Security Scan Report: web.whatsapp.zt.hl.cn

Submitted: Mar 23, 2026, 5:11:47 AMCompleted: Mar 23, 2026, 5:12:59 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 3 HTTP transactions. The main domain is web.whatsapp.zt.hl.cn and was registered NaN years ago.

Submitted URL: https://web.whatsapp.zt.hl.cn/

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Site impersonates Telegram on a newly registered, suspicious domain with malicious indicators; treat as high‑risk phishing.

Risk Factors
Brand impersonation (Telegram branding on non‑Telegram domain)
Malicious domain indicator (hl.cn)
Very new domain (<30 days) with no reputation
High‑severity network IDS alert (Spamhaus DROP list)
Unranked domain in Cisco Umbrella top 1M
Domain age information unavailable

Details

Page Title

web.whatsapp.zt.hl.cn

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

social media network

(52%)

Domain Information

The domain 'web.whatsapp.zt.hl.cn' uses the Chinese country-code top-level domain (.hl.cn) with subdomain 'web.whatsapp'. Count 2 characters in 'zt' holding zero vowels versus 2 consonants. Splitting it apart reveals two words: z, t. Expect 1 character per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://web.whatsapp.zt.hl.cn/

Page Load Overview

2.98s
Total Load Time
5
HTTP Requests
1
Domains
94 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:2,403 chars
Detector Agreement:60%

Website Classification

Primary Category

social media network52% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
52%
technology software
40%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5168.76.146.209South Africa
AS137951ASLINE LIMITED
51--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T128048F77329A063986558498F05B43099F20B143F506C9BCB9BCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:ifQho9PKBb9Js3q9Jzbs6tlg3SBKwdQWgceIszM2bMy8Oldw:ZhoC9JSqzzbs6o3Sj3gcrs42eA+

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:184496:E2EOHADTBA1QS5IeEgbABF5fQkJAOAJoCBCQwEMCkPD+8CNAIgKsSCIaGCkMmYEkMGNSAXIYlKTilHwggjkfgB4EACQMCUEo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc3c7ffffffff
Perceptual Hash:b3318ccccc673333
Difference Hash:00180c1400000000
Wavelet Hash:f0d0c0ccf0f0f0f0
Color Hash:#40b0bf

Other Hashes

Crop Resistant:00180c1400000000

Scan History

Scan history not available

Unable to load historical scan data