Phishing detection: build.comm-whatsapp.com
WhatsApp Investigate
Domain
build.comm-whatsapp.com40 CT hosts on apex
IP
156.234.67.88
URL
https://build.comm-whatsapp.com
Cert
YR1
Phishunt analysis Beta
37
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +6.1 Google Safe Browsing
- +5.3 Keyword match
- +5.1 Site cluster
- +4.0 Young domain
- +3.5 ASN reputation
- +3.4 Cert reuse
- +3.4 Shared IP cluster
- +1.1 No CSP header
- +0.9 Young certificate
- +0.9 No registrar lock
- +0.7 Brand in cert SAN
- +0.7 Bulletproof DNS
- +0.6 Final host mismatch
- +0.6 Registrar reputation
- +0.5 Long domain
- +0.3 Free CA
- +0.2 Suspicious TLD
- +0.1 Hyphens
- +0.1 Deep subdomain
22 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates WhatsApp on a 4-day-old lookalike domain registered through a Chinese registrar. Visitors are redirected to an external consent page, consistent with OAuth phishing. Flagged by Google Safe Browsing as social engineering on Yancy Limited infrastructure in Hong Kong.
Google Safe BrowsingFinal host mismatchYoung domain
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-04 · confidence 65%
External detection
Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Campaign
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise