whatsapp-kt.vip
Appeared in the .vip zone on Saturday, September 12, 2026; by the end of that day the census found redirects elsewhere. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Domain uses the WhatsApp brand in its name on a cheap .vip with free DNS (dnsowl) and does nothing but redirect to a wa.me/api.whatsapp.com deep link that opens a chat with an attacker-controlled number (+1 650 764 5100) pre-filled with 'Start verification' under a 'Customer Service' heading — the standard fake WhatsApp support/verification lure to harvest OTP codes and hijack accounts.
The domain whatsapp-kt.vip uses a brand-typosquat name and redirects to api.whatsapp.com with a 'Start verification' flow and phone number parameter, a classic credential/account-takeover phishing pattern. The use of free DNS (dnsowl.com) and the redirect infrastructure designed to impersonate WhatsApp's legitimate verification endpoint confirms malicious intent to deceive users into initiating account verification on a fraudulent domain.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Saturday, September 12, 2026

Same data as JSON: /api/zone/domain/whatsapp-kt.vip. This page is not indexed by search engines and does not link to the site it describes.