wetransfer0[.]uk
“Suspected phishing site | Cloudflare”
wetransfer0.uk — Acessível · acesso restrito (HTTP 403). Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 20/94 (alphaMountain.ai, Cluster25, CRDF, CyRadar, Emsisoft); URLQuery 4 alerts; PhishDestroy score 95/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies wetransfer0.uk as an elevated-risk domain engaged in brand impersonation phishing, specifically targeting users of the legitimate file-sharing service WeTransfer. The domain exploits the trusted WeTransfer name to trick visitors into entering credentials or downloading malicious content, posing a direct threat to personal and corporate data security.
This domain was flagged by 20 out of 95 security vendors on VirusTotal, indicating widespread detection across the security community. It is currently active and appears on at least one security blocklist. The domain was created on April 9, 2026, which is suspiciously recent, and is registered through Cloudflare, Inc., a common registrar for both legitimate and malicious sites. The domain resolves to IP address 35.157.26.135, and its SSL certificate is issued by Let's Encrypt (E8), which is frequently abused by phishing operations. Cloudflare itself has flagged the site, displaying a warning page titled "Suspected phishing site | Cloudflare." These combined indicators strongly confirm the domain's malicious intent.
To protect against this specific brand impersonation phishing threat, users should never enter any personal information, passwords, or payment details on wetransfer0.uk. Avoid clicking any links or downloading files from the site. If you have already interacted with the domain, change passwords for any accounts that may have been compromised and monitor for suspicious activity. Report the domain to your email provider or security team. Always verify URLs by checking for subtle misspellings or unusual domain extensions like .uk instead of the official .com. Implement web filtering to block this domain and similar impersonation attempts. PhishDestroy recommends treating all unsolicited file transfer requests with caution and directly navigating to the official WeTransfer website when needed.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | wetransfer0.uk/ |
malware | Detects file containing Telegram Bot API |
| DigiCert UltraDNS | wetransfer0.uk |
malicious | Sinkholed |
| Cloudflare DNS | wetransfer0.uk |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | wetransfer0.uk |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of wetransfer0.uk · checked Apr 9, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo