7[.]600212[.]xyz
“WhatsApp Web”
7.600212.xyz — Контент недоступний. Уособлення бренду: WhatsApp; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 14/95 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 97/100. Реєстратор: Porkbun.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis as of 23 July 2026 flags the domain 7.600212.xyz as an elevated‑risk brand‑impersonation site targeting WhatsApp users. The domain resolves to 192.253.229.153, an address assigned to AS152194 (CTG Server Limited) in Hong Kong. Registration occurred on 21 May 2025 through Porkbun LLC, using the default Porkbun nameservers (curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, salvador.ns.porkbun.com). No TLS certificate is presented, indicating the site serves only HTTP traffic. The page title returned from the live host was “WhatsApp Web”, matching the declared brand target of WhatsApp and the classified scam type of brand impersonation.
Reputation services provide a uniformly negative rating: Gridinsoft assigns a trust score of 0 / 100, while Scamadviser rates the domain 1 / 100. VirusTotal scans show 14 of 95 antivirus/URL engines flag the domain as malicious, reinforcing the suspicion. The domain appears on a single external blocklist and is listed by PhishDestroy as blocked, confirming that at least one security provider has taken mitigation action. The site is currently offline, limiting immediate threat exposure, yet the infrastructure components remain in place. Uncertainty remains around the specific payload or credential‑harvesting mechanisms, as no page content or HTTP response details have been captured.
Likewise, the presence of any additional command‑and‑control infrastructure or post‑compromise activity cannot be confirmed. Defenders should continue to monitor DNS queries for 7.600212.xyz and the associated IP address, enforce blocklists that include this domain, and consider adding the IP to network‑level deny lists. Organizations that implement WhatsApp Web authentication should educate users about the absence of HTTPS on suspicious URLs and encourage verification of certificate presence.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: 600212.xyz
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain 600212.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога