who-whatsapp[.]com[.]cn
“WhatsApp Web - 企业级通讯”
who-whatsapp.com.cn — Doğrulanmamış. Marka kimliğine bürünme: WhatsApp; Dolandırıcılık türü: Social Media Phishing. Kanıt özeti: VirusTotal 18/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Kayıt kuruluşu: 四川域趣网络科技有限公司.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain who-whatsapp.com.cn is assessed as a brand impersonation infrastructure impersonating WhatsApp, currently confirmed as offline. The observed page title "WhatsApp Web - 企业级通讯" indicates deliberate mimicry of legitimate messaging services to deceive users into trusting a fraudulent interface. The threat type is classified as brand_impersonation, with intent consistent with credential harvesting or session hijacking workflows.
Telemetry indicates the domain was flagged by 20 of 95 security vendors on VirusTotal, reflecting a significant detection consensus for malicious or deceptive behavior. The domain was registered through 四川域趣网络科技有限公司 and was created on December 25, 2025. It resolves to IP 156.252.40.11, hosted in Hong Kong under AS9294 GNET INC. No SSL certificate is present, increasing interception and spoofing risk. The domain appears on 1 security blocklist, and current status is reported as taken offline via PhishDestroy enforcement actions.
Despite being offline, the infrastructure profile suggests a high-risk impersonation campaign. The combination of WhatsApp branding abuse, lack of TLS encryption, and offshore hosting ASN alignment is consistent with disposable phishing infrastructure. Recommended actions include maintaining the domain in blocklists, preserving DNS and IP indicators (156.252.40.11, AS9294), and correlating with related domains registered under the same registrar. Security teams should deploy proactive detection rules for similar WhatsApp-themed domains, enforce user awareness controls against enterprise messaging impersonation, and monitor for reactivation attempts or cloned infrastructure under alternate TLDs. Continuous threat hunting is advised due to the observed pattern of rapid domain lifecycle turnover and impersonation reuse tactics.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin