派科技有限公司 and is currently listed as offline. Infrastructure analysis shows the domain resolves to IP address 43.226.17.44, which is owned by BGP Network Limited (AS64050) and geolocated in the Republic of Korea. No TLS certificate is presented for the host, indicating that the service operates without encryption. The authoritative name servers are ns1.kenpains.com and ns2.kenpains.com, both of which are associated with the same registrar.
The page title returned from HTTP requests is "WhatsApp Web," aligning with the observed scam type of Social Media Phishing. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service. VirusTotal scans report that 21 of 93 security vendors have flagged the domain, providing additional confidence in its malicious reputation. While the exact payload or credential‑harvesting mechanism has not been publicly disclosed, the combination of the WhatsApp‑related title, the lack of HTTPS, and the detection history strongly suggest a credential‑stealing campaign targeting WhatsApp users.
Defenders should continue to block DNS resolution for the domain, monitor outbound connections to the associated IP range, and ensure that email and web filters reject any URLs containing the domain or its sub‑domains. Because the site is offline, any ongoing campaigns may have shifted to new infrastructure; threat‑intel teams should watch for similarly patterned domains that reuse the same registrar, name servers, or IP ASN. Continuous re‑evaluation of blocklist status and VirusTotal detection counts is recommended to maintain up‑to‑date protection against this threat vector.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
| OpenDNS | 123.bmt-whatsapp.com.cn |
phishing | Phishing Block |
| Cloudflare DNS | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
| Quad9 DNS | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
| DNS4EU | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260227-06CED7 Recipient: zdn841@sina.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive