Security Scan Report: who-whatsapp.com.cn

Submitted: Jan 4, 2026, 6:44:25 AMCompleted: Jan 4, 2026, 6:45:47 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 2 HTTP transactions. The main domain is who-whatsapp.com.cn and was registered NaN years ago.

Submitted URL: https://who-whatsapp.com.cn/

AI Security Verdict

High Risk

Confidence: 95%

10
Risk Score

High‑risk phishing site impersonating WhatsApp; do not trust.

Risk Factors
Brand impersonation (WhatsApp) on an unranked, 10‑day‑old domain
Malicious external link to a known phishing domain (bot-whatsapp.com.cn)
Very new domain (<30 days) increases suspicion
Domain not listed in Cisco Umbrella top 1 M (low reputation)
Domain age information unavailable

Details

Page Title

WhatsApp 网页版 - 全球领先的即时通讯平台

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

corporate

(50%)

Domain Information

Within the Chinese country-code top-level domain (.com.cn), 'who-whatsapp.com.cn' is registered while skipping any subdomain. Count 12 characters in 'who-whatsapp' split between 3 vowels and eight consonants; it also includes one hyphen. Splitting it apart reveals 4 words: who, what, s, app. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://who-whatsapp.com.cn/

Page Load Overview

1.60s
Total Load Time
2
HTTP Requests
2
Domains
1 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:1,767 chars
Detector Agreement:50%

Website Classification

Primary Category

corporate50% confidence
Type: static
Method: structural

All Detected Categories

corporate
50%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1156.252.42.11Seychelles
AS9294GNET INC.
1156.252.40.11Seychelles
AS9294GNET INC.
22--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18FD2623660F330262513B2752FAA5B0B6EA5D417C80EDD763ADC06CC8FC2A959D9374E

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:cmhkxhuki9EgeYa10GEwRjKTr3I6c/Ein0WQCl:cmCxhuki9Eg/a10GhKTr3I6c/Ein0FCl

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:30794:BAZ8GQAiApAAuNEMhQoKGDAumSTYUiBIMgISBoMVhhLAUwEUAWaJDqmAD4EIDupWsmW6mAAWgxnw+DAJDEAgATXjGQoVFBAk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data