Phishing detection: me.h5-whatsapp-zn.hl.cn
WhatsApp Investigate
Domain
me.h5-whatsapp-zn.hl.cn1 CT host on apex
IP
192.197.113.111
URL
https://me.h5-whatsapp-zn.hl.cn
Cert
YR1
Phishunt analysis Beta
26
low suspicionheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +4.5 Brand in title
- +4.1 Brand in screenshot
- +3.0 OpenPhish
- +1.7 Shared IP cluster
- +1.1 ASN reputation
- +1.1 Cert reuse
- +1.1 No CSP header
- +1.0 Site cluster
- +0.7 Brand in cert SAN
- +0.7 Bulletproof DNS
- +0.6 Suspicious TLD
- +0.5 Young certificate
- +0.5 Long domain
- +0.3 Free CA
- +0.3 Deep subdomain
- +0.2 Hyphens
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site impersonates WhatsApp via a Chinese-hosted domain on Hong Kong infrastructure under HDTIDC LIMITED, using the brand in the TLS certificate and page title. Flagged as malicious by OpenPhish, it exhibits keyword patterns and subdomain depth consistent with credential harvesting.
Brand in titleBrand in cert SANOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-23 · confidence 62%
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise