Threat Hunting

Roster of tracked hunts and campaigns — each anchored to a deterministic structural fingerprint, a YARA rule, an SMQL query, or a TLS certificate. Every scanned script and page is matched against this roster automatically.

176 hunts32,294 total sightings
highother
BlueMoon - brand-lookalike lure domains (aerospace, defence, industrial) A
family: bluemoon-shadowpad-2026-09

Lookalike domains registered by the actor against real aerospace/defence/industrial brands on cheap TLDs (.fit .ink .lol .online .site). Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.

0 sightings0 hosts
criticalother
BlueMoon / ShadowPad - C2 host contacted by a scanned page
family: bluemoon-shadowpad-2026-09

A scanned page that CONTACTS the actor's infrastructure - the compromised-victim case, rather than someone scanning the C2 itself. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.

0 sightings0 hosts
highother
BlueMoon - brand-lookalike lure domains (aerospace, defence, industrial) B
family: bluemoon-shadowpad-2026-09

Second half of the lookalike set; split only to stay under the SMQL 20-node cap. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.

0 sightings0 hosts
highother
ShadowPad-style self-signed certificate claiming a major brand (tripwire)
family: bluemoon-shadowpad-2026-09

Generalizing tripwire, not an IoC: ShadowPad C2 servers in this campaign present SELF-SIGNED TLS certificates whose subject organization impersonates a major brand. This catches infrastructure we have no indicator for yet. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.

0 sightings0 hosts
criticalother
BlueMoon / ShadowPad - C2 and staging domains
family: bluemoon-shadowpad-2026-09

A scan whose entry or final URL is on the actor's own C2 / payload-staging infrastructure, or that resolves to 79.133.56.90. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.

0 sightings0 hosts
criticalother
BlueMoon / ShadowPad - Cloudflare Workers C2 tenants
family: bluemoon-shadowpad-2026-09

The actor's Cloudflare Workers C2 endpoints, by TENANT. Indicators from Proofpoint's "Once in a BlueMoon" report (2026-09) and MISP event 22904. SMQL hunts are DETECTORS, not verdict rules: match_tier 'smql' is excluded from both engines' verdict paths by design, so this collects sightings and shows a banner. Flooring for these indicators comes from the MISP feed via ioc-matcher.

1 sightings0 hosts2026-09-12
criticalphishing
RCFH AiTM toolkit — .digital proxy cohort (Payroll Pirates / Storm-2755)
family: rcfh-aitm-storm2755

The older, pre-rotation naming generation of the same AiTM authentication proxy: seven .digital domains built from generic corporate-sounding compounds, several with a hyphen inserted mid-word to dodge string matching (wisemediapa-ttern, xsyst-emsquantum, tec-hnoplatform2025). Arctic Wolf tied these back to the toolkit because they exposed the same /st_58200519/class_identifier.php fingerprinting path as the current 'ms'-labelled generation, despite sharing none of its naming conventions. All were reported defunct as of 2026-07-30.

0 sightings0 hosts
criticalphishing
RCFH AiTM toolkit — redirector & proxy root domains (Payroll Pirates / Storm-2755)
family: rcfh-aitm-storm2755

Adversary-in-the-middle credential/session theft feeding payroll-diversion BEC, overlapping the cluster Microsoft tracks as Storm-2755. Chain: voicemail-themed mail with subject '[Organization] :ATTN: Review messages. Ref id: [random]' -> redirect laundered through Google Meet linkredirect, Google Ads /ddm/clk/ click trackers and an S3 intermediary -> an 'idp.'-labelled Apache redirector 302s to the AiTM proxy -> the proxy bounces the victim once to /st_58200519/class_identifier.php to fingerprint the browser and cache a country code in an rcfh_country cookie -> the proxy relays the genuine login.microsoftonline.com flow, rewriting Microsoft's endpoints into its own path, and captures the authorization code and ID token at its callback. Post-compromise the actor signs in from residential proxies on an eight-hour cadence keeping one SessionID across ASNs, enumerates payroll/HR/finance staff over Microsoft Graph with an axios/1.18.1 user agent, and reads mail on payroll, invoices, banking and benefits.

0 sightings0 hosts
mediumphishing
RCFH AiTM toolkit — Hostinger hosting IPs (Payroll Pirates / Storm-2755, low-confidence)
family: rcfh-aitm-storm2755

The seven Hostinger addresses that served the published redirectors and AiTM proxies. Redirectors: 187.124.129.44 (idp.keyreniao.com), 194.5.157.204 (idp.korminel.com), 145.223.100.123 (idp.kualabemo.com). Proxies: 153.92.1.166 (mslogin.milocaroline.com), 31.97.76.103 (msauth.monlinelogicaline.com), 177.7.56.248 (msonline.logicalineonline.com), 72.62.0.181 (office.ofreace.com and office.ofercarc.com, two proxies co-located).

0 sightings0 hosts
criticalphishing
AiTM reverse proxy — Microsoft endpoints rewritten into the attacker's path
family: aitm-proxy-url-rewrite

Toolkit-agnostic detection for the structural artefact every Evilginx-style AiTM proxy leaves behind. A real AiTM relay does not clone the Microsoft sign-in page — it forwards the genuine flow and rewrites the URLs in the response, so Microsoft's own endpoints end up embedded in the PATH of the attacker's origin: https://<attacker>/https://login.microsoftonline.com/common/GetCredentialType, .../common/login, .../common/SAS/BeginAuth, .../common/SAS/EndAuth. Because the page is the real Microsoft page, brand-similarity, favicon, screenshot-hash and OCR checks all agree it looks legitimate — which is exactly why the rewriting artefact, rather than the page's appearance, is the thing to key on.

0 sightings0 hosts
highphishing
Microsoft-auth subdomain labels on non-Microsoft apexes (AiTM infrastructure tripwire)
family: ms-auth-subdomain-label

Forward-looking tripwire for the naming convention the Payroll Pirates AiTM proxies used, rather than for the burned domains themselves. Arctic Wolf observed the proxy tier consistently fronted by a Microsoft-themed leftmost label — mslogin., msonline., msauth. — on a freshly registered, otherwise meaningless apex, with the redirector tier one step back on an idp. label. This anchor catches the next rotation of that convention rather than the last one, which matters here because the published domains were all under ten days old when used and are all now suspended.

2 sightings0 hosts2026-09-01
highphishing
Prove / small-financial-brand phishing framework (panelFronts devtools-trap kit)
family: prove-financial-framework-202608

Shared phishing framework documented by urlscan 2026-08-04, deployed against deliberately LOW-PROFILE financial and identity brands rather than megabrands: Prove (identity verification), US Bank SinglePoint, AMINA E-Banking, Currency Cloud, Pleo, Slim CD, PayMongo, Aspire. Cloudflare-fronted, several hosts sharing a nameserver pair. Anchored on the kit-unique global __panelFrontsDevtoolsTrapStarted__ (a devtools-detection-trap guard) — a framework identifier coded into the kit logic, so it survives host rotation and minification, unlike IP/domain/hash IoCs.

0 sightings0 hosts
criticalphishing
DOUBLECUP — delivery domains & CountLoader C2 (SMQL tracker)
family: doublecup-clickfix-laas

DOUBLECUP delivery domains and CountLoader C2

0 sightings0 hosts
criticalphishing
DOUBLECUP — CRM-brand phishing lures (SMQL tracker)
family: doublecup-clickfix-laas

CRM-brand phishing pages that inject DOUBLECUP

0 sightings0 hosts
criticalphishing
DOUBLECUP ClickFix Loader-as-a-Service (CountLoader / DeviceManager RAT)
family: doublecup-clickfix-laas

Rented ClickFix delivery service active since June 2026. Operators embed a fixed frontend snippet into their own lure pages; DOUBLECUP hosts the steganographic PNG, the session endpoints and the encryption keys. Stage 1 is a clipboard command that finds the cached PNG by exact file size and carves an embedded script out of it, so nothing is downloaded at execution time. Stage 2 derives its decryption key from the victim's public IP, meaning the payload will not decrypt in an offline sandbox. Observed payloads: CountLoader 4.5p (Windows PowerShell and macOS Mach-O) and DeviceManager, a Python RAT that resolves C2 from Ethereum/Polygon smart contracts (EtherHiding) and tunnels over DNS using microsoft.com as a decoy apex.

0 sightings0 hosts
criticalphishing
CaptiveCrunch — Midnight Blizzard (Storm-2945) traveler-targeting infrastructure
family: captivecrunch-storm2945

Microsoft-reported campaign (2026-07-31): Storm-2945 (Midnight Blizzard / SVR) manipulates hospitality captive-portal traffic to deliver fake browser/OS updates (CornFlake RAT, ChocoShell stealer) and steal Microsoft 365 credentials via device-code-flow and AiTM phishing. Anchors: campaign domains (incl. statistic-g.com, community DNS pivot), C2/AiTM IPs, and the FruitStone operator-panel title "CloudSync Console".

10 sightings0 hosts2026-08-02
highphishing
Meta 'Page Appeal' kit — sp*ct-biz8 pages.dev host cohort (SMQL tracker)
family: meta-page-appeal

Cloned Meta/Facebook 'Page Appeal' credential-phishing kit deployed across a burst of throwaway Cloudflare Pages hosts with the naming scheme sp[1-6]ct-<word>-biz8-<word>-<word>.pages.dev (55+ distinct hosts, 2026-07-20 onward). Decoy variants render a fake Facebook homepage (title 'Facebook', real fbcdn assets) or are already Cloudflare-blocked ('Suspected Malware | Cloudflare' interstitial). Real captures carry the kit React bundle and are verdict-floored by the sibling content anchors (#158 content_sha256 0693dd46…, #153 AST). This SMQL row tracks the full host cohort INCLUDING interstitial/decoy captures no JS anchor can reach; smql tier is verdict-inert by design.

