Güvenlik raporuna geç
Checked 09.08.2026 Ref F7A6DBBA

MALICIOUS — CRITICAL

whatsaplusazul[.]com

Analysis of whatsaplusazul.com indicates a high-risk phishing domain targeting users seeking modified WhatsApp applications.

100/100 evidence score · Critical
VirusTotal
14/91
Blocklists
No stored match
Kullanılabilirlik
Bilinen son aktif · HTTP 200
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 14. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
Jump to section
Rapor özeti

whatsaplusazul.com — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); CF Radar malicious; PhishDestroy score 100/100. Kayıt kuruluşu: Hosting Concepts.

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Evidence Analysis

Ref F7A6DBBA

whatsaplusazul.com — WhatsApp APK phishing domain report

Analysis of whatsaplusazul.com indicates a high-risk phishing domain targeting users seeking modified WhatsApp applications.

Analysis of whatsaplusazul.com indicates a high-risk phishing domain targeting users seeking modified WhatsApp applications. The domain, registered through Hosting Concepts B.V. d/b/a Registrar.eu, resolves to IP address 31.43.191.219 and is currently active as of July 12, 2026. The page title, 'WhatsApp Plus Azul Descargar APK (Oficial) Última versión 2026,' explicitly promotes a purported official download for a modified WhatsApp client, a common vector for distributing malicious APK files. Infrastructure analysis reveals the use of Cloudflare and HTTP/3, which may complicate detection and takedown efforts. The domain's SSL certificate is issued by Let's Encrypt, a legitimate provider often exploited in phishing campaigns to appear trustworthy. The domain appears on two security blocklists and has been flagged in 15 threat intelligence pulses on AlienVault OTX, suggesting prior malicious activity. While 14 of 95 security vendors on VirusTotal have detected this domain as malicious, the absence of detections from other vendors does not confirm safety. The domain has been blocked by at least two security solutions, further indicating its malicious nature. Defenders should treat this domain as a confirmed phishing threat, particularly for campaigns distributing trojanized APK files. Network-level blocking of 31.43.191.219 and monitoring for related domains using similar naming conventions (e.g., 'WhatsApp Plus' or 'APK Oficial') is recommended. Given the use of Cloudflare, additional scrutiny of traffic patterns and SSL inspection may be necessary to mitigate exposure. The exact payload or infection chain remains unconfirmed, but the domain's intent aligns with historical patterns of mobile malware distribution.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
14 det.
OTX references
DNS Security
4/14
CF Radarı
Zararlı
TLS sertifikası
Let's Encrypt
Gözlemlenen durum
Bilinen son aktif 200
PhishDestroy
DestroyList
Listede
Veri kapsamı12 recorded checks
VirusTotal 14 / 91 URLQuery kontrol edilmedi PhishStats kontrol edilmedi OTX 15 community references CF Radarı provider verdict: malicious URLScan capture not submitted URLScan verdict değerlendirme yok DNS engellemeleri 4/14 TLS valid certificate, 70d WHOIS not parsed Ekran görüntüsü yakalanmadı Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratı
DNS Provider Blocks 4 / 14
Adguard Default Adguard Family Cloudflare Family Cloudflare Security
CF Cloudflare Radar Verdict Zararlı
Phishing Phishing Security threats

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
12/14

Genel Engelleme Listesi Durumu

Etki Alanı Analizi

Alan adı
Sunucu / ASN LiteSpeed · AS210848 Telkom Internet LTD
IP itibarı abuse score 0/100 0 reports checked 08.08.2026
Kayıt kuruluşu Hosting Concepts NL(NL)
IP adresi 31.43.191.219 AZ
Coğrafi konumAZ Baku, AZ
AS210848 · FOP Dmytro Nedilskyi
HTTP Durumu200
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi10.06.2026
Submitted URLhttp://whatsaplusazul.com/
Ad sunucularıkara.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 23.06.2026scanned 09.07.2026
Favicon Hash
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Teknolojiler · 2 identified
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com %100 güven
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org %100 güven
Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

14 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed Previous stored snapshot: 13 detections
alphaMountain.ai
BitDefender
CRDF
CyRadar
ESET
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
MalwareURL
SOCRadar
Sophos
VIPRE
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of whatsaplusazul.com · checked Jul 13, 2026

90
Good
Performance
FCP
2.86s
First Contentful Paint
LCP
2.86s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.3s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Site Yapılandırma Analizi
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.
Sitemap Present · HTTP 200
Valid sitemap observed; total page count is unavailable.
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin
Bu Raporu YerleştirRead-only HTML widget
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/whatsaplusazul.com"
  title="PhishDestroy threat report for whatsaplusazul.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.