hub-whats-whatapp.com.cn
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of hub-whats-whatapp.com.cn
The domain hub-whats-whatapp.com.cn appears to be a newly registered website using a name that resembles the WhatsApp brand while altering the spelling to "whatapp" and adding extra words such as "hub" and "whats." Based on the visible homepage, the site does not currently present a functioning public service or business offering. Instead, it shows a sparse Chinese-language placeholder page stating that the site has not been configured and includes a link to an administrative backend.
The broader link structure associated with this domain references multiple similarly named subdomains and related domains using repeated "whatapp" and "whatssapp" patterns. That naming pattern may indicate an interconnected infrastructure rather than a standalone informational website. Based on the available content and domain naming, the site does not appear to represent an established official service operator at the time of this scan.
Safety Assessment for hub-whats-whatapp.com.cn
This domain shows several notable risk indicators at the time of this scan. It was flagged by 15 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. The domain name also closely resembles the WhatsApp brand while using altered spelling, which may indicate a look-alike setup intended to confuse visitors. In addition, the domain is extremely new, with a registration age of 0 days, and it has no established traffic ranking.
Although the malware scan did not identify flagged files in the sampled content, that result should be interpreted cautiously because the visible page is only a minimal placeholder and may not reflect the full intended use of the domain. Blacklist checks were mixed: major content-threat databases listed here were clean at the time of this scan, but the domain's IP address was listed on one mail-reputation blocklist, which is a weaker but still relevant cautionary signal.
Taken together, the combination of multi-engine phishing detections, brand-like naming, and very recent registration materially increases risk. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site is using a valid Let's Encrypt SSL certificate that was set to expire on 2026-11-15. A valid certificate helps encrypt traffic in transit, but it does not by itself indicate legitimacy. The server is hosted on IP address 192.197.113.111 in Seoul, South Korea, with the hosting/provider field identified as IP Transit. The web server software and supported protocol details were not identified in the scan data.
From a domain-security perspective, DNSSEC appears to be unsigned, which means DNS responses may lack an additional layer of authenticity protection. The domain was registered very recently and uses nameservers ns1.kenpains.com and ns2.kenpains.com. The homepage currently appears to be an unconfigured site with an exposed administrative path reference, which may suggest incomplete deployment or temporary staging infrastructure.
Share your experience with this website. Was it safe? Did you encounter any issues?