vvv-wahst5pp[.]com
“whatsapp官网登录入口| 发送文件的最佳格式:确保顺畅传输”
Riepilogo delle prove
The domain vvv-wahst5pp.com was registered on February 21, 2026 through GKG.Net, Inc. and is configured to use the authoritative nameservers n1.xundns.com and n2.xundns.com. DNS resolution points to the IP address 103.80.133.43, which belongs to AS205960 HDTIDC LIMITED and is geolocated in the Republic of Korea. The site presented an SSL certificate issued by Let’s Encrypt (R12), indicating that HTTPS was available at the time of observation. The HTTP response header identified the web server as Apache HTTP Server, and the page contained Baidu Analytics tracking code. The page title retrieved from the site reads "whatsapp官网登录入口| 发送文件的最佳格式:确保顺畅传输," directly referencing WhatsApp and suggesting a login portal.
This title, together with the documented brand target of WhatsApp, confirms the infrastructure was designed to impersonate the messaging service. Malware and URL reputation services have taken notice: VirusTotal recorded detections from 16 of 93 scanning engines, and the domain appears on one public security blocklist. It has also been referenced in thirteen AlienVault OTX threat pulses, indicating that the indicator has been shared among multiple threat‑intel communities. The site was subsequently taken offline and is currently listed as blocked by PhishDestroy.
Although the domain is no longer active, defenders should continue to monitor for any re‑registration or resurgence of the same infrastructure, especially given the elevated risk rating. Network defenders are advised to add the IP 103.80.133.43 and the domain vvv-wahst5pp.com to deny‑list policies, ensure that endpoint protection solutions surface the Let’s Encrypt certificate fingerprint, and audit any outbound connections to the Korean hosting ASN. Because the site employed a legitimate SSL certificate and common web technologies, automated filters may miss it; therefore, security teams should incorporate the observed page title and the Baidu Analytics indicator into content‑inspection rules.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | vvv-wahst5pp.com |
malicious | Sinkholed |
| OpenDNS | vvv-wahst5pp.com |
phishing | Phishing Block |
| DigiCert UltraDNS | vvv-wahst5pp.com |
malicious | Sinkholed |
| Hagezi Threat Feed | vvv-wahst5pp.com |
malicious | Sinkholed |
| DNS4EU | vvv-wahst5pp.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Raggiungibile → Non raggiungibile
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
-
Stato del dominio
Non raggiungibile → Raggiungibile
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie
2 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of vvv-wahst5pp.com · checked Mar 2, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo