webfresh[.]wheelnwater[.]com
“webfresh – Just another WordPress site”
webfresh.wheelnwater.com — Não verificado. Representação da marca: Facebook; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, SOCRadar, Webroot); PhishDestroy score 65/100. Registrador: Enartia Single Member.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain webfresh.wheelnwater.com was identified as a brand‑impersonation infrastructure targeting Facebook users. The site is hosted on the IPv4 address 185.146.22.243, which belongs to ASN 55293 (A2 Hosting, Inc.) and is geolocated in the Netherlands. Registration data show the domain was created on 22 November 2019 through the registrar Enartia Single Member S.A., and the authoritative name servers are ns1‑ns4.a2hosting.com. No TLS certificate is presented; the service was reachable via HTTP only, and the current HTTP status is offline as of the report date. A passive web scan retrieved the page title “webfresh – Just another WordPress site”, which does not contain overt branding but confirms the site is powered by a default WordPress installation.
The infrastructure received a Gridinsoft trust score of 0 out of 100, indicating a high likelihood of malicious intent. VirusTotal analysis recorded six detections out of ninety‑five scanners, confirming that multiple security engines consider the domain suspicious. The domain appears on a single public blocklist and is explicitly blocked by the PhishDestroy service, reinforcing the classification as a phishing vector. Evidence confirms the campaign’s objective is brand impersonation of Facebook, although the exact payload or credential‑harvesting page has not been captured. The absence of an SSL certificate and the reliance on a generic WordPress title suggest a low‑effort deployment, yet the presence on multiple detection platforms indicates active abuse.
Uncertainty remains regarding the specific phishing page content, any associated malware, and whether the domain has been reused in other campaigns. Defenders should add 185.146.22.243 and webfresh.wheelnwater.com to network‑level deny lists, monitor DNS queries for the domain and its A2 Hosting name servers, and enforce TLS inspection to block any clear‑text HTTP attempts.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Registration: wheelnwater.com
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wheelnwater.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo