Phishing detection: transcode.static-whatsapp.com
WhatsApp Screenshot
No screenshot available yet
Captured automatically on the next refresh cycle
Investigate
Domain
transcode.static-whatsapp.com30 CT hosts on apex
IP
156.234.67.88
URL
https://transcode.static-whatsapp.com
Cert
YR1
Phishunt analysis Beta
36
medium suspicion suspiciousheuristic risk score · not a probability
Why?
- +6.1 Google Safe Browsing
- +5.3 Keyword match
- +5.1 Site cluster
- +3.5 ASN reputation
- +3.4 Cert reuse
- +3.4 Shared IP cluster
- +3.2 Young domain
- +1.1 No CSP header
- +0.9 No registrar lock
- +0.7 Brand in cert SAN
- +0.7 Unrecognised DNS provider
- +0.6 Long domain
- +0.6 Registrar reputation
- +0.5 Young certificate
- +0.3 Free CA
- +0.2 Suspicious TLD
- +0.1 Hyphens
- +0.1 Deep subdomain
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Transcode subdomain of static-whatsapp.com, a WhatsApp impersonation cluster at Yancy Limited (Hong Kong, ASN 138415). Certificate is shared across cluster members, the registrar is flagged for abuse, and Google Safe Browsing marks the site as social engineering targeting WhatsApp credentials.
Google Safe BrowsingCert reuseASN reputation
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-08 · confidence 70%
External detection
Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise