h5-whatsapp[.]hk[.]cn
“WhatsApp 網頁版 - H5移動端與網頁多端極速登入”
h5-whatsapp.hk.cn — Контент недоступний. Уособлення бренду: WhatsApp; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 21/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 det.; URLScan malicious verdict; Spamhaus DBL_ABUSED_PHISH; PhishDestroy score 98/100. Реєстратор: 北京新网数码信息技术有限公司.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain h5-whatsapp.hk.cn is an active credential theft phishing site that impersonates WhatsApp Web to harvest login credentials from mobile and desktop users. The page title "WhatsApp 網頁版 - H5移動端與網頁多端極速登入" mimics legitimate WhatsApp Web interfaces, targeting users seeking cross-platform messaging access. Infrastructure analysis reveals the domain resolves to IP address 156.239.9.106 and is protected by a Let's Encrypt SSL certificate, which provides a false sense of security.
Evidence of malicious intent is robust. VirusTotal detection shows 17 out of 95 security vendors flag this domain as malicious. The domain was registered on June 30, 2026, through Chinese registrar 北京新网数码信息技术有限公司 (Beijing Xinwang Digital Information Technology Co., Ltd.), a registrar frequently observed in phishing campaigns. No blocklist count was provided in the intelligence, but the high VT detection ratio and active hosting status confirm the threat is live and operational.
Users who visited this site should immediately change their WhatsApp credentials and enable two-factor authentication on their accounts. They should also scan their devices for keyloggers or malware that may have been delivered via the phishing page. Monitoring for unauthorized account access and reporting the incident to their email provider is advised. Security teams should block the domain and IP 156.239.9.106 at the network perimeter to prevent further exposure.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 8 identified
Envoy is an open-source edge and service proxy, designed for cloud-native applications.
www.envoyproxy.io 100% впевненостіApache Traffic Server is an open-source caching and proxying server that serves as an HTTP/1.1 and HTTP/2 reverse proxy with caching capabilities, load balancing, request routing, SSL termination, and support for advanced HTTP features.
trafficserver.apache.org 100% впевненостіTaboola is a content discovery & native advertising platform for publishers and advertisers.
www.taboola.com 100% впевненостіSnowplow is an open-source behavioral data management platform for businesses.
snowplowanalytics.com 50% confidencePubMatic is a company that develops and implements online advertising software and strategies for the digital publishing and advertising industry.
www.pubmatic.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Publisher Tag (GPT) is an ad tagging library for Google Ad Manager which is used to dynamically build ad requests.
developers.google.com 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260703-93092C Recipient: wwdengdai4@gmail.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога