wswhts[.]one
“WhatsApp”
Сводка доказательств
This domain, wswhts.one, was registered on 21 February 2026 and is currently offline. Passive DNS shows it resolves to the IPv4 address 192.163.167.170, which belongs to an Antbox Networks Limited network (AS138995) hosted in Hong Kong. The server presents an SSL certificate identified as R13, indicating a low‑trust rating. The only visible HTML element retrieved before takedown was a page title of “WhatsApp”, suggesting a possible attempt to lure users familiar with the messaging service. Threat intelligence categorises the site as a brand‑impersonation campaign targeting the financial services brand Argent.
The campaign’s primary vector appears to be a malicious domain that mimics a legitimate service to harvest credentials or redirect victims, consistent with the “Brand Impersonation” label. Reputation checks show the domain appears on a single public blocklist, PhishDestroy, which has already flagged it as malicious. VirusTotal analysis recorded nine detections out of ninety‑five scanners, confirming that multiple security vendors consider the host suspicious. No additional public blocklists or safe‑browsing services have reported the domain, and no open‑source threat‑intel feeds (OTX, etc.) currently reference it, leaving the broader visibility of the infrastructure uncertain.
Given the limited exposure, defenders should prioritize adding the domain to local deny‑list rules and monitoring outbound DNS queries for the resolved IP address 192.163.167.170. Correlation of network traffic against the Antbox Networks ASN may reveal related campaigns or shared infrastructure. Continuous re‑evaluation of the domain’s status on VirusTotal and other scanning services is advised, as additional detections could emerge. Organizations that use Argent services should educate users about unsolicited requests referencing WhatsApp or similar messaging platforms, and enforce multi‑factor authentication to reduce the impact of potential credential compromise.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | wswhts.one |
phishing | Phishing Block |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание