whats-vip[.]cc
whats-vip.cc — 内容不可用 (HTTP 502). 品牌冒充:WhatsApp; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 18/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain whats-vip.cc indicates a brand-impersonation campaign targeting WhatsApp users, operational from November 17, 2025, until its recent takedown. The domain resolved to the IP address 154.221.25.232, hosted under AS142403 (YISU CLOUD LTD) in Hong Kong. Infrastructure analysis reveals the use of shared nameservers a.share-dns.com, a9.share-dns.com, b.share-dns.net, and b9.share-dns.net, a pattern consistent with low-cost bulletproof hosting setups observed in prior phishing operations. The domain was registered through Gname.com Pte. Ltd., a registrar frequently associated with abusive registrations in Southeast Asia.
No SSL certificate was detected, increasing the likelihood of interception or man-in-the-middle attacks had the site remained active. At the time of assessment, the domain was flagged by 18 of 95 security vendors on VirusTotal, with additional detections recorded by PhishDestroy and a single security blocklist. AlienVault OTX included the domain in two threat intelligence pulses, suggesting prior campaign tracking. Gridinsoft assigned a trust score of 0/100, reflecting high-risk indicators.
The domain’s status is currently offline, though residual DNS records may persist. Defenders are advised to block the IP 154.221.25.232 and associated nameservers at the perimeter, monitor for related domains registered under the same registrar, and review logs for connections to the IP or domain prior to its deactivation. The exact content and delivery mechanism of the phishing kit remain unconfirmed, as no page title or kit identifier was provided in available intelligence. Further investigation into the hosting provider’s network may reveal additional linked infrastructure.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。