3,891 sightings58 hosts2026-09-12
highother
Crypto task-scam (刷单) app — bd0b60a8 module (content anchor)
family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

3 sightings1 hosts2026-07-17
ast: bd0b60a810012d88
highother
Crypto task-scam (刷单) app — 2c314cb4 module (content anchor)
family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

3 sightings1 hosts2026-07-17
ast: 2c314cb42a98988c
highother
Crypto task-scam (刷单) app — 2ccf4896 module (content anchor)
family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

3 sightings1 hosts2026-07-17
ast: 2ccf48967b4c5ded
highother
Crypto task-scam (刷单) app — 5fa7c18e module (content anchor)
family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

3 sightings1 hosts2026-07-17
ast: 5fa7c18e20c861d3
highother
Crypto task-scam (刷单) app — 2053752f module (content anchor)
family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

3 sightings1 hosts2026-07-17
ast: 2053752fb505847d
highother
Crypto task-scam (刷单) app — b516ab02 module (content anchor)
family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

3 sightings1 hosts2026-07-17
ast: b516ab021db8c5a6
highother
Crypto task-scam (刷单) app — a76e9b67 module (content anchor)
family: crypto-task-scam-appflow

Client-rendered uni-app/Vue H5 crypto task-order scam (刷单): deposit USDT (TRC20), earn commissions on tasks, invite-code pyramid. Renders BLANK so screenshot/OCR/forms are empty. Anchored on rebuild-stable canonical_ast_hash (Vite content-hashed filenames + bundle hashes rotate per deploy; AST survives). Verified corpus-distinct: each hash appears ONLY in webapp-run.us scans.

3 sightings1 hosts2026-07-17
ast: a76e9b6733f3009f
highphishing
Meta 'Page Appeal' kit — 0693dd46 bundle cohort (content anchor)
family: meta-page-appeal

Facebook/Meta Business Page-Appeal credential-phishing kit — NEW bundle cohort (rotated JS hash) not covered by the main.ca88c9b6.js / main.c3146523.js sibling anchors. Same 3-way datacenter cloaking (redirect to real facebook.com / blank decoy / lure); the 0693dd46 segment is present across all capture variants — Facebook-decoy title (232 hosts), 'Meta for Business | Page Appeal' lure (77), Cloudflare Suspected-Phishing interstitial. Byte-identical kit bundle, zero legit titles.

5,029 sightings3,034 hosts2026-09-12
sha256: 0693dd46a180a448
highphishing
Poczta (Polish WP webmail) phishing kit — page YARA (content anchor)
family: poczta-webmail-kit-202607

YARA content anchor for the Poczta webmail credential-phishing kit (sibling of tlsh/smql hunt #146). Custom authForm harvesting login/pass to first-party /api/login then redirecting to the real brand. Live auto-collection via trg_hunt_sightings_record_yara.

32 sightings8 hosts2026-07-23
highphishing
Meta 'Page Appeal' kit — main.c3146523.js cohort (content anchor)
family: meta-page-appeal

Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.

13 sightings13 hosts2026-08-13
sha256: 89c501a71b46639c
ast: 91fc3a6e6301b888
highphishing
Meta 'Page Appeal' kit — main.ca88c9b6.js cohort (content anchor)
family: meta-page-appeal

Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.

10 sightings10 hosts2026-07-07
sha256: 2b5db72551589782
ast: eb1c23db55521501
highphishing
Meta 'Page Appeal' kit — main.1580aa47.js cohort (content anchor)
family: meta-page-appeal

Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.

3,622 sightings2,052 hosts2026-09-12
ast: c2ea845495b8c22f
highphishing
Meta 'Page Appeal' kit — main.a1eb3a24.js cohort (content anchor)
family: meta-page-appeal

Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.

1,292 sightings861 hosts2026-09-12
ast: 888ece076fc7f15f
highphishing
Meta Verified 'rewards' phishing kit — utils.js exfil (content anchor)
family: meta-verified-rewards

Facebook/Meta 'Meta Verified — rewards for you' credential-phishing campaign on disposable hosting (safe-badge-*/bluetick-* pages.dev tenants). A distinct kit from the Meta Page-Appeal campaign, luring users with a fake paid-verification reward. Anchored on the residential-capture lure title.

24 sightings17 hosts2026-08-25
sha256: 5c4343f0588b034e
ast: 511fdccc5b797957
highphishing
Meta Verified 'rewards' phishing (safe-badge kit)
family: meta-verified-rewards

Facebook/Meta 'Meta Verified — rewards for you' credential-phishing campaign on disposable hosting (safe-badge-*/bluetick-* pages.dev tenants). A distinct kit from the Meta Page-Appeal campaign, luring users with a fake paid-verification reward. Anchored on the residential-capture lure title.

412 sightings0 hosts2026-09-12
highphishing
Meta 'Page Appeal' credential phishing (scanner-cloaked)
family: meta-page-appeal

Facebook/Meta 'Business — Page Appeal' credential-phishing campaign on disposable hosting (pages.dev/vercel/netlify/workers). The kit cloaks scanners three ways — redirecting datacenter IPs to real facebook.com, serving them a blank decoy shell, or showing the lure directly — while residential clients always get the Meta-branded appeal lure. Anchored on the residential-capture title so all three capture variants are tracked together.

4,932 sightings0 hosts2026-09-12
highphishing
Poczta (Polish webmail) phishing kit — page content-hash
family: poczta-webmail-kit-202607

Byte-identical Polish-webmail ("Poczta") credential-phishing kit deployed across many throwaway *.vercel.app gibberish subdomains. Anchor = exact page TLSH (fuzzy_hashes->>tlsh); same ssdeep + favicon mmh3 -75849909. Generalizes across the campaign (caught 6 hosts at creation vs the 2 in hunt #145). Rule engine rates these low (known FN class); AI flags HIGH_RISK credential phishing. NOTE: smql/tlsh anchor is backfill-only (no live trigger) — re-backfill to catch new hosts, or add a YARA rule for live auto-collection. Provenance: 2026-07-02 health-alert verdict audit.

24 sightings5 hosts2026-07-23
highphishing
Webmail & brand credential-phishing kits (2026-07-02 audit)
family: credential-phishing-kits-202607

5 credential-phishing hosts confirmed TP in the 2026-07-02 health-alert verdict audit: webmail/Poczta login clones on throwaway hosting (hfmthsga.vercel.app, pljnsad.vercel.app, mid-scarlet-rqxuosjc.edgeone.dev, pub-<hash>.r2.dev), plus meritking2542.com (MeritKing casino brand-abuse). All render a password form; actions self-POST / javascript: / blob-with-embedded-target-email. smql-tier anchor (does not drive verdicts).

29 sightings5 hosts2026-08-18
criticalphishing
Cloudflare Workers Phishing Kits (device-code / EvilToken & brand lures)
family: cloudflare_workers_phishing

High-risk phishing kits hosted on Cloudflare Workers (*.workers.dev) — disposable gibberish-subdomain hosts impersonating brands (Adobe / Microsoft / DocuSign / GitHub / banks). Includes form-less device-code / OAuth-consent (EvilToken-style) kits that lure victims into authorising a Microsoft device code on the real identity provider, plus credential-harvest clones. Anchored on the throwaway platform + the AI malice verdict, so it captures the family without per-site rules.

6,074 sightings24 hosts2026-09-12
lowbenign
Microsoft Attack Simulation Training
family: microsoft-attack-simulator

Microsoft Defender for O365 "Attack simulation training" — Microsoft-owned decoy domains serving Microsoft-branded login pages for phishing-awareness testing. Benign; tracked for inventory only. Whole fleet shares one TLS cert (issuer Microsoft Corporation, CN www.attemplate.com, 131 SANs). Forward-collected via the tls_certificates trigger + security-analyzer cert classifier.

59 sightings54 hosts2026-09-12
criticalphishing
ClickFix FakeCAPTCHA — LOLBin variant (msiexec/mshta/wmic/etc.)
family: clickfix-fakecaptcha

Same fake-CAPTCHA flow as the PowerShell variant but the copied command is a non-PowerShell Windows LOLBin (msiexec /i <URL>, mshta, wmic, certutil, regsvr32, curl, iex, Invoke-Expression). First validated live on 00c29c34fd.nxcli.io from threatfox's IClickFix-tagged feed (scan 52b189eb / 2f465516 / f6c071f8). Markup-tolerant string matchers (<b>R</b> / <b>V</b> / <b>Enter</b>) catch kits whose instruction text is HTML-formatted.

7 sightings3 hosts2026-08-26
criticalphishing
ClickFix FakeCAPTCHA — PowerShell variant
family: clickfix-fakecaptcha

Fake-CAPTCHA HTML page that copies a `powershell -enc <base64>` command to clipboard for the victim to paste into Win+R. Social-engineering pretext: "Verify you are human" / "Not a robot" / "Verification Steps" / "Press Windows Key + R / Ctrl + V / Enter". YARA rule reports 283 samples matched, >60% zero AV detection at time of analysis.

0 sightings0 hosts
criticalphishing
Multi-Brand pages.dev Phish Kit — yandex js.js
family: multibrand-pagesdev-phish

360-yandex-mail cohort js.js — 9 hosts.

12 sightings10 hosts2026-06-30
sha256: cb289c2c092f0731
ast: c4166bf8d509ff23
criticalphishing
Multi-Brand pages.dev Phish Kit — naver cohort js.js
family: multibrand-pagesdev-phish

Naver (Korean) cohort js.js — 8 hosts.

13 sightings8 hosts2026-05-24
sha256: 6c20198ee0753ea1
ast: 8dbd7cc953c984f6
criticalphishing
Multi-Brand pages.dev Phish Kit — pdf cohort js.js
family: multibrand-pagesdev-phish

PDF/Adobe cohort js.js — 16 hosts.

25 sightings18 hosts2026-08-28
sha256: bdc585e39a502805
ast: 6cad13f1b0860ed1
criticalphishing
Multi-Brand pages.dev Phish Kit — excel cohort js.js
family: multibrand-pagesdev-phish

Excel/Office365 cohort js.js — 13 hosts.

20 sightings14 hosts2026-07-01
sha256: b3fdd88a11692fa9
ast: cace2b9510cf4905
criticalphishing
Multi-Brand pages.dev Phish Kit — update cohort js.js
family: multibrand-pagesdev-phish

"update" generic cohort js.js — 38 hosts.

54 sightings42 hosts2026-08-28
sha256: 925eb2c4c3e7d6da
ast: d0dd708a9d76e831
criticalphishing
Multi-Brand pages.dev Phish Kit — sso-godaddy js.js
family: multibrand-pagesdev-phish

GoDaddy SSO cohort js.js — 100 hosts.

151 sightings120 hosts2026-09-09
sha256: 4d19a14f029c727d
ast: 5d9aece34dc653ac
criticalphishing
Multi-Brand pages.dev Phish Kit — js1.js (universal kit-internal)
family: multibrand-pagesdev-phish

Universal kit-internal js1.js across the multi-brand pages.dev operator. 206 hosts.

330 sightings255 hosts2026-09-09
sha256: 8adbc9ca2f539ad6
ast: b462ea640b31bda2
criticalphishing
Multi-Brand pages.dev Phish Kit — jg.js (universal handler)
family: multibrand-pagesdev-phish

Multi-brand credential-phishing kit deployed across 220+ *.pages.dev hosts under one operator. Brand cohorts: sso-godaddy (100h), update (39h), excel (16h), pdf/adobe/adobe-pdf (19h), 360-yandex-mail (9h), hostinger-mail (7h), nid-naver-mail (6h), zoho-mail, mailhostbox, nate-mail, dropbox, dhl, outlook-mail, office365-mail, we-tl, mail-one-update. Page title "Are you not a robot?" — fake-CAPTCHA pretext. jg.js is the shared handler script across all cohorts.

334 sightings264 hosts2026-09-09
sha256: 9201f2ee02b6b642
ast: bbe80426cb516fd8
criticalphishing
Gambling Vue PWA Kit — index-v431.js
family: gambling-vue-pwa-1fb0

127-host gambling/casino app Vue PWA kit. ONE operator running random brand hostnames across .shop/.world/.store/.site/.website/.com TLDs. Page titles include "Tower Rush", "Chicken Road", "Lucky Casino", "Chicken Road 2", "BEAST GAMES: ICE FISHING", "Ice Fishing", "Revolut Slots" (Revolut bank brand impersonation in a slots scam). Path pattern /assets/<chunk>-v431.js + PWA service workers (/PwaWorker.js, /push/vapp/VappWorker.js).

537 sightings209 hosts2026-05-24
sha256: 7abf588b07d22725
ast: 1fb0c3766220c5ef
criticalphishing
gasing777 Indonesian Gambling Kit — root_desktop.js
family: gasing777-indonesian-gambling

Desktop layout module for the Indonesian gambling kit.

378 sightings50 hosts2026-08-05
sha256: 2f75b623b967d92b
ast: 6ea936d43d9c8d15
criticalphishing
gasing777 Indonesian Gambling Kit — uc_login.js
family: gasing777-indonesian-gambling

Login chunk of the Indonesian gambling kit (UC framework: uc_login.js).

606 sightings79 hosts2026-07-22
sha256: 465942d00c4cae69
ast: 729a72785a3cef61
criticalphishing
gasing777 Indonesian Gambling Kit — page_searchgame.js
family: gasing777-indonesian-gambling

23+ host Indonesian gambling SPA. Brand titles: "Bansos188", "SKYLAR88", "SOGOSLOT", "Dausbet", "CAGURBET" — all Indonesian gambling brand patterns with "Slot Online", "Slot Gacor", "Anti Rungkat", "Maxwin" terminology. Hosts: gasing777tidakindex.shop, apktiptoplock.sbs, babejd.icu, cagurbetkyu.icu, ndxskylar88.click. Extensive feature set: live chat, login, banners, announcements, page searching.

351 sightings61 hosts2026-07-20
sha256: e99282e4269dfcbd
ast: 14c7b803f996cc0f
criticalphishing
Gambling Vue PWA Kit — App-v442.js (newer cohort)
family: gambling-vue-pwa-1fb0

Newer cohort build (v442) of the same gambling Vue PWA kit. Same operator, kit upgraded.

192 sightings82 hosts2026-05-24
sha256: 92d1994fbc007c3e
ast: 4dc6aafefd732c15
criticalphishing
Gambling Vue PWA Kit — VappWorker.js (PWA service worker)
family: gambling-vue-pwa-1fb0

PWA service worker (/push/vapp/VappWorker.js) of the gambling kit. The PWA architecture is distinctive — most kits don't register service workers; this one does (for push notifications / offline-mode fake-app feel).

288 sightings225 hosts2026-05-24
sha256: b37c83b462175f61
ast: 9441f5048c62bfa4
criticalphishing
Gambling Vue PWA Kit — MarketPageComponent-v431.js
family: gambling-vue-pwa-1fb0

Marketplace page chunk for the gambling kit — renders the fake-casino game catalogue.

507 sightings202 hosts2026-05-24
sha256: 565876d5dc664fff
ast: 187852cef99fe78e
criticalphishing
Gambling Vue PWA Kit — vue-core-v431.js
family: gambling-vue-pwa-1fb0

Vendor bundle of the gambling Vue PWA kit (Vue runtime core, v431 cohort).

528 sightings209 hosts2026-05-24
sha256: 0fe8127f44538ca5
ast: 8a824eec974b6222
criticalphishing
Fake-Telegram Phishing Kit — compatTest.js
family: fake-telegram-dashan

Browser-compatibility probe of the fake-Telegram kit.

33 sightings27 hosts2026-05-24
sha256: 3ee5b1443f69c457
ast: 664a589b55e55226
criticalphishing
btbuu Kit — Bursa Malaysia Stock-Exchange Extension
family: btbuu-bursa-malaysia-extension-7aa6

Extension of the existing btbuu-fake-crypto-exchange operator family targeting a new brand: Bursa Malaysia (Malaysian stock exchange). 7-host cluster including bursamalaysia.space, served from the same /Public/Static/js/layer/layer.js path the btbuu operator uses on btbuu.com and trade-maxs.com. Same operator, new brand.

157 sightings50 hosts2026-08-15
sha256: 01c1dac4350f12ee
ast: 7aa68afc79d60dc4
criticalphishing
Fake-Telegram Phishing Kit — webpack chunk 7283
family: fake-telegram-dashan

Webpack chunk 7283 of the fake-Telegram kit.

26 sightings23 hosts2026-05-24
sha256: 1e558fa516560083
ast: fb2faeab79559bb4
criticalphishing
Fake-Telegram Phishing Kit — webpack chunk 5193
family: fake-telegram-dashan

Webpack chunk 5193 of the fake-Telegram kit.

184 sightings146 hosts2026-08-31
sha256: 60df5c6365dba1e2
ast: 6163b9d82d607519
criticalphishing
Fake-Telegram Phishing Kit — redirect.js
family: fake-telegram-dashan

Massive 139-host Telegram brand-impersonation operation. ONE operator running random-letter hostnames across .icu/.sbs/.xyz/.top/.lat/.homes/.shop/.cn/.com/.org/.love/.life TLDs (dashan.icu, danvato.icu, eldravox.icu, claw111a.xyz, ai123h.xyz, bot789c.xyz, euhe-tg.com, htrx-tg.com, hujli.shop, telegarm-jp.org, yfhmg.love, fdshfgjd.{lat,homes}, …). Pages titled "Telegram" or "Secure Messenger". Operator-built Vue.js SPA. The "-tg" suffix in domain names and Japan/JP brand hints suggest Telegram-Japan credential-harvest focus.

159 sightings85 hosts2026-08-31
sha256: 375141f2d3f04c73
ast: a7840520d70cbd25
highphishing
.forum TLD Rotation Sister Cohort (f96966) — js/app
family: forum-tld-sister-f969

Sister cohort of forum-tld-kit-b86d1a / forum-tld-kit-6ed2. 39 .forum hosts with uniform 8-char random hostnames (bgvwaihj.forum, bosmehqu.forum, …). Path pattern /js/app.<hash>.js — different chunk path than the earlier forum kits.

39 sightings39 hosts2026-05-22
sha256: c5ac711bb2bc1ec9
ast: f96966e057e047f2
criticalphishing
login-client/metasuite Phishing Kit — main.js
family: login-client-metasuite-54de

4-host operator: login-client-6i5.pages.dev, metasuite-business.com cohort. Numbered "login-client" Cloudflare Pages deployments paired with "metasuite-business" branding — textbook MS 365 / business-suite credential-harvest naming.

7 sightings4 hosts2026-05-23
sha256: d9cb0357bf1752fb
ast: 54de74dfebdc817b
highphishing
htxnadf.top Operator — js/app
family: htxnadf-2503

5-host operator running random-named .top hostnames anchored on htxnadf.top.

9 sightings5 hosts2026-05-24
sha256: 69fcb27026b08ca4
ast: 2503627a0bf781f7
criticalphishing
Chinese WhatsApp Impersonation — main.js
family: whatsapp-cn-bf71

5-host Chinese WhatsApp brand impersonation: it-web-whatsapp.hl.cn, llg-whatsapp.com.cn, etc. Third-region sister of whatsapp-bd-771c (Bangladesh) and whatsapp-pk-96b1 (Pakistan) — same kit-as-a-service operator targeting more countries.

5 sightings5 hosts2026-05-24
sha256: 7dd85aca2c29abbe
ast: bf712e0fcf12f967
highphishing
Random-Letter .com Rotation Sister — js/app
family: random-letter-com-sister-a218

Sister cohort of random-letter-com-199c. 18 hosts with 10-letter random .com hostnames (2zrlupki.com, luckrfbyjg.com, …). Different bundler path (/js/app.<hash>.js) than the original 199c kit.

28 sightings18 hosts2026-05-24
sha256: e08ba4c5bb4b2307
ast: a218803fc5c5e5cc
highphishing
.forum TLD Rotation Sister Cohort (cc0aeb) — js/app
family: forum-tld-sister-cc0a

Sister cohort #2 of the .forum-TLD rotation family. 17 hosts with random 10-char hostnames (hvwvwvjwso.forum, nbilrwodrt.forum, …). Different build hash from f969.

17 sightings17 hosts2026-05-23
sha256: 3b4b47338201582e
ast: cc0aeb09a46919c8
highphishing
Chinese Kaiyun Gambling Kit — js/app
family: cn-kaiyun-gambling-7460

42-host Chinese gambling operator running "Kaiyun" brand impersonation across cn-kaiyunapp.vip, zh-kaiyuntiyu.vip, danti4833.com subdomains with random hostname prefixes. Path pattern /js/app.<hash>.js. Kaiyun (开云) is a known Chinese gambling brand frequently impersonated; "kaiyun" naming + Chinese-numeric subdomains is a strong operator signature.

42 sightings42 hosts2026-05-25
sha256: 84782284c7ec7fbf
ast: 746038d26798d27a
criticalphishing
CME/NYSE Multi-Broker Sister Cohort — chunk-vendors
family: multi-broker-sister-e21c

Sister cohort of multi-broker-impersonation-195a. 3 hosts: cmenyses.com (CME+NYSE), cmekeya.com (CME+Keya). Same operator running additional broker-name combinations.

3 sightings3 hosts2026-05-24
sha256: 351a36c2e0c3153e
ast: e21c25c168f2f502
highphishing
Mufolio Portfolio Impersonation — chunk-vendors
family: mufolio-portfolio-c376

1 host (mufolio-portal-x.com) impersonating a portfolio/asset-management brand. "Mufolio" is operator-coined.

1 sightings1 hosts2026-05-23
sha256: 521e97b8b6e292df
ast: c376671c613e9722
highphishing
Minexus VIP Impersonation — chunk-vendors
family: minexus-impersonation-beb4

1 host (minexusvip.com) — Minexus is a real crypto-mining brand. The "vip" suffix is operator-added.

1 sightings1 hosts2026-05-24
sha256: cd3c314c872baf82
ast: beb497b84a323b25
criticalphishing
TrustUcoin Crypto-Wallet Impersonation — chunk-vendors
family: trustucoin-impersonation-caba

1 host (trustucoin.com) impersonating Trust Wallet / Trust Coin brand.

2 sightings1 hosts2026-05-24
sha256: b1815d107dd560fb
ast: cabad64b4e940061
criticalphishing
MTS Gold Impersonation — chunk-vendors
family: mts-gold-impersonation-22fc

1 host (mtsgoldr.com) impersonating MTS Gold (real precious-metals broker). The trailing "r" is typo-brand phishing.

1 sightings1 hosts2026-05-22
sha256: 4aad80655719d4e9
ast: 22fc9cb63d94952d
criticalphishing
Whale Exchange Impersonation — chunk-vendors
family: whale-exchange-impersonation-50a4

1 host (www.whaleoex.com) impersonating Whale (real crypto-derivatives exchange / similar branding).

1 sightings1 hosts2026-05-24
sha256: 7bc9f4fe65db112d
ast: 50a44be799fb4657
criticalphishing
Shopify Brand Impersonation — chunk-vendors
family: shopify-impersonation-5512

1 host (shoopeifyus.com) impersonating Shopify. Triple-vowel "shoopeify" + "us" suffix is a textbook brand-typo phishing pattern.

5 sightings1 hosts2026-05-24
sha256: 01a748c2f61adcce
ast: 5512842a77086f7a
criticalphishing
Tokyo Financial Exchange Impersonation #2 — chunk-vendors
family: tokyo-financial-exchange-5833

Companion build of the Tokyo Financial Exchange impersonation kit. Same host (tokyofinancialexchange.work) but second chunk hash — different cohort build of the same kit.

2 sightings2 hosts2026-06-29
sha256: 5882914cb80ca205
ast: 58336fe7452c1110
criticalphishing
Tokyo Financial Exchange Impersonation #1 — chunk-vendors
family: tokyo-financial-exchange-bd76

1 host so far (tokyofinancialexchange.work) impersonating Tokyo Financial Exchange (real Japanese exchange). Operator-built anchor — canonical_ast_hash trigger will catch any future cohort rebuilds.

2 sightings2 hosts2026-06-29
sha256: 5db10d8472ba73c8
ast: bd765b0d6817de52
criticalphishing
FP Markets Forex Impersonation — chunk-vendors
family: fpmarkets-impersonation-3856

2-host operator impersonating FP Markets (real Australian forex broker). fpmarts.com cohort.

2 sightings2 hosts2026-05-22
sha256: 8fc61ae80db8d039
ast: 385699b684c6e16f
highphishing
zhesinc/zhesinr Sister Cohort #1 — chunk-vendors
family: zhesin-sister-f125

2-host operator: zhesinc.com, zhesinr.com (variants of "zhesin" brand prefix). Surfaced via cosine pivot.

2 sightings2 hosts2026-05-23
sha256: 4b17561e0d471732
ast: f1250c96b5228c49
criticalphishing
OneKey Wallet Impersonation — chunk-vendors
family: onekey-impersonation-f866

2-host operator impersonating OneKey (real crypto-wallet brand). onekey1.com cohort. Crypto wallets are high-value phishing targets — credential theft = drained wallets.

5 sightings2 hosts2026-05-23
sha256: be58d76acb3308c6
ast: f86634325a133e48
highphishing
tuops Sister Cohort — chunk-vendors
family: tuops-sister-eab1

3-host random-domain sister cohort surfaced via cosine pivot. tuops.top cohort.

4 sightings3 hosts2026-05-24
sha256: 02b0ee964ef23d8c
ast: eab170e2226f7f6e
criticalphishing
MeridianLink Lending-Tech Impersonation — chunk-vendors
family: meridianlink-impersonation-7cbc

3-host operator impersonating MeridianLink (real US lending/banking tech company). meridianlinkgroup.com cohort.

3 sightings3 hosts2026-05-24
sha256: c3f9b21ab5797a83
ast: 7cbc1fb043a7677a
criticalphishing
BitMart Crypto-Exchange Impersonation — chunk-vendors
family: bitmart-impersonation-cdcd

3-host operator impersonating BitMart (real crypto exchange). Surfaced via cosine pivot on btbuu-fake-crypto-exchange anchors. Hosts include bitmartsweb.com.

4 sightings3 hosts2026-05-23
sha256: 7dd75c6d0850e58c
ast: cdcd24061e2a346c
highphishing
zhesinc/zhesinr Sister Cohort #2 — chunk-vendors
family: zhesin-sister-f221

Companion build of the zhesin-sister kit.

2 sightings2 hosts2026-05-23
sha256: 28e8ad9c93737621
ast: f22163e7b66b5885
highphishing
nyadegd/nyduehs Numbered Sister Cohort — chunk-vendors
family: nyadegd-nyduehs-sister-244b

4-host numbered brand sister of the existing nyedfrt-top-3af6 kit. Hosts: nyadegd856.top, nyduehs598.top, nyduehs621.top.

4 sightings4 hosts2026-05-23
sha256: 967e15be66e36a6a
ast: 244b28272ed4efd3
highphishing
Random-Domain Vue Sister Cohort (3ed975) — chunk-vendors
family: random-domain-sister-3ed9

Sister cohort of the existing random-letter-multitld-4ba7 kit. 6 hosts: klajlzmopkiak9kanz.{icu,qpon}, myj9qlcd05jj.qpon, nhgijgskjmriaks.icu, yjksnolkdjhikakr.{click,cyou}. Cosine-pivoted at sim=1.0000.

11 sightings6 hosts2026-05-23
sha256: a7e6053eab96dc2d
ast: 3ed975d6df23ad49
highphishing
Random-Domain Vue Sister Cohort (aec05b) — chunk-vendors
family: random-domain-sister-aec0

Sister cohort of the random-letter-multitld kit family. 3 hosts: hjuiwansdjjsdjks.cyou, nbjiwuqnskdkza.icu, nuhjsjjjskwjaksjs.icu. Cosine-pivoted from existing 9d69 and 4ba7 anchors.

3 sightings3 hosts2026-05-24
sha256: 070253c66f110335
ast: aec05be5cdaf797c
highphishing
.click TLD Vue Sister Cohort (6287713d) — chunk-vendors
family: click-tld-sister-6287

Sister cohort of the existing click-tld-kit-a260ef. 2 hosts: manwasite.cc, mwxz10.cc. Cosine-pivoted at sim=1.0000.

4 sightings2 hosts2026-05-24
sha256: 0cde578ea2c8975d
ast: 6287713dd6e3e352
highphishing
Pionex Crypto-Bot Brand Impersonation — chunk-vendors
family: pionex-impersonation-b14b

5-host operator impersonating Pionex (real crypto trading bot platform): pioddnexqye.com, pionexadv.com, etc. The "pionex" substring is the operator's mimicry of the brand.

7 sightings5 hosts2026-05-23
sha256: 127f1c7fd5f4352b
ast: b14b11e28b278e34
highphishing
BitMax Crypto-Exchange Impersonation — chunk-vendors
family: bitmax-impersonation-8632

5-host operator impersonating BitMax (real crypto exchange now rebranded to AscendEX). bitmax123.com cohort.

16 sightings5 hosts2026-05-24
sha256: 75e8f139ce332b1f
ast: 8632a2771850661b
highphishing
DDEX DEX Impersonation — chunk-vendors
family: ddex-impersonation-a692

4-host operator impersonating DDEX (decentralized exchange brand): ddex319.top, ddex329.top, plus raw IP 112.213.125.56:35971. The raw-IP serving is suspicious infrastructure.

5 sightings4 hosts2026-05-24
sha256: 5c520023c4fea99d
ast: a6920bca60e00824
highphishing
Golden Shield AI Investment Scam — chunk-vendors
family: goldenshieldai-47907a

4-host operator running "Golden Shield AI" investment-scam brand across multi-TLD: goldenshieldai.homes, goldenshieldai.lat, goldenshieldai.online. Same brand, throwaway TLDs.

5 sightings4 hosts2026-05-25
sha256: a362881fca1e9fe3
ast: 47907aea0ff497ab
highphishing
crimsonagility Numbered Brand Rotation — chunk-vendors
family: crimsonagility-2724

6-host numbered-brand series: crimsonagility[22|33|55|…].com.

6 sightings6 hosts2026-05-23
sha256: d0139214d19ab601
ast: 2724d49cfa5fc2d4
highphishing
Brazilian Gambling Sister Cohort (7v-) — chunk-vendors
family: pt-brazil-gambling-sister-9e19

5-host Brazilian Portuguese gambling sister of pt-brazil-gambling-80be. Hosts: 7v-elefante.com, 7v-leao.vip ("elephant", "lion"). Same operator, 7v-prefix cohort.

12 sightings5 hosts2026-05-24
sha256: 56d9f1e60b072a2f
ast: 9e190ec3029d8485
highphishing
slh Numbered Series + slhofworld — chunk-vendors
family: slh-numeric-9aa7

4-host numbered brand series: slh005.com, slh006.com, …, slhofworld.vip.

4 sightings4 hosts2026-05-25
sha256: a00fa06622b5a7a8
ast: 9aa7de68ebff3b16
highphishing
aazzkf Multi-TLD Same-Prefix Kit — chunk-vendors
family: aazzkf-multitld-36df

4-host same-prefix multi-TLD operator: aazzkf.cc, aazzkf.com, aazzkf.org, aazz-kf.com. Sister pattern to aaoopg-eejjkf-02d6.

4 sightings4 hosts2026-05-24
sha256: 8db8cd38410b5a6f
ast: 36dfc2978517092d
highphishing
ldwebsync Numbered .top Series — chunk-vendors
family: ldwebsync-numeric-ba2a

4-host numbered brand series: ldwebsync[32|73|78|…].top.

4 sightings4 hosts2026-05-23
sha256: d5998518256f3519
ast: ba2a7c44c21c40cd
highphishing
dhptgo Multi-TLD Same-Prefix — chunk-vendors
family: dhptgo-multitld-ea03

4-host same-prefix multi-TLD operator: dhptgo.cc, dhptgo.sbs, dhptgo.top.

4 sightings4 hosts2026-05-24
sha256: 0fed425ab0366b22
ast: ea035b1a53a008e4
highphishing
Wildcard-DNS Port-3443 Cohort — chunk-vendors
family: wildcard-port3443-aa15

4-host wildcard-DNS abuse sister of nested-subdomain-9003, serving on non-standard port 3443: tyyx.dakowe.1bdbr3.com:3443, tyyx.ooios.mgqlfa.com:3443.

8 sightings5 hosts2026-06-09
sha256: 1fe80c98689db948
ast: aa15624d01589eb7
highphishing
Random-Letter Multi-TLD Sister Cohort (3cdd1b) — chunk-vendors
family: random-letter-sister-3cdd

6-host sister cohort of the random-letter-multitld kit family. Random keyboard-mash hostnames on .icu/.shop.

6 sightings6 hosts2026-05-24
sha256: feb8fc67f986ed5b
ast: 3cdd1bbb090720fc
highphishing
Azure Static Web Apps Sister Cohort — chunk-vendors
family: azure-swa-sister-119a

Sister of the existing `cloud-storage-abuse-72ea` kit. 5 hosts on Azure Static Web Apps: abw219, hk3091, london25, nsd90317, xdl719 — geographic-cohort naming (HK=Hong Kong, london, etc.) suggests targeted-region phishing.

9 sightings5 hosts2026-05-24
sha256: d92a79b05f0c944e
ast: 119a352ab882fd25
highphishing
Wildcard-DNS Multi-Subdomain Sister Cohort — chunk-vendors
family: nested-subdomain-sister-86c0

Sister of the existing `nested-subdomain-9003` kit using wildcard-DNS abuse with deeply-nested random subdomains: lycl.cjilea.b7ryzkx.com, lypz.j9ado3.ikxoxfjp.com, uicl.oiusnx0w0.c7m26j3n2k.com:3443 (also serving on non-standard port 3443).

7 sightings7 hosts2026-08-21
sha256: 6184aec1ea2fc303
ast: 86c0cf3defc9e36d
highphishing
Cimamedia/Speedride Sister Cohort — chunk-vendors
family: cimamedia-speedride-sister-5f2e

Sister cohort of the existing `cimamedia-speedride-682f` kit: cimamedia0i.com, cimamedia99.com, cimamediaia.com, speedride0i.com, speedridecc.com, speedridezz.com. Same operator, second build hash.

6 sightings6 hosts2026-05-24
sha256: 780f720c4be1039d
ast: 5f2eb35d9064c8ed
highphishing
Huawei Brand Impersonation — chunk-vendors
family: huawei-impersonation-788f

4-host operator running Huawei brand impersonation: huaw3.cn, huaw3.com plus wzg56.cc, wzg71.cc sister hosts. "huaw" is the operator-chosen prefix mimicking "huawei".

4 sightings4 hosts2026-05-24
sha256: 1e5c80e0f1a6e95d
ast: 788f2038605749ee
highphishing
Pakistan WhatsApp Impersonation — chunk-vendors
family: whatsapp-pk-96b1

Pakistan-targeting WhatsApp brand impersonation: pak2whatsapp.com, pak3whatsapp.com, pakwhatsapp.com, pk2wapp.com, pk3wagetmoney.com, pk7wagetmoney.com. Sister of the existing `whatsapp-bd-771c` Bangladesh cohort — same kit-as-a-service operator targeting different countries.

6 sightings6 hosts2026-05-23
sha256: 8abaae6bd2da7d74
ast: 96b19170f3dadc62
criticalphishing
COMEX/Ortex Trading Impersonation — chunk-vendors
family: comex-ortex-impersonation-61ea

6-host operator: comex-ex.com, comex-glob.com, comex-next.com, comex-next-desk.com, ortexlabs.com, ortexportal.com. COMEX + Ortex (real institutional trading-research firm) impersonation. Sister of the d7a2 cluster.

6 sightings6 hosts2026-05-24
sha256: 453c4ea305349139
ast: 61ea29ba81a626b9
criticalphishing
CME/AMEX/NYSE/Schwab Multi-Broker Impersonation — chunk-vendors
family: multi-broker-impersonation-195a

6-host operator running MULTIPLE major financial-brand impersonations from a single template: cmeamex.com, cmeamexs.com, cmenyse.com (CME+AMEX, CME+NYSE), schwabvs.com (Charles Schwab), tradesoksca.com, tradesokscs.com. Single SPA deployed under each broker's name.

8 sightings6 hosts2026-05-24
sha256: 9f011ba91090578d
ast: 195ac2a49d3b05b4
criticalphishing
COMEX/Tada Cloud-Hosted Trading Kit — chunk-vendors
family: fake-trading-platform-d7a2

6-host operator hosting fake trading platform on Azure Static Web Apps + .top with port: comex309.z1.web.core.windows.net + secondary, tada1912.z23.web.core.windows.net + tada93179, web6699.313675.top:39395. "COMEX" = Commodity Exchange impersonation; "tada" branding signals throwaway cohorts.

14 sightings6 hosts2026-05-24
sha256: dd153fe7cf4e118a
ast: d7a27a645cee0cc8
highphishing
Indonesian Gambling Next.js Kit — pages/_app
family: indonesian-gambling-nextjs

Companion pages/_app build for the Indonesian gambling Next.js SPA.

57 sightings30 hosts2026-05-24
sha256: cfc02413fb7cf119
ast: ba5e07a8d93bce1b
highphishing
Indonesian Gambling Next.js Kit — pages/index #1
family: indonesian-gambling-nextjs

Next.js SPA deployed across 37+ Indonesian-language online gambling sites. Brand+number naming (ammo88jaya, apek88-apk2, banteng328bersama, banteng328goyang.site, bos56.xyz, dragon969resmi.site, elang55b.com, eth77original.site, …). Page titles in Bahasa Indonesia: "Situs Slot Online Gampang Menang", "Login Situs Slot 4d Mahjong yang Pasti Bayar 2025", "RTP Gacor Hari Ini" (slot/mahjong/RTP terminology).

133 sightings37 hosts2026-05-24
sha256: 88fa9fe9bff0cafd
ast: c38e7ac86c6d19db
criticalphishing
Telcel Mexico Brand Impersonation — index.js #1
family: latam-telcel-mx-phish-52aa

Brand-impersonation phishing kit targeting Telcel (Mexico's dominant mobile carrier). 23 hosts on .top/.vip with mx-prefixed names (mxstelcec.top, mxtecelah.top, mxtelelsuy.top, mxtelesvip.vip, …). URL path /apps/MX_PT_06/assets/index-*.js — the "MX_PT_06" naming matches the Tigo SV kit's "SV_PT_01", strong evidence of one operator running localized LATAM carrier kits.

26 sightings23 hosts2026-05-24
sha256: 12d9cc0136e05f8e
ast: 52aa5c54fed1ee67
highphishing
status-account-NNN.pages.dev Scam Kit — index.js
family: status-account-pagesdev-4455

19-host operator running numbered Cloudflare Pages deployments: status-account-{8,10,13,14,16-21,43,53,70,71,75,122,123,124,125}.pages.dev. Hostnames are textbook account-suspended phishing pattern (Microsoft/Google "your account has been suspended" credential harvest).

27 sightings20 hosts2026-08-06
sha256: 7104333d5b7a42fe
ast: 4455ca38966d3e48
criticalphishing
Tigo El Salvador Brand Impersonation — index.js #2
family: latam-tigo-sv-phish-1b7d

Companion build of the Tigo SV kit — same 19 hosts, second anchor chunk.

25 sightings19 hosts2026-05-24
sha256: 779fcf56e879ec5d
ast: 291e03be04471f90
criticalphishing
Tigo El Salvador Brand Impersonation — index.js #1
family: latam-tigo-sv-phish-1b7d

Brand-impersonation phishing kit targeting Tigo El Salvador (major LATAM telecom). 19 hosts on .cc/.help/.click/.art/.sbs/.top with tigo-prefixed names (sv-tigo.cc, tigoboss.help, tigosrwvp.help, tigovseop.click, tigovspom.help, …). Page title: "La primera Red 5G de El Salvador | Tigo El Salvador" (direct quote from real Tigo SV marketing). URL path /apps/SV_PT_01/assets/index-*.js — sister to the Telcel MX MX_PT_06 kit, same operator.

25 sightings19 hosts2026-05-24
sha256: b8d61f196248b37a
ast: 1b7de72432be2b3c
criticalphishing
Telcel Mexico Brand Impersonation — index.js #2
family: latam-telcel-mx-phish-52aa

Companion build of the Telcel MX kit — same 23 hosts, second anchor chunk under the same /apps/MX_PT_06/ path.

26 sightings23 hosts2026-05-24
sha256: 11dd561046a293f3
ast: 21d2c7084985c7bb
criticalphishing
AMP Futures Brand Impersonation — index.js
family: amp-futures-phish-a637

Brand-impersonation phishing kit targeting AMP Futures (US futures broker, ampfutures.com). Deployed across 62 random-letter .xyz hostnames matching pattern [a-z][0-9][a-z][0-9][a-z].xyz (a2q6w.xyz, a4k7n.xyz, b2k9t.xyz, …). All 62 hosts serve the page title "AMP Futures"; all were graded Low Risk or Medium Risk by the verdict layer.

68 sightings62 hosts2026-05-24
sha256: c5947182321ae741
ast: a637397379fb0f0f
highphishing
Deeply-Nested Random Subdomains — chunk-vendors
family: nested-subdomain-9003

7-host operator using DEEPLY-NESTED random subdomains (4+ labels): cccys.zokide.6x1qko1.com, ccyy.xmsck.jluoo8h.com, cuiu.yw9u2e.esh536.com, cyppt.apxpiff.ztlcsqwf.com, cyqqt.x01jjex.ay9fc.com, cyttp.cokpa.lyaj69w.com, hue.oaiweu.6o99od.com. Wildcard-DNS abuse pattern.

11 sightings7 hosts2026-05-24
sha256: 9820b3d4882221ed
ast: 90039727879e8821
highphishing
chd-suffix .com Random Rotation — chunk-vendors
family: chd-suffix-com-f6c1

7-host operator: aeychdent.com, caichdfdt.com, daochderu.com, ejgchdcbt.com, fjhchdlep.com, gajchdvbt.com, hajchdkru.com. Uniform `chd` substring at positions 4-6 in random-alpha .com hostnames.

9 sightings7 hosts2026-05-24
sha256: 10b4f1400e753ae9
ast: f6c12af645a09a8e
highphishing
WhatsApp Brand Impersonation — chunk-vendors
family: whatsapp-bd-771c

7-host operator impersonating WhatsApp: bd1whatsapp.com, bd2wapp.com, bd2whatsapp.com, bd3wapp.com, bd3whatsapp.com, bdwhatsapp.com, pk6wagetmoney.com. The "bd"/"pk" prefixes suggest Bangladesh/Pakistan targeting.

7 sightings7 hosts2026-05-24
sha256: e5cba98752db082d
ast: 771cbd9ee0d126e1
highphishing
Random-Alphanumeric .vip Kit — chunk-vendors
family: random-vip-alphanum-0165

7-host operator running long random alphanumeric .vip hostnames: cxwf0r2o9t9w1o9w7.vip, hiut9h0v4l2d7a7v0.vip, ijne8g2c1f5q0f9l5.vip, kmkf1e3z8z8s5q2k0.vip, vbja9y9n8u0w5s2b6.vip, vbjk2x2t9z3m6g7s2.vip, vcve2mcixbkl3kfd32fg.vip.

8 sightings7 hosts2026-05-24
sha256: f52d36e50bdde79b
ast: 0165362030b69da3
highphishing
[X][N].cn Random-Pattern Kit — chunk-vendors
family: letterhex-cn-25f3

7-host operator on .cn TLD with letter+digit random pattern: j3h1k9.cn, m9u6y0.cn, n4c6v5.cn, p4i6o3.cn, q4x9v6.cn, q7e2r6.cn, q8t4y7.cn.

14 sightings7 hosts2026-05-25
sha256: 1b97eb47489c928a
ast: 25f302f9303d140f
highphishing
xt Prefix .com Rotation — chunk-vendors
family: xt-prefix-295e

7-host operator: xtcuf.com, xtdli.com, xtfue.com, xtjvn.com, xtlwh.com, xtnmc.com, xtpxd.com. Uniform xt[CCC].com pattern.

8 sightings7 hosts2026-05-24
sha256: 5441732c97b13508
ast: 295e6e76305e02a7
highphishing
Pages.dev + .top Mixed Rotation — chunk-vendors
family: pagesdev-top-1b9a

7-host mix of Cloudflare Pages + .top TLDs: elmapp.pages.dev, ggzszfl.top, ghtsmr.top, hptsmn.top, mgtred.top, qnqb61.top, sizeg.top.

9 sightings9 hosts2026-08-26
sha256: 813f5be7488249a4
ast: 1b9addc68e62635e
highphishing
xpj/uuyl Numeric Lottery/Gambling — chunk-vendors
family: xpj-uuyl-1a5e

7-host operator: 266229.com, 500698.com, 500798.com, klyl6.net, www.uuyl.net, www.uuyl.xyz, xpj2487.com. Chinese-style numeric gambling/lottery brands.

9 sightings7 hosts2026-05-25
sha256: 47a1e33272718e00
ast: 1a5efee5179866ce
highphishing
Azure/Tencent Cloud Storage Abuse Kit — chunk-vendors
family: cloud-storage-abuse-72ea

7-host operator abusing free cloud storage to host the SPA: 5 Azure Static Web Apps (*.zNN.web.core.windows.net) + Tencent Cloud Object Storage (*.pichk.myqcloud.com). The cloud-vendor domains lend false legitimacy.

18 sightings7 hosts2026-05-24
sha256: 0e8c5aefedc14ca1
ast: 72ea0edd14bc5180
highphishing
Portuguese/Brazilian Gambling Rotation — chunk-vendors
family: pt-brazil-gambling-80be

8-host operator running Portuguese/Brazilian-language gambling brands: 54rr.win, 91-earring-pg.vip, muito-777.win ("777" + Portuguese for "a lot"), okokflash.mom, voy-brow-pg.vip, we-operapg.mom ("opera-pg"), wgbetkk.win, wg-relogio.win ("relogio" = watch).

24 sightings8 hosts2026-05-24
sha256: cf7c65b6c64c32af
ast: 80be79f13f588948
highphishing
andes* Prefix Rotation — chunk-vendors
family: andes-prefix-4556

8-host operator running andes-prefixed brands: andekhu5, andesapply24, andesapply8k, andeshsk11, andesiodshuqian22, andesjhsh2, andessdf3, andsskli8 on .com.

11 sightings8 hosts2026-05-23
sha256: 3118af6c53c27589
ast: 45568096f11b3baf
highphishing
aaoopg/eejjkf Multi-TLD Same-Prefix Kit — chunk-vendors
family: aaoopg-eejjkf-02d6

9-host operator running aaoopg.{app,cc,net,one,vip} + eejjkf.{app,com,net,one}. Same prefix across multiple TLDs — characteristic of bulk-domain phishing.

20 sightings15 hosts2026-08-17
sha256: c86e2531db3c70fd
ast: 02d6854acc416c94
highphishing
bbq/carros/ty Portuguese Brand Rotation — chunk-vendors
family: bbq-carros-pt-03a5

9-host operator running Portuguese-language brand impersonation: bbq-kf.com, bbqkf.com, bbqkfpg.com, carros-ty.com, carrosty.com, okcarros.com, ty-carros.com, tycarros.com, vip-carros.com (BBQ + cars).

14 sightings9 hosts2026-05-24
sha256: 73c6cbe13389b504
ast: 03a5675e5dad98b9
highphishing
hhmh Numbered Brand Series — chunk-vendors
family: hhmh-numeric-891d

10-host numbered series: hanhan12.com + hhmh1[386|387|388|389|390|397|398|399|400].com.

14 sightings14 hosts2026-07-10
sha256: e477b368e396d95f
ast: 891d4e8f15135644
highphishing
nyedfrt Numbered .top Series — chunk-vendors
family: nyedfrt-top-3af6

10-host numbered series operator: 532810.top, nyadegd[326|517].top, nydash812.com, nyedfrt[017|195|367|591|728|937].top.

15 sightings10 hosts2026-05-23
sha256: 6ac8277c4b729f04
ast: 3af68fe57ddff5f6
highphishing
Auto-Word-Pair Brand Rotation (shop/com) — chunk-vendors
family: wordpair-shop-0d56

10-host operator running auto-generated word-pair brand names: deeply-marketsearch.com, deeps-datastudy.com, finely-stylecraft.com, quicks-cdbuild.com on .com + findraregive/getfastrun/grabfreshsell/keepgoodsave/makesweetbake/picksmartubuy on .shop. Lure: looks like quick-build / market-research / save-money brand.

27 sightings20 hosts2026-08-09
sha256: ed2a1e88067fdf0b
ast: 0d565e03ac5acc68
highphishing
Random-Letter .com Rotation — chunk-vendors
family: random-letter-com-199c

11-host operator running 10-letter random .com hostnames (cjnwqvprty.com, dkpvtrmzla.com, fgrtqpxlme.com, …).

19 sightings11 hosts2026-05-24
sha256: bc2afc0a62439d41
ast: 199c83f3dc8f5113
highphishing
acce* Prefix Rotation — chunk-vendors
family: acce-prefix-d0ae

12-host operator running acce[afae|afaf|dew|dzz|eann|haiu|kioa|lnn|mfg|mmrk|qrf|rmk].com sister hosts. Uniform `acce` prefix, two-three random suffix characters.

14 sightings12 hosts2026-05-24
sha256: 42cf479e4079992a
ast: d0ae69c765a1748c
highphishing
Random-Letter Multi-TLD Kit (shop/sbs/cyou/icu) — 13h
family: random-letter-multitld-74f3

Vue.js webpack SPA across 13 random-letter hostnames on .shop/.sbs/.cyou/.icu TLDs.

20 sightings13 hosts2026-05-24
sha256: 159e65e8d02e6bb8
ast: 74f3e3d4dbb851b4
highphishing
Cimamedia/Speedride Sister-Brand Rotation — chunk-vendors
family: cimamedia-speedride-682f

15-host operator running two parallel brand prefixes: cimamedia[88|92|9i|aa|io|ip|vi|vip|vvip].com and speedride[88|92|9i|ia|io|vi].com.

15 sightings15 hosts2026-05-24
sha256: ba82cc04e52e3e29
ast: 682fef0b99fc7b9a
highphishing
Random-Letter Multi-TLD Kit (icu/click/cfd) — 15h
family: random-letter-multitld-4ba7

Vue.js webpack SPA across 15 random-letter hostnames on .icu/.click/.cyou/.cfd/.shop/.sbs TLDs.

21 sightings15 hosts2026-05-24
sha256: d790d7ba2e47a11a
ast: 4ba7a0589a341f3e
highphishing
Random-Letter Multi-TLD Kit (icu/shop/cyou/sbs) — 15h
family: random-letter-multitld-9cba

Vue.js webpack SPA across 15 random-letter hostnames on .icu/.shop/.cyou/.sbs TLDs.

16 sightings15 hosts2026-05-25
sha256: cafe5e1e8ae907cb
ast: 9cbad927fd759031
highphishing
Meituan Brand Impersonation + Chinese Names — chunk-vendors
family: meituan-impersonation-c171

Operator across 16 hosts impersonating Meituan (Chinese super-app): qiqimeituan.xyz, shengmeituan.xyz, plus generic Chinese-themed names (songsong123.xyz, tangtang123.asia, zhanxupeng6.asia) and qazwsxNNN.asia placeholders.

22 sightings16 hosts2026-05-25
sha256: ed528efb979a5d8d
ast: c171df7eae858756
highphishing
Random-Letter Multi-TLD Kit (cyou/icu/shop/sbs) — 16h
family: random-letter-multitld-95ed

Vue.js webpack SPA across 16 random-letter hostnames on .cyou/.icu/.shop/.sbs TLDs.

17 sightings16 hosts2026-05-25
sha256: 00a3c04b868fe2be
ast: 95ed255c605216b6
highphishing
.forum TLD Rotation Kit (b) — chunk-vendors
family: forum-tld-kit-6ed2

Vue.js webpack SPA across 17 .forum TLD hosts (bqetfpng.forum, bvgapqrm.forum, djtzmlwl.forum, …). Distinct operator from the migration-080 b86d1a cluster.

18 sightings17 hosts2026-05-22
sha256: 7269af925516b3e1
ast: 6ed2ce87def9f57e
highphishing
rwusdt/axex/safe Crypto Wallet Impersonation — chunk-vendors
family: rwusdt-axex-safe-e232

Operator running multi-brand crypto-wallet impersonation across 17 hosts: rwusdtc[a-y].com (USDT impersonation), axexclub/axexhub on .com+.top, safeger/safegnr/safetar.com, plus dbecrede.com, exintir.com. Fake-wallet credential harvesting.

25 sightings21 hosts2026-09-07
sha256: 72e50786bc5e7149
ast: e2322b1c7fa3e700
highphishing
.click TLD Rotation Kit (b) — chunk-vendors
family: click-tld-kit-1f93

Vue.js webpack SPA across 17 hostnames mostly on .click TLD (bpqsfyum.click, deddrvta.click, hxrygdhl.click, …) plus shakti.top and tea01.bahfn.cn. Different operator from a260ef.

23 sightings19 hosts2026-08-20
sha256: dc6aff7b6af74d25
ast: 1f93def433746651
highphishing
YJDM Numbered Brand Series — chunk-vendors
family: yjdm-numeric-f7d1

Operator running a numbered series of `yjdm[NNNN].com` + `yjdm[NNN].club` sister hosts (yjdm1371-1395.com, yjdm332-355.club — 18 hosts total). Likely Chinese gambling/lottery brand.

22 sightings20 hosts2026-07-14
sha256: 190acfbeaec13e1f
ast: f7d1a6213697c92b
highphishing
Random-Letter Multi-TLD Kit (icu/cyou/qpon/sbs) — 21h
family: random-letter-multitld-9d69

Vue.js webpack SPA across 21 random-letter hostnames on .icu/.cyou/.qpon/.shop/.click/.sbs TLDs. Sister cohort of the kit-as-a-service template.

30 sightings21 hosts2026-05-24
sha256: 59f2136c658bb9a0
ast: 9d69598d7dc9c06f
highphishing
Random-Letter Multi-TLD Kit (cyou/shop/qpon/click) — 26h
family: random-letter-multitld-8c1c

Vue.js webpack SPA across 26 random-letter hostnames on .cyou/.shop/.qpon/.click/.icu TLDs (huwhnkjahksjwnak.cyou, klajlkza12jasdjk131.click, mblgfkltkllpuoprfltp.icu, …). Same kit-as-a-service template as the migration-080 random-domain kits.

36 sightings26 hosts2026-05-23
sha256: e724905a3b420276
ast: 8c1c86c077f2e1c0
highphishing
Random-Letter Multi-TLD Kit (shop/cyou/icu/sbs) — 16h
family: random-letter-multitld-8999

Vue.js webpack SPA across 16 random-letter hostnames on .shop/.cyou/.icu/.sbs TLDs.

19 sightings16 hosts2026-05-25
sha256: 6299bc4af81c01fe
ast: 89994cadce8a60b2
highphishing
Random-Domain Vue Scam Kit (icu/sbs/shop/cyou) — chunk-vendors
family: random-domain-kit-0e990c

Vue.js webpack SPA deployed across 63 random-letter hostnames on .icu/.sbs/.cyou/.shop TLDs. Hostnames are keyboard-mash strings (e.g. baiiwerogkasdfg.sbs, bbqupospdkgkaj.shop, bjioqjksdjkskzx.cyou). Every host in the cluster was graded "Low Risk" or "Medium Risk" by the verdict layer.

76 sightings64 hosts2026-06-12
sha256: 834ae39993dcd84a
ast: 0e990c84e7d4894d
highphishing
.click TLD Rotation Kit — chunk-vendors
family: click-tld-kit-a260ef

Vue.js webpack SPA deployed across 31 hostnames ALL on the .click TLD with 8-character random hostnames (aicjgkjk.click, cbcsljlc.click, pshhttokse.click, qhzelnxa.click, …). Uniform TLD + hostname pattern is a strong operator signal.

39 sightings31 hosts2026-05-24
sha256: 456b1a5957805e4a
ast: a260efe80f4a4801
highphishing
Random-Domain Vue Scam Kit (sbs/qpon/cyou) — chunk-vendors
family: random-domain-kit-c73042

Vue.js webpack SPA deployed across 32 random-letter hostnames on .sbs/.qpon/.cyou/.click/.icu TLDs (iewyrgajdghfvdhdjs.sbs, jkahskdnzl6kajhmza.qpon, …). Includes the .qpon TLD which is rare and a strong scam-infrastructure marker.

35 sightings32 hosts2026-05-24
sha256: 57b551724bafaf27
ast: c73042d87dee76b1
highphishing
Random-Domain Vue Scam Kit (cyou/shop/sbs) — chunk-vendors
family: random-domain-kit-9f38c9

Vue.js webpack SPA deployed across 33 random-letter hostnames on .cyou/.shop/.sbs/.icu TLDs (oodjdfuigewjkfdssf.cyou, bcmnrjwyrishfdjdgf.shop, dsfjngfwisdjfoisdjs.shop, …). TLSH body identical to the 0e990c cluster — likely the same template, different operator cohort.

46 sightings33 hosts2026-05-24
sha256: 164eac04259ecb4e
ast: 9f38c99b21913bcd
highphishing
.forum TLD Rotation Kit — chunk-vendors
family: forum-tld-kit-b86d1a

Vue.js webpack SPA deployed across 40 hostnames ALL on the .forum TLD with 8-character random hostnames (cmkpxlpv.forum, lhivtxfx.forum, ruxkxjyybs.forum, …). The uniformity of TLD + filename-length is a strong operator signal.

44 sightings40 hosts2026-05-23
sha256: ce3d2e4fb9f2fc2a
ast: b86d1a00104d2763
highphishing
Gambling Rotation Kit (.win/.mom/.vip) — chunk-vendors
family: gambling-vip-win-kit-d0d844

Online-gambling/betting kit deployed across 43 brand-prefixed hostnames on .win/.mom/.vip TLDs. Includes 1xbet-style impersonation (1x-clz.vip, 1x-gzm.vip, 1x-xl.vip) and generic bet/win brands (0227bet.win, 107win.mom, 208win2.vip). All hosts graded "Low Risk" or "Medium Risk".

