webfresh[.]wheelnwater[.]com
“webfresh – Just another WordPress site”
Riepilogo delle prove
The domain webfresh.wheelnwater.com was identified as a brand‑impersonation infrastructure targeting Facebook users. The site is hosted on the IPv4 address 185.146.22.243, which belongs to ASN 55293 (A2 Hosting, Inc.) and is geolocated in the Netherlands. Registration data show the domain was created on 22 November 2019 through the registrar Enartia Single Member S.A., and the authoritative name servers are ns1‑ns4.a2hosting.com. No TLS certificate is presented; the service was reachable via HTTP only, and the current HTTP status is offline as of the report date. A passive web scan retrieved the page title “webfresh – Just another WordPress site”, which does not contain overt branding but confirms the site is powered by a default WordPress installation.
The infrastructure received a Gridinsoft trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal analysis recorded six detections out of ninety‑five scanners, confirming that multiple security engines consider the domain suspicious. The domain appears on a single public blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the classification as a phishing vector. Evidence confirms the campaign’s objective is brand impersonation of Facebook, although the exact payload or credential‑harvesting page has not been captured. The absence of an SSL certificate and the reliance on a generic WordPress title suggest a low‑effort deployment, yet the presence on multiple detection platforms indicates active abuse.
Uncertainty remains regarding the specific phishing page content, any associated malware, and whether the domain has been reused in other campaigns. Defenders should add 185.146.22.243 and webfresh.wheelnwater.com to network‑level deny lists, monitor DNS queries for the domain and its A2 Hosting name servers, and enforce TLS inspection to block any clear‑text HTTP attempts.
Data Coverage
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 13/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Registration: wheelnwater.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wheelnwater.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo