uao-wswhatsapp[.]cc
“whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具”
uao-wswhatsapp.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Google; Тип мошенничества: Social Media Phishing. Сводка доказательств: VirusTotal 16/95 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Регистратор: Dominet (HK).
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On July 23, 2026, the domain uao-wswhatsapp.cc was observed as an offline infrastructure used to impersonate Google in a social‑media phishing campaign. The site was registered on 02 Oct 2025 through Dominet (HK) Limited and resolves to the IPv4 address 103.80.133.70, which belongs to AS205960 operated by HDTIDC LIMITED in South Korea. Four authoritative name servers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname) are configured, but the site lacks an SSL/TLS certificate, indicating that any traffic would be transmitted unencrypted. The page title returned by the server is "whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具", a Chinese phrase unrelated to Google, suggesting that the content has not yet been publicly analyzed.
Gridinsoft assigned a trust score of 0 / 100, and the domain is listed on at least one public blocklist and has been blocked by PhishDestroy. Threat intelligence aggregation services have recorded the domain in 16 AlienVault OTX pulses, and VirusTotal reports 16 of 95 scanning engines flagging the domain as malicious. The combination of a newly created domain, low‑reputation hosting, absence of TLS, and multiple detections points to a high likelihood of credential‑harvesting activity targeting Google users via a purported WhatsApp login interface. However, the exact payload, phishing kit, or compromised accounts remain unknown because the site is offline and no forensic capture of the landing page is available.
Defenders should add uao-wswhatsapp.cc to URL filtering and endpoint allow‑list exclusion rules, monitor DNS queries for the four associated name servers, and enforce strict TLS inspection for outbound traffic to the IP 103.80.133.70. Incident response teams should also correlate any recent Google authentication failures with requests to this domain and consider user‑education campaigns that clarify the mismatch between the Chinese page title and the alleged Google impersonation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание