whatqsapp[.]us[.]cc
“WhatsApp Web”
证据摘要
This domain is assessed as a brand impersonation infrastructure targeting WhatsApp Web users. The page is configured to visually mimic a legitimate messaging login interface, indicating a credential theft operation designed to capture user authentication data such as phone-linked login sessions or verification codes. The observed threat type is brand impersonation, with a clear focus on deceptive login redirection rather than legitimate service functionality.
Technical indicators confirm malicious classification across multiple sources. VirusTotal reports 17/95 security vendors flagging the domain. The domain was created on February 21, 2026. It resolves to IP 38.54.6.75 hosted under AS138915 Kaopu Cloud HK Limited. SSL certificate is issued as R12. The domain appears on 1 security blocklist and is actively blocked by PhishDestroy. Page title analysis confirms "WhatsApp Web" impersonation content consistent with social engineering infrastructure.
The domain is currently taken offline, reducing active exposure; however, historical indicators suggest prior operational phishing capability. Residual risk remains due to potential clone infrastructure reuse or mirrored deployments under similar domains. Recommended response actions include credential rotation for any accounts entered, verification of active WhatsApp sessions, and review of linked device authorizations. Network defenders should maintain blocklist entries for the IP 38.54.6.75 and monitor for related domains using similar naming patterns to prevent re-establishment of the campaign.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控