Phishing detection: me.h5-whatsapp-zn.hl.cn

WhatsApp
https://me.h5-whatsapp-zn.hl.cn Access site
Screenshot
Screenshot of me.h5-whatsapp-zn.hl.cn
Investigate
Domain me.h5-whatsapp-zn.hl.cn1 CT host on apex
URL https://me.h5-whatsapp-zn.hl.cn
Phishunt analysis Beta
26 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +4.5 Brand in title
  • +4.1 Brand in screenshot
  • +3.0 OpenPhish
  • +1.7 Shared IP cluster
  • +1.1 ASN reputation
  • +1.1 Cert reuse
  • +1.1 No CSP header
  • +1.0 Site cluster
  • +0.7 Brand in cert SAN
  • +0.7 Bulletproof DNS
  • +0.6 Suspicious TLD
  • +0.5 Young certificate
  • +0.5 Long domain
  • +0.3 Free CA
  • +0.3 Deep subdomain
  • +0.2 Hyphens
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonates WhatsApp via a Chinese-hosted domain on Hong Kong infrastructure under HDTIDC LIMITED, using the brand in the TLS certificate and page title. Flagged as malicious by OpenPhish, it exhibits keyword patterns and subdomain depth consistent with credential harvesting.

Brand in titleBrand in cert SANOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-23 · confidence 62%
Domain & Network
Whois
Network
Country Hong KongHong Kong
Hosting HDTIDC LIMITED
ASN AS136038
TLS Cert YR1
External detection OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-08-23 01:03 UTC  ·  Last refreshed 2026-08-31 09:30 UTC