web[.]whatsapp[.]sc[.]cn
“WhatsApp Web”
web.whatsapp.sc.cn — Conteúdo indisponível (HTTP 502). Representação da marca: WhatsApp; Tipo de golpe: Social Media Phishing. Resumo das evidências: VirusTotal 21/95 (ADMINUSLabs, BitDefender, Cluster25, CRDF, CyRadar); URLQuery 5 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. Registrador: 成都垦派科技有限公司.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, web.whatsapp.sc.cn, is confirmed to host a fake WhatsApp Web login portal designed to harvest user credentials. Analysis indicates the site impersonates the legitimate WhatsApp Web service, a tactic commonly employed in credential phishing campaigns. The domain is currently offline, though prior activity suggests it was actively targeting users seeking to access WhatsApp through a web interface. Infrastructure analysis reveals the domain was flagged by 21 of 95 security vendors on VirusTotal, indicating moderate consensus on its malicious nature. It was registered through 成都垦派科技有限公司, a registrar with a history of hosting suspicious domains. The domain resolves to IP address 168.76.144.203, located in Hong Kong under AS137951 (ASLINE LIMITED). Notably, the domain was created on February 22, 2026, an anomalous future date likely intended to evade detection or mislead investigators. It appears on one security blocklist and lacks an SSL certificate, further reducing its legitimacy. No valid encryption or authentication mechanisms were observed during assessment. The domain has been taken offline, mitigating immediate risk to users. However, organizations and individuals are advised to block the domain and its associated IP (168.76.144.203) at the network level. Security teams should monitor for related domains registered under the same registrar or resolving to the same IP range. Users who may have interacted with the site should reset their credentials immediately and enable multi-factor authentication on all accounts. Proactive phishing awareness training is recommended to prevent future compromise via similar impersonation tactics.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | web.whatsapp.sc.cn |
malicious | Sinkholed |
| OpenDNS | web.whatsapp.sc.cn |
phishing | Phishing Block |
| Hagezi Threat Feed | web.whatsapp.sc.cn |
malicious | Sinkholed |
| DNS4EU | web.whatsapp.sc.cn |
malicious | Sinkholed |
| Quad9 DNS | web.whatsapp.sc.cn |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of web.whatsapp.sc.cn · checked Mar 1, 2026
Evidências e relatórios externos
PD-20260222-4CFAFE Recipient: vbd016@sina.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo