uao-wswhatsapp[.]cc
“whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具”
uao-wswhatsapp.cc — Контент недоступний (HTTP 502). Уособлення бренду: Google; Тип шахрайства: Social Media Phishing. Зведення доказів: VirusTotal 16/95 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: Dominet (HK).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
On July 23, 2026, the domain uao-wswhatsapp.cc was observed as an offline infrastructure used to impersonate Google in a social‑media phishing campaign. The site was registered on 02 Oct 2025 through Dominet (HK) Limited and resolves to the IPv4 address 103.80.133.70, which belongs to AS205960 operated by HDTIDC LIMITED in South Korea. Four authoritative name servers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname) are configured, but the site lacks an SSL/TLS certificate, indicating that any traffic would be transmitted unencrypted. The page title returned by the server is "whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具", a Chinese phrase unrelated to Google, suggesting that the content has not yet been publicly analyzed.
Gridinsoft assigned a trust score of 0 / 100, and the domain is listed on at least one public blocklist and has been blocked by PhishDestroy. Threat intelligence aggregation services have recorded the domain in 16 AlienVault OTX pulses, and VirusTotal reports 16 of 95 scanning engines flagging the domain as malicious. The combination of a newly created domain, low‑reputation hosting, absence of TLS, and multiple detections points to a high likelihood of credential‑harvesting activity targeting Google users via a purported WhatsApp login interface. However, the exact payload, phishing kit, or compromised accounts remain unknown because the site is offline and no forensic capture of the landing page is available.
Defenders should add uao-wswhatsapp.cc to URL filtering and endpoint allow‑list exclusion rules, monitor DNS queries for the four associated name servers, and enforce strict TLS inspection for outbound traffic to the IP 103.80.133.70. Incident response teams should also correlate any recent Google authentication failures with requests to this domain and consider user‑education campaigns that clarify the mismatch between the Chinese page title and the alleged Google impersonation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога