whatscoapp[.]com[.]cn
“WhatsApp网页版”
Kanıt özeti
This domain, whatscoapp.com.cn, poses a brand impersonation threat specifically targeting users of WhatsApp Web. Analysis of the page title, 'WhatsApp网页版,' indicates an attempt to deceive visitors into believing they are accessing the legitimate WhatsApp Web interface. Such impersonation schemes are commonly used to harvest login credentials, distribute malware, or facilitate further social engineering attacks by exploiting trust in the targeted brand. The domain’s infrastructure and content are designed to closely mimic the authentic service, increasing the likelihood of successful deception, particularly among users who may not scrutinize the URL or page details closely. Evidence supporting the malicious nature of this domain includes multiple technical indicators. The domain is flagged by 14 out of 95 security vendors on VirusTotal, a significant detection rate that underscores its association with known phishing or fraudulent activity. It was registered on October 18, 2025, through 四川域趣网络科技有限公司, a registrar frequently linked to suspicious or high-risk domains. The domain appears on one security blocklist, further confirming its classification as a threat. Additionally, the domain resolves to the IP address 154.55.246.40, hosted on AS174 (Cogent Communications, LLC) in the United States, a network often utilized for malicious infrastructure due to its accessibility and lack of stringent abuse controls. The absence of an SSL certificate is another red flag, as legitimate services almost universally employ encryption to protect user data. Users who visited whatscoapp.com.cn should take immediate action to mitigate potential risks. If any credentials were entered on the site, those credentials should be changed immediately across all platforms where they may have been reused. Affected users should also scan their devices for malware using updated security tools, as phishing sites often serve malicious payloads. Monitoring financial and communication accounts for unauthorized activity is recommended, particularly if sensitive information was disclosed. To prevent future incidents, users should verify domain names carefully before entering login details and enable multi-factor authentication wherever possible. Organizations should consider blocking this domain and its associated IP address within their security infrastructure to prevent further access by employees or customers.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin