123[.]bmt-whatsapp[.]com[.]cn
“WhatsApp Web”
123.bmt-whatsapp.com.cn — 内容不可用. 品牌冒充:WhatsApp; 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 21/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 5 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: 成都垦派科技有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain 123.bmt-whatsapp.com.cn was registered on February 27, 2026 through 成都垦派科技有限公司 and is currently listed as offline. Infrastructure analysis shows the domain resolves to IP address 43.226.17.44, which is owned by BGP Network Limited (AS64050) and geolocated in the Republic of Korea. No TLS certificate is presented for the host, indicating that the service operates without encryption. The authoritative name servers are ns1.kenpains.com and ns2.kenpains.com, both of which are associated with the same registrar.
The page title returned from HTTP requests is "WhatsApp Web," aligning with the observed scam type of Social Media Phishing. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service. VirusTotal scans report that 21 of 93 security vendors have flagged the domain, providing additional confidence in its malicious reputation. While the exact payload or credential‑harvesting mechanism has not been publicly disclosed, the combination of the WhatsApp‑related title, the lack of HTTPS, and the detection history strongly suggest a credential‑stealing campaign targeting WhatsApp users.
Defenders should continue to block DNS resolution for the domain, monitor outbound connections to the associated IP range, and ensure that email and web filters reject any URLs containing the domain or its sub‑domains. Because the site is offline, any ongoing campaigns may have shifted to new infrastructure; threat‑intel teams should watch for similarly patterned domains that reuse the same registrar, name servers, or IP ASN. Continuous re‑evaluation of blocklist status and VirusTotal detection counts is recommended to maintain up‑to‑date protection against this threat vector.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
| OpenDNS | 123.bmt-whatsapp.com.cn |
phishing | Phishing Block |
| Cloudflare DNS | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
| Quad9 DNS | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
| DNS4EU | 123.bmt-whatsapp.com.cn |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260227-06CED7 Recipient: zdn841@sina.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。