wetransfer0[.]uk
“Suspected phishing site | Cloudflare”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
PhishDestroy identifies wetransfer0.uk as an elevated-risk domain engaged in brand impersonation phishing, specifically targeting users of the legitimate file-sharing service WeTransfer. The domain exploits the trusted WeTransfer name to trick visitors into entering credentials or downloading malicious content, posing a direct threat to personal and corporate data security.
This domain was flagged by 20 out of 95 security vendors on VirusTotal, indicating widespread detection across the security community. It is currently active and appears on at least one security blocklist. The domain was created on April 9, 2026, which is suspiciously recent, and is registered through Cloudflare, Inc., a common registrar for both legitimate and malicious sites. The domain resolves to IP address 35.157.26.135, and its SSL certificate is issued by Let's Encrypt (E8), which is frequently abused by phishing operations. Cloudflare itself has flagged the site, displaying a warning page titled "Suspected phishing site | Cloudflare." These combined indicators strongly confirm the domain's malicious intent.
To protect against this specific brand impersonation phishing threat, users should never enter any personal information, passwords, or payment details on wetransfer0.uk. Avoid clicking any links or downloading files from the site. If you have already interacted with the domain, change passwords for any accounts that may have been compromised and monitor for suspicious activity. Report the domain to your email provider or security team. Always verify URLs by checking for subtle misspellings or unusual domain extensions like .uk instead of the official .com. Implement web filtering to block this domain and similar impersonation attempts. PhishDestroy recommends treating all unsolicited file transfer requests with caution and directly navigating to the official WeTransfer website when needed.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | wetransfer0.uk/ |
malware | Detects file containing Telegram Bot API |
| DigiCert UltraDNS | wetransfer0.uk |
malicious | Sinkholed |
| Cloudflare DNS | wetransfer0.uk |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | wetransfer0.uk |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of wetransfer0.uk · checked Apr 9, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога