Security Scan Report: whatsatapp.hl.cn

Submitted: Mar 27, 2026, 10:32:46 PMCompleted: Mar 27, 2026, 10:33:58 PMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 3 HTTP transactions. The main domain is whatsatapp.hl.cn and was registered NaN years ago.

Submitted URL: https://whatsatapp.hl.cn/

AI Security Verdict

Confirmed Scam

Confidence: 95%

9
Risk Score

Site impersonates WhatsApp on a brand‑new, suspicious domain; classified as confirmed scam.

Risk Factors
Malicious Indicators of Compromise match (hl.cn)
Brand impersonation of WhatsApp on non‑official domain
Brand‑new domain (<7 days) with brand claim
Unranked domain with brand mismatch
Unreachable page indicating possible phishing lure
Domain age information unavailable

Details

Page Title

whatsatapp.hl.cn

Scan Type

public

Language

🇨🇳

Chinese

(60% confidence)

Category

technology software

(29%)

Domain Information

Domain 'whatsatapp.hl.cn' uses the Chinese country-code top-level domain (.hl.cn) while skipping any subdomain. Count 10 characters in 'whatsatapp' with three vowels and seven consonants. Splitting it apart reveals four words: what, s, at, app. Average segment length settles at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://whatsatapp.hl.cn/

Page Load Overview

1.30s
Total Load Time
3
HTTP Requests
1
Domains
3 KB
Total Size

Language Analysis

Primary Language

🇨🇳Chinese
Code: zh
Confidence:60%
Script:Han
Direction:ltr

Detection Details

Language Code:zh
Detection Confidence:60%
Script Type:Han
HTML Lang Attribute:zh-CN
Text Length:3,217 chars
Detector Agreement:50%

Website Classification

Primary Category

technology software29% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3168.76.145.207South Africa
AS137951ASLINE LIMITED
31--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EB048E77329A063986558498F05B43099F20B143F506C9BCB9BCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:VfQho9PKBb9Js3q9Jzbs6tlg3SBKwdQWgceIsz02bMy8Olde:yhoC9JSqzzbs6o3Sj3gcrsQ2eAE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:184471:SCQCIYTEAAAABcEYIYV0awA7AtCAGBsAMGITSyYiWywjUpah2DOowA+gACfiwIcEBqCQFQXkFJDIDEUKiQgACAqC9UoC7dYC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc3cfffffffff
Perceptual Hash:b3318ccccc673333
Difference Hash:00180c1800000000
Wavelet Hash:ffdfc3cf00000000
Color Hash:#563a78

Other Hashes

Crop Resistant:00180c1800000000

Scan History

Scan history not available

Unable to load historical scan data