yrs-wswhatsapp[.]cc
“whatsapp web login- 如何设置语音通话的优先级:优化通话体验”
yrs-wswhatsapp.cc — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Google; Jenis penipuan: Social Media Phishing. Ringkasan bukti: VirusTotal 15/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Registrar: Dominet (HK).
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis indicates that the domain yrs-wswhatsapp.cc was registered on 2025-10-02 through Dominet (HK) Limited and resolves to IP 103.80.133.94, which is announced in ASN 205960 and geolocated to South Korea under HDTIDC LIMITED. No TLS certificate is present, so connections are unencrypted. The page title observed during a brief fetch reads “whatsapp web login- 如何设置语音通话的优先级:优化通话体验”, implying a lure that mixes WhatsApp Web login language with a Google impersonation angle. The campaign is categorized as social media phishing targeting the Google brand.
Detection data show that 15 of 95 VirusTotal scanners flagged the domain as malicious, the Gridinsoft trust score is 0 / 100, and the domain appears on one external security blocklist. AlienVault OTX has recorded the domain in 17 threat‑intel pulses, and the PhishDestroy sinkhole has blocked it. Authoritative name servers are ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, and ns4.domainname, a pattern often associated with disposable hosting. The current status is offline, likely due to takedown actions.
Uncertainty remains about the specific phishing kit used and whether credential‑stealing forms were served before the shutdown, as only the page title is available. Defenders should block the IP address 103.80.133.94 and the associated name servers, add yrs-wswhatsapp.cc to URL filtering and blocklists, and monitor for future domains registered via the same registrar or hosted in the same ASN. Enrich threat‑intel feeds with these indicators and advise users to treat unsolicited WhatsApp Web login prompts that reference Google as malicious.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Forensik
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive