Criticalscore 83 · flagged Friday, September 18, 2026

whatsappdep.shop

Appeared in the .shop zone on Friday, September 18, 2026; by the end of that day the census found active website about saas & tech. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

brand in the name
matched: whatsapp
+30
brand name behind Cloudflare
matched: cloudflare.com
+6
brand name at a retail registrar
matched: GNAME.COM PTE. LTD.
+8
brand name at a watch-list registrar
matched: GNAME.COM PTE. LTD.
+6
brand name and brand-styled page
matched: whatsapp
+15
form on a brand-styled page
matched: has_form
+18
Registrar
GNAME.COM PTE. LTD.
Nameserver provider
Nameservers
magdalena.ns.cloudflare.com, ruben.ns.cloudflare.com
First-day state
active website
HTTP status
200
Page title
WhatsApp Desktop for Windows - Download it from Uptodown for free
Has a form
yes
Brand echoed
whatsapp

Model opinions

Second opinionlooks like abusetarget: WhatsAppconfidence 78%· claude-opus-5

The domain 'whatsappdep.shop' (WhatsApp desktop) serves a verbatim clone of Uptodown's 'WhatsApp Desktop for Windows' download page, including its review/download counts, with no offsite links to the real Uptodown or WhatsApp — the classic fake-installer download page whose only plausible purpose is delivering a trojanised 'WhatsApp Desktop' binary under a brand-squat name.

First passlooks like phishingtarget: WhatsAppconfidence 92%· claude-haiku-4-5

The domain whatsappdep.shop impersonates WhatsApp with a typosquat name and hosts a form (credential capture) on a page falsely titled as an Uptodown download page for WhatsApp Desktop. The page text mimics legitimate app-store content (mentioning QR-code login, reviews, version numbers) to establish false credibility, but the actual domain and .shop TLD are not WhatsApp's infrastructure; the form posts to itself with no offsite links (sealed-room phishing shape), designed to harvest credentials

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, September 18, 2026

Screenshot of whatsappdep.shop taken by the zone census on 2026-09-18

Same data as JSON: /api/zone/domain/whatsappdep.shop. This page is not indexed by search engines and does not link to the site it describes.