uao-wswhatsapp[.]cc
“whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具”
uao-wswhatsapp.cc — 内容不可用 (HTTP 502). 品牌冒充:Google; 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 16/95 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Chong Lua Dao, CyRadar); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. 注册商: Dominet (HK).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
On July 23, 2026, the domain uao-wswhatsapp.cc was observed as an offline infrastructure used to impersonate Google in a social‑media phishing campaign. The site was registered on 02 Oct 2025 through Dominet (HK) Limited and resolves to the IPv4 address 103.80.133.70, which belongs to AS205960 operated by HDTIDC LIMITED in South Korea. Four authoritative name servers (ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com, ns4.domainname) are configured, but the site lacks an SSL/TLS certificate, indicating that any traffic would be transmitted unencrypted. The page title returned by the server is "whatsapp电脑端登录- 如何设置自动回复:提升工作效率的工具", a Chinese phrase unrelated to Google, suggesting that the content has not yet been publicly analyzed.
Gridinsoft assigned a trust score of 0 / 100, and the domain is listed on at least one public blocklist and has been blocked by PhishDestroy. Threat intelligence aggregation services have recorded the domain in 16 AlienVault OTX pulses, and VirusTotal reports 16 of 95 scanning engines flagging the domain as malicious. The combination of a newly created domain, low‑reputation hosting, absence of TLS, and multiple detections points to a high likelihood of credential‑harvesting activity targeting Google users via a purported WhatsApp login interface. However, the exact payload, phishing kit, or compromised accounts remain unknown because the site is offline and no forensic capture of the landing page is available.
Defenders should add uao-wswhatsapp.cc to URL filtering and endpoint allow‑list exclusion rules, monitor DNS queries for the four associated name servers, and enforce strict TLS inspection for outbound traffic to the IP 103.80.133.70. Incident response teams should also correlate any recent Google authentication failures with requests to this domain and consider user‑education campaigns that clarify the mismatch between the Chinese page title and the alleged Google impersonation.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。