whatsapp.nm.hl.cn
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of whatsapp.nm.hl.cn
The domain whatsapp.nm.hl.cn presents itself as a Chinese-language landing page for WhatsApp Web, using the WhatsApp name, logo styling, and messaging-related descriptions such as instant messaging, voice calls, and video meetings. Based on the page title and visible content, it appears to be imitating or referencing the web interface of the well-known WhatsApp communications platform rather than operating as an independent service with its own distinct branding.
The site appears to be hosted on a relatively new subdomain under hl.cn rather than on WhatsApp's commonly recognized official web properties. No clear operator identity is visible in the provided scan data, and the page content shown is promotional rather than a standard login or QR-based web client interface. Based on the domain structure, branding, and page presentation, this website may be attempting to attract users looking for the official WhatsApp Web service.
Safety Assessment for whatsapp.nm.hl.cn
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 17 out of 91 security engines, with many of those detections classifying it as phishing or otherwise malicious. In addition, the domain closely uses the WhatsApp brand name while being hosted on an unrelated subdomain, which may indicate a look-alike or impersonation setup intended to resemble the legitimate messaging service.
Other findings add to the caution. The domain is only 31 days old, has no established traffic ranking, and its IP address is listed on one mail-reputation blocklist. Although the malware scan did not identify malicious files and several threat-database checks were clean at the time of this scan, those clean results do not outweigh the broad phishing consensus from multiple security engines and the strong brand-impersonation pattern visible in the page content.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate expiring on 2026-09-29 and is served over nginx from IP address 154.195.71.90, hosted by Asline Limited in Tseung Kwan O, Hong Kong. DNSSEC appears to be unsigned, and the domain uses the nameservers ns1.kenpains.com and ns2.kenpains.com.
From a technical perspective, HTTPS presence alone should not be treated as a trust signal, since low-cost certificates are commonly used by both legitimate and deceptive sites. The combination of a very new domain, unsigned DNSSEC, limited infrastructure history, and phishing detections across multiple security engines may warrant caution at the time of this scan.
Share your experience with this website. Was it safe? Did you encounter any issues?