Phishing detection: whatsapp-inv.icu

WhatsApp
https://whatsapp-inv.icu Access site
Screenshot
Screenshot of whatsapp-inv.icu
Phishunt analysis Beta
35 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +4.5 Brand in title
  • +4.1 Brand in screenshot
  • +4.0 Young domain
  • +3.7 Brand in domain label
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +0.9 Young certificate
  • +0.9 No registrar lock
  • +0.9 Suspicious TLD
  • +0.7 Brand in cert SAN
  • +0.7 Unrecognised DNS provider
  • +0.6 Registrar reputation
  • +0.3 Free CA
  • +0.3 Long domain
  • +0.1 Hyphens
  • +0.1 External scripts
20 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

One-day-old domain embedding the WhatsApp brand name, registered on an abuse-prone .icu TLD and flagged by Google Safe Browsing as social engineering. Hosted on ALEXHOST SRL infrastructure, it appears designed to harvest WhatsApp credentials or account data.

Google Safe BrowsingBrand in domain labelYoung domain
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-11 · confidence 79%
Domain & Network
Whois
Network
Country United StatesUnited States
Hosting ALEXHOST SRL
ASN AS200019
TLS Cert YR2
External detection Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io · SANS ISC
Report this phishing

Tracked from 2026-09-11 17:25 UTC  ·  Last refreshed 2026-09-13 03:30 UTC