ws-whatapp[.]com[.]cn
“Suche – Microsoft Bing”
Збережене виявлення
Виявлено маскування
- Тип маскування
bot_redirect_safe- Оцінка маскування
- 4/6
Зведення доказів
This domain is flagged as a high-risk instance of brand impersonation phishing, specifically targeting Microsoft. Analysis indicates the site mimics Microsoft’s search portal, as evidenced by the page title "Suche – Microsoft Bing," a clear attempt to deceive users into believing they are interacting with a legitimate Microsoft service. The domain’s infrastructure and content are designed to exploit trust in the Microsoft brand for malicious purposes, including credential harvesting or malware distribution. Infrastructure analysis reveals the following technical indicators: the domain ws-whatapp.com.cn was registered on May 20, 2026, through 万商云集(成都)科技股份有限公司, a registrar with a history of hosting suspicious domains. It resolves to the IP address 188.114.96.3, associated with CloudFlare, Inc. in Canada, a common tactic to obscure the true origin of malicious traffic. The domain is currently active and employs a Let's Encrypt SSL certificate (E8), which, while providing encryption, does not validate the legitimacy of the site. Security vendors on VirusTotal flagged the domain at a rate of 16/95, indicating moderate consensus among detection engines. It appears on one security blocklist and is blocked by PhishDestroy, further corroborating its malicious classification. To mitigate risks associated with this brand impersonation phishing domain, organizations and users should implement the following measures: immediately block the domain and its resolving IP (188.114.96.3) at the network perimeter using firewalls or DNS filtering. Security teams should update endpoint protection rules to flag or quarantine any attempts to access ws-whatapp.com.cn or related subdomains. User awareness training should emphasize the risks of interacting with domains that mimic official branding, particularly those with slight misspellings or unusual top-level domains. Additionally, monitoring for SSL certificates issued to similar domains (e.g., Let's Encrypt E8) may help identify other impersonation attempts. If credentials or sensitive data were entered on this site, affected accounts should be locked and passwords reset immediately, with multi-factor authentication enabled where possible.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260522-945F8D- Заголовок збереженої сторінки
- Search - Microsoft Bing
- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | ws-whatapp.com.cn |
phishing | Phishing Block |
| Cloudflare DNS | ws-whatapp.com.cn |
malicious | Sinkholed |
| DNS4EU | ws-whatapp.com.cn |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | ws-whatapp.com.cn |
malicious | Sinkholed |
| Hagezi Threat Feed | ws-whatapp.com.cn |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Технології
Виявлено 5 технологій із високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of ws-whatapp.com.cn · checked May 22, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога