h5-whatsapp[.]hk[.]cn
“WhatsApp 網頁版 - H5移動端與網頁多端極速登入”
h5-whatsapp.hk.cn — Conteúdo indisponível. Representação da marca: WhatsApp; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 21/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 det.; URLScan malicious verdict; Spamhaus DBL_ABUSED_PHISH; PhishDestroy score 98/100. Registrador: 北京新网数码信息技术有限公司.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain h5-whatsapp.hk.cn is an active credential theft phishing site that impersonates WhatsApp Web to harvest login credentials from mobile and desktop users. The page title "WhatsApp 網頁版 - H5移動端與網頁多端極速登入" mimics legitimate WhatsApp Web interfaces, targeting users seeking cross-platform messaging access. Infrastructure analysis reveals the domain resolves to IP address 156.239.9.106 and is protected by a Let's Encrypt SSL certificate, which provides a false sense of security.
Evidence of malicious intent is robust. VirusTotal detection shows 17 out of 95 security vendors flag this domain as malicious. The domain was registered on June 30, 2026, through Chinese registrar 北京新网数码信息技术有限公司 (Beijing Xinwang Digital Information Technology Co., Ltd.), a registrar frequently observed in phishing campaigns. No blocklist count was provided in the intelligence, but the high VT detection ratio and active hosting status confirm the threat is live and operational.
Users who visited this site should immediately change their WhatsApp credentials and enable two-factor authentication on their accounts. They should also scan their devices for keyloggers or malware that may have been delivered via the phishing page. Monitoring for unauthorized account access and reporting the incident to their email provider is advised. Security teams should block the domain and IP 156.239.9.106 at the network perimeter to prevent further exposure.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 8 identified
Envoy is an open-source edge and service proxy, designed for cloud-native applications.
www.envoyproxy.io 100% de confiançaApache Traffic Server is an open-source caching and proxying server that serves as an HTTP/1.1 and HTTP/2 reverse proxy with caching capabilities, load balancing, request routing, SSL termination, and support for advanced HTTP features.
trafficserver.apache.org 100% de confiançaTaboola is a content discovery & native advertising platform for publishers and advertisers.
www.taboola.com 100% de confiançaSnowplow is an open-source behavioral data management platform for businesses.
snowplowanalytics.com 50% confidencePubMatic is a company that develops and implements online advertising software and strategies for the digital publishing and advertising industry.
www.pubmatic.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaGoogle Publisher Tag (GPT) is an ad tagging library for Google Ad Manager which is used to dynamically build ad requests.
developers.google.com 100% de confiançaGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-20260703-93092C Recipient: wwdengdai4@gmail.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo