autoconfig.whatsappengagepro.com - malicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned autoconfig.whatsappengagepro.com and returned a malicious verdict (score 98), categorised as phishing, credential-harvest, impersonating whatsapp. The page resolved to 154.26.128.162 on Cogent Communications in SG. The domain was registered 7 days ago through GoDaddy.com, LLC. 1 domain and 1 IP were contacted, over 11 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 98) · Confidence 100%
- Scanned URL:
https://autoconfig.whatsappengagepro.com/ - Domain: autoconfig.whatsappengagepro.com · IP: 154.26.128.162 · AS141995 · SG
- Server: nginx
- Page title: Brightnous
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: GoDaddy.com, LLC · domain age 7 days · created 2026-08-15
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 20 02: · subject CN=mx1.mailsteward.in
- HTTP requests captured: 11 · cookies set: 1 · outgoing links: 28
- Scan tier: standard · observed 2026-08-22 04:42:45 UTC
Antivirus & YARA (1 of 48 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
Categories
- phishing
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Domain impersonates whatsapp (combosquat)
- Credential-harvesting form
- Domain registered 7 day(s) ago
- Certificate issued < 48h ago
- Matches phishing-kit family "u-admin (uAdmin)"
Detected technologies
- Nginx
Contacted infrastructure
- 154.26.128.162 - AS141995 Cogent Communications (Singapore)
Observed indicators
- autoconfig.whatsappengagepro.com
- 154.26.128.162
- https://autoconfig.whatsappengagepro.com/
- https://autoconfig.whatsappengagepro.com/cache/e9d7abaa5bdece3e1bd297a0acd7d21041e36c05.css
- https://autoconfig.whatsappengagepro.com/css/themes/mailcow-darkmode.css
- https://autoconfig.whatsappengagepro.com/favicon.png
- https://autoconfig.whatsappengagepro.com/img/cow_mailcow.svg
- https://autoconfig.whatsappengagepro.com/?lang=cs-cz
- https://autoconfig.whatsappengagepro.com/?lang=da-dk
- https://autoconfig.whatsappengagepro.com/?lang=de-de
- https://autoconfig.whatsappengagepro.com/?lang=en-gb
- https://autoconfig.whatsappengagepro.com/?lang=es-es
- https://autoconfig.whatsappengagepro.com/?lang=fi-fi
- https://autoconfig.whatsappengagepro.com/?lang=fr-fr
- https://autoconfig.whatsappengagepro.com/?lang=gr-gr
- https://autoconfig.whatsappengagepro.com/?lang=hu-hu
- https://autoconfig.whatsappengagepro.com/?lang=it-it
- https://autoconfig.whatsappengagepro.com/?lang=ko-kr
- https://autoconfig.whatsappengagepro.com/?lang=lv-lv
- https://autoconfig.whatsappengagepro.com/?lang=nb-no
Questions about autoconfig.whatsappengagepro.com
- Is autoconfig.whatsappengagepro.com safe?
- No. MalwareAnalyzer scanned autoconfig.whatsappengagepro.com on 22 Aug 2026 and returned a malicious verdict with a score of 98 out of 100, categorised as phishing and credential-harvest. Treat it as hostile until it is re-checked.
- Does autoconfig.whatsappengagepro.com belong to whatsapp?
- No. This page claims the identity of whatsapp but nothing establishes that whatsapp operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- How was autoconfig.whatsappengagepro.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of autoconfig.whatsappengagepro.com · Other whatsapp phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan