app-tap-whatsappweb[.]com[.]cn
“WhatsApp網頁版”
app-tap-whatsappweb.com.cn — 内容不可用 (HTTP 502). 品牌冒充:WhatsApp; 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 21/95 (Criminal IP, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, CRDF); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 100/100. 注册商: 四川域趣网络科技有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, app-tap-whatsappweb.com.cn, is identified as a brand impersonation threat targeting WhatsApp users. Analysis indicates the site mimics the official WhatsApp Web portal, presenting a login interface under the title 'WhatsApp網頁版' to deceive users into entering credentials. No crypto drainer or malware payloads were explicitly linked to this domain, but the impersonation tactic aligns with credential harvesting campaigns commonly observed in phishing operations. Infrastructure analysis reveals the following technical indicators: the domain is flagged by 21 out of 95 security vendors on VirusTotal, indicating moderate detection coverage. It was registered through 四川域趣网络科技有限公司 (Sichuan Yugu Network Technology Co., Ltd.) on October 24, 2025, and resolves to the IP address 80.97.160.74, hosted under AS48753 (AVA HOST SRL) in Moldova. The domain lacks an SSL certificate, increasing the likelihood of interception during credential transmission. It appears on one security blocklist and was blocked by PhishDestroy, though no Google Safe Browsing (GSB) entries were recorded at the time of analysis. The domain has since been taken offline, reducing immediate exposure risk. However, the infrastructure remains a potential vector for future campaigns, particularly given the registrar's history of hosting impersonation domains. Users who accessed the site prior to its takedown should assume credential compromise and initiate password resets for associated accounts. Organizations are advised to monitor network logs for connections to 80.97.160.74 and implement domain-based blocking for app-tap-whatsappweb.com.cn to prevent residual access attempts. The elevated risk classification stems from the domain's targeted impersonation of a widely used messaging platform, combined with its low detection coverage on initial deployment.
安全信号
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。