ws-whatapp[.]com[.]cn
“Suche – Microsoft Bing”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
bot_redirect_safe- Gizleme puanı
- 4/6
Kanıt özeti
This domain is flagged as a high-risk instance of brand impersonation phishing, specifically targeting Microsoft. Analysis indicates the site mimics Microsoft’s search portal, as evidenced by the page title "Suche – Microsoft Bing," a clear attempt to deceive users into believing they are interacting with a legitimate Microsoft service. The domain’s infrastructure and content are designed to exploit trust in the Microsoft brand for malicious purposes, including credential harvesting or malware distribution. Infrastructure analysis reveals the following technical indicators: the domain ws-whatapp.com.cn was registered on May 20, 2026, through 万商云集(成都)科技股份有限公司, a registrar with a history of hosting suspicious domains. It resolves to the IP address 188.114.96.3, associated with CloudFlare, Inc. in Canada, a common tactic to obscure the true origin of malicious traffic. The domain is currently active and employs a Let's Encrypt SSL certificate (E8), which, while providing encryption, does not validate the legitimacy of the site. Security vendors on VirusTotal flagged the domain at a rate of 16/95, indicating moderate consensus among detection engines. It appears on one security blocklist and is blocked by PhishDestroy, further corroborating its malicious classification. To mitigate risks associated with this brand impersonation phishing domain, organizations and users should implement the following measures: immediately block the domain and its resolving IP (188.114.96.3) at the network perimeter using firewalls or DNS filtering. Security teams should update endpoint protection rules to flag or quarantine any attempts to access ws-whatapp.com.cn or related subdomains. User awareness training should emphasize the risks of interacting with domains that mimic official branding, particularly those with slight misspellings or unusual top-level domains. Additionally, monitoring for SSL certificates issued to similar domains (e.g., Let's Encrypt E8) may help identify other impersonation attempts. If credentials or sensitive data were entered on this site, affected accounts should be locked and passwords reset immediately, with multi-factor authentication enabled where possible.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260522-945F8D- Yakalanan sayfa başlığı
- Search - Microsoft Bing
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | ws-whatapp.com.cn |
phishing | Phishing Block |
| Cloudflare DNS | ws-whatapp.com.cn |
malicious | Sinkholed |
| DNS4EU | ws-whatapp.com.cn |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | ws-whatapp.com.cn |
malicious | Sinkholed |
| Hagezi Threat Feed | ws-whatapp.com.cn |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Teknolojiler
5 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ws-whatapp.com.cn · checked May 22, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin