Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
one[.]message-whatapp[.]com[.]cn
“WhatsApp网页版 - 多设备登录与脱离手机”
Kanıt özeti
One.message-whatapp.com.cn is a newly registered domain (created 28 July 2026) that resolves to the IPv4 address 192.197.113.111. The domain is delegated to the name servers ns1.kenpains.com and ns2.kenpains.com and was registered through 万商云集(成都)科技股份有限公司. VirusTotal scans show that 12 of 91 security vendors flag the domain as malicious, indicating a consensus of moderate to high confidence in a phishing classification. The domain appears on at least one public blocklist and has been explicitly blocked by the PhishDestroy filtering service, yet it remains listed as active in current observations.
No public SSL certificate information, HTTP status codes, or page titles have been disclosed, limiting insight into the content that is being served. The lack of a known Safe Browsing or OTX entry suggests that the domain has not yet been harvested by those feeds, but the existing vendor detections and blocklist inclusion provide sufficient evidence for immediate mitigation. Defenders should add the domain and its resolving IP address 192.197.113.111 to deny‑list rules across perimeter firewalls, DNS filtering, and endpoint protection suites.
Continuous monitoring of the hosting infrastructure and the two kenpains.com name servers is advised, as any change in resolution could indicate a shift in the underlying command‑and‑control infrastructure. Organizations that rely on WhatsApp‑related communications should educate users about unsolicited messages that reference the domain, and enforce MFA to reduce credential compromise risk. Because the registration details point to a Chinese corporate entity, threat‑intel teams may also consider cross‑referencing other domains registered by the same registrar for patterns of abuse.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260806-45130C- Yakalanan sayfa başlığı
- WhatsApp网页版 - 多设备登录与脱离手机
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | one.message-whatapp.com.cn |
malicious | Sinkholed |
| OpenDNS | one.message-whatapp.com.cn |
phishing | Phishing Block |
| Cloudflare DNS | one.message-whatapp.com.cn |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
İlk kayıt
İlk kayıtlı değer: Erişilebilir
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of one.message-whatapp.com.cn · checked Aug 6, 2026
Site Yapılandırma Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin