drk-whatsapp.hk.cn
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of drk-whatsapp.hk.cn
This domain appears to present itself as a WhatsApp Web login page, using WhatsApp branding, a QR-code sign-in layout, and page metadata that references WhatsApp Web features such as message syncing and end-to-end encryption. The screenshot shows a login flow in Chinese that closely imitates the appearance of the legitimate WhatsApp Web interface.
Based on the domain name and page content, this does not appear to be an official WhatsApp-owned domain. The hostname combines the WhatsApp brand name with unrelated subdomain elements and uses a domain structure that is not commonly associated with Meta's official services. That combination suggests the site may be attempting to mimic a well-known messaging platform rather than operate as an independent service with its own brand identity.
Safety Assessment for drk-whatsapp.hk.cn
Multiple independent signals indicate elevated risk at the time of this scan. The site was categorized by several web-classification providers as phishing or fraud-related, and 21 out of 91 security engines flagged the domain. In addition, the page visually resembles WhatsApp Web and uses the WhatsApp name and interface style on a non-official domain, which may indicate an attempt to collect credentials or session access from visitors.
Although the page-level malware scan did not detect malicious files and some blacklist checks were clean at the time of review, those findings do not outweigh the broader phishing indicators. A valid certificate and a polished login screen can also appear on deceptive sites, so those elements should not be treated as proof of legitimacy.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-08-30. It appears to be served by nginx from an IP hosted on Microsoft Azure Cloud in the East Asia region, with the server geolocated to Hong Kong. DNSSEC appears to be unsigned, which is common but means DNS responses do not benefit from that additional integrity layer.
From a content-loading perspective, the page references local JavaScript and CSS assets along with common third-party libraries from public CDNs. No flagged files or iframes were reported in the page scan, but the main technical concern is not exploit delivery; it is the apparent impersonation of a well-known messaging service on an unrelated domain.
Share your experience with this website. Was it safe? Did you encounter any issues?