imsites-whatsapp[.]com[.]cn
“WhatsApp 网页版 - 官方入口 - 提供WhatsApp隔离环境长效保障”
imsites-whatsapp.com.cn — Контент недоступний. Уособлення бренду: WhatsApp; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 21/91 (Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 98/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain imsites-whatsapp.com.cn confirms its classification as an active phishing site targeting WhatsApp users. Registered on June 17, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, the domain resolves to IP address 156.239.9.106 and is currently flagged by 21 security vendors on VirusTotal. The page title, 'WhatsApp 网页版 - 官方入口 - 提供WhatsApp隔离环境长效保障,' explicitly references WhatsApp Web, suggesting an attempt to deceive users into believing the site is an official or secure portal for WhatsApp services. The domain appears on one security blocklist and has been included in five threat intelligence pulses on AlienVault OTX, indicating prior detection by the security community. Infrastructure analysis reveals the use of Nginx as the web server, with HSTS and HTTP/3 protocols enabled, which may be employed to lend an appearance of legitimacy. The SSL certificate is issued by Let's Encrypt, a common tactic among phishing sites to avoid browser warnings. Despite these technical measures, the domain has been assigned a trust score of 0/100 by Gridinsoft, reinforcing its malicious classification. Defenders should treat this domain as high-risk and prioritize blocking it at the network level. Given its active status and the presence of WhatsApp branding in the page title, the site is likely designed to harvest credentials or distribute malicious payloads under the guise of an official WhatsApp service. No evidence currently links this domain to a specific phishing kit or broader campaign, but its infrastructure and targeting align with common phishing tactics. Further monitoring is recommended to assess any shifts in its operational behavior or additional indicators of compromise.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of imsites-whatsapp.com.cn · checked Jul 13, 2026
Докази та зовнішні звіти
PD-20260630-D41F36 Recipient: kk989qaz@gmail.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога