wa-whatapp.hl.cn
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of wa-whatapp.hl.cn
This website appears to present itself as a Chinese-language service related to a web-based WhatsApp workflow tool. Based on the page title and visible content, it claims to help users manage multiple WhatsApp web sessions, distribute customer inquiries intelligently, and organize overseas traffic by team or region. The homepage uses product-marketing language and interface elements that resemble a software landing page rather than a personal blog or informational site.
The domain name is notable because it includes a misspelled variation of “WhatsApp” (“whatapp”), while the page content prominently references WhatsApp网页版. That combination may indicate an unofficial third-party tool, a brand-adjacent service, or a look-alike site attempting to benefit from recognition of the WhatsApp name. No clear evidence in the provided scan identifies the actual operator beyond the domain registration and hosting details.
Safety Assessment for wa-whatapp.hl.cn
Several scan signals suggest elevated risk at the time of this scan. The domain was flagged by 14 out of 91 security engines, with many of those detections classifying it as phishing. In addition, the site is extremely new — registered the same day it was scanned — and it is not ranked in major traffic lists. The domain name also closely resembles the WhatsApp brand while using a misspelled form (“whatapp”), which may indicate a look-alike setup intended to create user trust or confusion.
Other signals are mixed but do not outweigh the stronger concerns. A malware scan reported no flagged files, although it did attach a generic suspicious-object label to the domain and one blacklist database also listed it with a generic suspicious designation. Major content-malice blacklist checks shown here were otherwise clean, and the site uses valid HTTPS, but those factors can also appear on newly created phishing pages. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid TLS certificate issued by a mainstream certificate authority, expiring on 2026-10-01. It is hosted behind Cloudflare infrastructure, with the observed server IP resolving to 172.67.198.104 and nameservers set to jim.ns.cloudflare.com and lisa.ns.cloudflare.com. The web server appears to be Cloudflare, and the reported geolocation for the observed edge IP is Toronto, Canada.
From a domain-security perspective, the domain is extremely new and DNSSEC appears to be unsigned. The use of Cloudflare can obscure origin hosting details, which is common for both legitimate and abusive sites. No DNS-based mail-reputation blocklist hits were reported in the provided data, but the combination of same-day registration, brand-like naming, and multi-engine phishing detections remains a significant technical concern at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?