ubi[.]weppb[.]icu
“Whatsapp”
Riepilogo delle prove
The domain ubi.weppb.icu was registered on 21 February 2026 and is currently taken offline. Technical analysis shows it resolves to the IP address 23.102.234.67, which is hosted in Hong Kong and belongs to ASN 8075 (Microsoft Corporation). The site presented a page title of "Whatsapp," matching the declared brand target of WhatsApp and confirming a brand‑impersonation intent. A TLS certificate was observed with an R12 rating, indicating a low‑trust certificate.
Reputation services assign extremely low scores: Gridinsoft rates the domain 0 out of 100, while Scamadviser assigns 1 out of 100, both reflecting a high likelihood of malicious activity. VirusTotal scans flagged the domain in 15 of 95 vendor engines, reinforcing the suspicion. The domain appears on a single security blocklist and has been actively blocked by PhishDestroy, demonstrating that at least one external mitigation service has taken protective action.
No additional content, login forms, or payload details have been disclosed, so the exact phishing lures or credential‑harvesting mechanisms remain unknown. Defenders should add the domain and its resolved IP to network‑level deny lists, monitor for future DNS resolutions to the same IP range, and enforce URL filtering policies that block any pages titled "Whatsapp" originating from untrusted hosts. Continuous observation of related sub‑domains and newly registered domains with similar naming patterns is recommended to pre‑empt potential re‑use of the same infrastructure.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ZONA SHORTDOT · PROVE PUBBLICHE
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Informazioni forensi
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo