627web[.]whatsapwcox[.]com
“Whatsapp Web”
Kanıt özeti
627web.whatsapwcox.com is currently resolved to IP 38.55.19.51, an address owned by AS8796 FASTNET DATA INC and located in the United States. The domain was created on 21 February 2026 via the registrar Gname.com Pte. Ltd. and is delegated to the Cloudflare name servers elsa.ns.cloudflare.com and javier.ns.cloudflare.com. No TLS certificate is presented, meaning the service is delivered over plain HTTP only. The HTTP response includes a page title of "Whatsapp Web", directly matching the declared brand target "whatsapp" and confirming the intent to impersonate the messaging platform. VirusTotal analysis shows that 20 of 93 scanning engines flag the domain as malicious, and the site appears on a single external blocklist. PhishDestroy has already taken the domain offline, and the Gridinsoft trust score is 0 out of 100, reinforcing the malicious classification. The observed scam type is listed as "Social Media Phishing", indicating that the infrastructure was likely used to harvest WhatsApp credentials or other personal data.
Infrastructure analysis suggests the attacker used a short‑lived domain, a reputable registrar, and Cloudflare DNS to mask the true hosting environment while still exposing the underlying IP address. The lack of an SSL certificate reduces the credibility of any login interface that may have been served, but the specific "Whatsapp Web" title is a concrete indicator of brand impersonation. The modest number of VirusTotal detections and the presence on only one blocklist imply a brief operational window before the takedown.
Defenders should immediately add 627web.whatsapwcox.com to DNS and proxy blocklists, enforce HTTPS‑only policies to prevent fallback to insecure HTTP, and monitor traffic to the associated IP range (38.55.19.0/24) for any residual connections.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260131-0231F5- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: Illegal Activities section forbids phishing, fraud, fake sites, malware distribution; registrar investigates and may suspend or delete domain
Applicable Laws: Computer Misuse Act 1993 §§3+, Penal Code §§415–420 (cheating), Online Criminal Harms Act (OCHA)
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | 627web.whatsapwcox.com |
malicious | Sinkholed |
| OpenDNS | 627web.whatsapwcox.com |
phishing | Phishing Block |
| Cloudflare DNS | 627web.whatsapwcox.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: whatsapwcox.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain whatsapwcox.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin