wetransfer0[.]uk
“Suspected phishing site | Cloudflare”
Osservazione memorizzata
Contrasto dei titoli osservato
Riepilogo delle prove
PhishDestroy identifies wetransfer0.uk as an elevated-risk domain engaged in brand impersonation phishing, specifically targeting users of the legitimate file-sharing service WeTransfer. The domain exploits the trusted WeTransfer name to trick visitors into entering credentials or downloading malicious content, posing a direct threat to personal and corporate data security.
This domain was flagged by 20 out of 95 security vendors on VirusTotal, indicating widespread detection across the security community. It is currently active and appears on at least one security blocklist. The domain was created on April 9, 2026, which is suspiciously recent, and is registered through Cloudflare, Inc., a common registrar for both legitimate and malicious sites. The domain resolves to IP address 35.157.26.135, and its SSL certificate is issued by Let's Encrypt (E8), which is frequently abused by phishing operations. Cloudflare itself has flagged the site, displaying a warning page titled "Suspected phishing site | Cloudflare." These combined indicators strongly confirm the domain's malicious intent.
To protect against this specific brand impersonation phishing threat, users should never enter any personal information, passwords, or payment details on wetransfer0.uk. Avoid clicking any links or downloading files from the site. If you have already interacted with the domain, change passwords for any accounts that may have been compromised and monitor for suspicious activity. Report the domain to your email provider or security team. Always verify URLs by checking for subtle misspellings or unusual domain extensions like .uk instead of the official .com. Implement web filtering to block this domain and similar impersonation attempts. PhishDestroy recommends treating all unsolicited file transfer requests with caution and directly navigating to the official WeTransfer website when needed.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | wetransfer0.uk/ |
malware | Detects file containing Telegram Bot API |
| DigiCert UltraDNS | wetransfer0.uk |
malicious | Sinkholed |
| Cloudflare DNS | wetransfer0.uk |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | wetransfer0.uk |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 11/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of wetransfer0.uk · checked Apr 9, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo