Phishing detection: canary.static-whatsapp.com

WhatsApp
https://canary.static-whatsapp.com Access site
Screenshot
No screenshot available yet Captured automatically on the next refresh cycle
Investigate
Domain canary.static-whatsapp.com30 CT hosts on apex
URL https://canary.static-whatsapp.com
Phishunt analysis Beta
36 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +3.5 ASN reputation
  • +3.4 Cert reuse
  • +3.4 Shared IP cluster
  • +3.2 Young domain
  • +1.1 No CSP header
  • +0.9 No registrar lock
  • +0.7 Brand in cert SAN
  • +0.7 Unrecognised DNS provider
  • +0.6 Registrar reputation
  • +0.5 Young certificate
  • +0.5 Long domain
  • +0.3 Free CA
  • +0.2 Suspicious TLD
  • +0.1 Hyphens
  • +0.1 Deep subdomain
19 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

WhatsApp impersonation site sharing IP and hosting infrastructure with a companion phishing domain, both operated by Yancy Limited in Hong Kong (ASN 138415). The certificate embeds the WhatsApp brand. Flagged by Google Safe Browsing as social engineering targeting messaging account credentials.

Brand in cert SANGoogle Safe BrowsingASN reputation
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-08 · confidence 83%
Domain & Network
Whois
Network
Country Hong KongHong Kong
Hosting Yancy Limited
ASN AS138415
TLS Cert YR1
External detection Google Safe Browsing
GSB category: SOCIAL_ENGINEERING
CleanOpenPhish · PhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-09-08 05:25 UTC  ·  Last refreshed 2026-09-10 03:30 UTC