who-whatsapp[.]com[.]cn
“WhatsApp Web - 企业级通讯”
who-whatsapp.com.cn — Неперевірений. Уособлення бренду: WhatsApp; Тип шахрайства: Social Media Phishing. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); Spamhaus DBL_PHISH; PhishDestroy score 95/100. Реєстратор: 四川域趣网络科技有限公司.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain who-whatsapp.com.cn is assessed as a brand impersonation infrastructure impersonating WhatsApp, currently confirmed as offline. The observed page title "WhatsApp Web - 企业级通讯" indicates deliberate mimicry of legitimate messaging services to deceive users into trusting a fraudulent interface. The threat type is classified as brand_impersonation, with intent consistent with credential harvesting or session hijacking workflows.
Telemetry indicates the domain was flagged by 20 of 95 security vendors on VirusTotal, reflecting a significant detection consensus for malicious or deceptive behavior. The domain was registered through 四川域趣网络科技有限公司 and was created on December 25, 2025. It resolves to IP 156.252.40.11, hosted in Hong Kong under AS9294 GNET INC. No SSL certificate is present, increasing interception and spoofing risk. The domain appears on 1 security blocklist, and current status is reported as taken offline via PhishDestroy enforcement actions.
Despite being offline, the infrastructure profile suggests a high-risk impersonation campaign. The combination of WhatsApp branding abuse, lack of TLS encryption, and offshore hosting ASN alignment is consistent with disposable phishing infrastructure. Recommended actions include maintaining the domain in blocklists, preserving DNS and IP indicators (156.252.40.11, AS9294), and correlating with related domains registered under the same registrar. Security teams should deploy proactive detection rules for similar WhatsApp-themed domains, enforce user awareness controls against enterprise messaging impersonation, and monitor for reactivation attempts or cloned infrastructure under alternate TLDs. Continuous threat hunting is advised due to the observed pattern of rapid domain lifecycle turnover and impersonation reuse tactics.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога