whatspp.icu
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of whatspp.icu
The domain whatspp.icu appears to present itself as a WhatsApp Web-related page, using branding, layout, and wording associated with the messaging platform's desktop login flow. The screenshot shows a page titled "Whatsapp" with WhatsApp-style visuals, Chinese-language instructions for linking a device, and a QR-code themed interface intended to resemble a web login or tutorial page.
Based on the domain name and page presentation, this site does not appear to be an official WhatsApp domain. The missing "a" in "whatspp" makes the address closely resemble the well-known WhatsApp brand while differing slightly from the expected spelling, which may indicate an attempt to attract users looking for the legitimate service. No clear operator identity or legitimate business ownership information is visible from the provided scan data.
Safety Assessment for whatspp.icu
Multiple independent signals indicate elevated risk at the time of this scan. The site was categorized by several web-classification providers as phishing or fraud-related, and 21 out of 92 security engines flagged the domain. In addition, the domain closely resembles the WhatsApp brand name and may be a look-alike intended to mislead visitors seeking the legitimate WhatsApp Web service.
The domain is also extremely new, with a reported age of 3 days, which can increase uncertainty and is commonly seen with short-lived phishing infrastructure. While some blacklist databases were clean at the time of this scan, one threat database listed the domain, and the broader multi-engine consensus is notably negative. The malware scan did not report confirmed malicious files, but its generic object labels are lower-confidence signals than the stronger phishing classifications and brand resemblance concerns.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring in August 2026. It appears to be served by nginx from an IP address geolocated to Hung Hom, Hong Kong, with hosting identified as Mega II. The domain uses nameservers on SHARE-DNS infrastructure, and DNSSEC is unsigned.
From a security posture perspective, the combination of a very recently registered domain, unsigned DNSSEC, and a page imitating a major web service raises concern. The scan also noted several internally hosted resources and one external URL associated with the page flow. Although no confirmed malware payloads were identified in the scanned files at the time of analysis, the infrastructure profile does not offset the phishing-related indicators.
Share your experience with this website. Was it safe? Did you encounter any issues?