110 sightings43 hosts2026-05-24
sha256: d16088f9201a6156
ast: d0d844a485875495
highphishing
Pages.dev Vue Investment Scam — vindax cohort chunk-vendors
family: pagesdev-vue-investment-scam

Cloudflare-Pages-hosted Vue.js fake-investment kit. ONE operator running brand cohorts (vindax/mint/digtal/pimco impersonation) on *.pages.dev, all sharing the same Vue.js webpack skeleton with cohort-specific branding strings. This anchor catches the vindax-1xy / vindax-9io / mint-5st cohort.

7 sightings3 hosts2026-05-23
sha256: 2a329bc31db7cd82
ast: a0d231cf5829f876
highphishing
Pages.dev Vue Investment Scam — mint-34z cohort chunk-vendors
family: pagesdev-vue-investment-scam

mint-34z.pages.dev cohort build of the Pages.dev Vue investment-scam kit.

1 sightings1 hosts2026-05-24
sha256: f4b560e4eb554c7b
ast: 27cde52d0e53d5c2
highphishing
Pages.dev Vue Investment Scam — pimco cohort chunk-vendors
family: pagesdev-vue-investment-scam

PIMCO-impersonation cohort of the Pages.dev Vue investment-scam kit. PIMCO (Pacific Investment Management Company) is a major real-world asset manager — this kit lures users into a fake investment platform under that brand.

4 sightings4 hosts2026-05-25
sha256: d828a06ac368de17
ast: 631b10c1fb95cf74
highphishing
Pages.dev Vue Investment Scam — mint-b1v cohort chunk-vendors
family: pagesdev-vue-investment-scam

mint-b1v.pages.dev cohort build of the Pages.dev Vue investment-scam kit.

2 sightings1 hosts2026-05-23
sha256: ab194d8bb832a34b
ast: 5a84fb2d53300269
highphishing
Pages.dev Vue Investment Scam — digtal-du cohort chunk-vendors
family: pagesdev-vue-investment-scam

digtal-du.pages.dev cohort build of the Pages.dev Vue investment-scam kit. "Digital" finance brand impersonation (misspelt).

1 sightings1 hosts2026-05-22
sha256: 52b834c1e3fc8eaa
ast: 3c5bee1029ab2344
highphishing
Pages.dev Vue Investment Scam — mint-bnq cohort chunk-vendors
family: pagesdev-vue-investment-scam

mint-bnq.pages.dev cohort build of the Pages.dev Vue investment-scam kit.

1 sightings1 hosts2026-05-23
sha256: 2ccad86e1df97d02
ast: fac56bfb0b2cccb9
highphishing
Pages.dev Vue Investment Scam — vindax pages-index-index.js
family: pagesdev-vue-investment-scam

Index page chunk for the Pages.dev Vue investment-scam kit (vindax cohort build). Shows the fake exchange order book.

7 sightings3 hosts2026-05-23
sha256: aee9cf33d68c9f8d
ast: 6e5fd4de1c98138f
highphishing
Pages.dev Vue Investment Scam — vindax index.js
family: pagesdev-vue-investment-scam

Entry chunk for the Pages.dev Vue investment-scam kit (vindax cohort build).

7 sightings3 hosts2026-05-23
sha256: 1d10b3652b773c82
ast: db03fe660d6e837c
criticalphishing
Medtronic Brand Impersonation — index.js
family: medtronic-impersonation

Brand-impersonation phishing kit targeting Medtronic (the medical-device manufacturer). Vue.js SPA deployed across 4 sister hosts (medtronicwmn.com, medtronicwrr.cc, medtronicwrz.com, medtronicwtt.cc) under /static/js/ paths. Chunks reveal a fake-login + fake-account-detail flow (pages-login, pages-welcome, pages-account-account-detail, pages-Detail, pages-Particulars).

11 sightings4 hosts2026-05-24
sha256: bd9dc2d635550092
ast: 2a818c058644f8c9
highphishing
teje-rotating-domain kit — main.js
family: teje-rotating-domain

Webpack-bundled SPA deployed across an 8-host rotation that all share the `teje` prefix on cheap/suspicious TLDs (tejehqnfih.work, tejehqzjxt.club, tejeiviusk.asia, tejeiwdeow.cloud, tejeiycpyh.asia, tejeizzifa.wiki, …). Most graded Malicious by the verdict layer, some Low Risk — the roster catches the misses.

12 sightings8 hosts2026-08-30
sha256: ff07595993768488
ast: 0431f7cd7a178c89
criticalphishing
Medtronic Brand Impersonation — chunk-vendors.js
family: medtronic-impersonation

Vendor bundle for the Medtronic brand-impersonation kit. Vue+ElementUI+etc. compiled by the operator's specific webpack build.

11 sightings4 hosts2026-05-24
sha256: a2c9927c37f8d0ec
ast: 803f8f97e7113a41
criticalphishing
Medtronic Brand Impersonation — pages-welcome-welcome.js
family: medtronic-impersonation

Welcome-page chunk for the Medtronic brand-impersonation kit. Small, highly diagnostic.

11 sightings4 hosts2026-05-24
sha256: c51ceee5624e7792
ast: 51107f7f0af254a9
highphishing
Random-TLD Multi-Domain Rotation Kit — main.v2.js
family: hevvugu-multi-domain

Single shared main.v2.js deployed across 17 throwaway domains on cheap/suspicious TLDs (.icu, .sbs, .cfd, .cyou, .shop, .wiki, .one, .asia, .club). Includes telegran.one — Telegram brand impersonation. The 17 hosts have inconsistent verdicts (Low Risk → Malicious); the roster catches all of them via a single fingerprint.

84 sightings32 hosts2026-05-24
sha256: 6bf5a0f55daa60a3
ast: fd5ed316ed4cc419
highphishing
btbuu Fake Crypto Exchange — ws-deedfeeds.js
family: btbuu-fake-crypto-exchange

WebSocket feed client used by the btbuu fake crypto-exchange UI to render fake real-time price ticks.

13 sightings8 hosts2026-07-10
sha256: 40c8218a42f4dadf
ast: 21e150991f2a87dd
highphishing
btbuu Fake Crypto Exchange — kline.min.js
family: btbuu-fake-crypto-exchange

Fake crypto-derivatives exchange kit. Operator-deployed K-line / Contract / Trade UI across btbuu.com, wbitx.cfd, trade-maxs.com, evergreen-capital.org. Path pattern /Public/Static/js/*, page pattern /Contract/index, /Trade/index?type=buy&symbol=*. Earlier sweep had bounced on the kit's pako.min.js (real zlib library) — these are the operator-specific files.

13 sightings8 hosts2026-07-10
sha256: 6f141e75fb299645
ast: be431f34f2f765fd
highphishing
teje-rotating-domain kit — 2976.js
family: teje-rotating-domain

Numeric webpack chunk for the teje-rotating-domain kit.

48 sightings8 hosts2026-08-30
sha256: 259a29a5b25f869b
ast: fc103f2af5d57b5d
highphishing
teje-rotating-domain kit — compatTest.js
family: teje-rotating-domain

Browser-compatibility probe used by the teje-rotating-domain kit. Tiny but unique.

15 sightings10 hosts2026-08-30
sha256: 15c24ec2b4cb94f2
ast: a275790c6a6dc010
highphishing
mailNNN.com Credits Scam — pages-login-login.js
family: mail-credits-scam

Login page chunk for the mailNNN.com fake-credits Vue SPA. Renders the credential-harvesting form.

5 sightings3 hosts2026-05-23
sha256: 93985698a0c8a72c
ast: e2fab8cf60b56403
highphishing
mailNNN.com Credits Scam — pages-home-index.js
family: mail-credits-scam

Home/dashboard chunk showing fabricated account balances after login.

6 sightings3 hosts2026-05-23
sha256: 908dfba02fa1a2e0
ast: b30fdf0a494c0532
highphishing
mailNNN.com Credits Scam — index.js
family: mail-credits-scam

Vue.js single-page application deployed across mailNNN.com sister hosts (mail238/279/799 known) as a fake credits / fake banking platform. Users register, "recharge" (deposit), see fabricated balances, and cannot actually withdraw. Chunk names: pages-login-login, pages-recharge-index, pages-withdrawal-index, pages-record-index, pages-user-address-index. index.js is the SPA's entry chunk.

6 sightings3 hosts2026-05-23
sha256: ac1ccd9d40727c2f
ast: 41c9ab4ebe71fd9a
highother
J365 Gambling Platform — CometMarathon.js
family: j365-gambling-platform

Long-poll companion to Comet.js — secondary WebSocket channel used by the J365 illegal-gambling platform.

12 sightings5 hosts2026-05-25
sha256: e2bfb9fc21f2a1a6
ast: 28055543dc238a25
highother
J365 Gambling Platform — gui-base.js
family: j365-gambling-platform

Chinese-language illegal online-gambling platform served from a rotating set of brand-prefixed landing domains (j365*.xyz, lvs*.vip, hgty*.vip, hg*.vip, usdbetvip*.biz, xpj*.com — including punycoded variants) backed by a small set of operator CDN hosts on pham.xin and yqdkrj.com under the path /ftl/commonPage/. Offers fish-shooter, casino, sports, chess games. gui-base.js is the kit's shared UI framework.

12 sightings5 hosts2026-05-25
sha256: 4370313fa317e441
ast: 3505cf9008ade7dd
highother
J365 Gambling Platform — Comet.js
family: j365-gambling-platform

Custom WebSocket C2/heartbeat code (/websocket/Comet.js) used by the J365 illegal-gambling platform. Operator-specific real-time channel for bet placement, balance updates, and admin control.

12 sightings5 hosts2026-05-25
sha256: 6cf6e96f51f13834
ast: e038c6256687833b
criticalphishing
ShinyHunters Okta PassToken
family: okta-passtoken

Okta-themed brand-impersonation phishing kit. Landing URL has the ?passtoken=&redirect=/ signature; backend.php polls for MFA-bypass state; pingServer heartbeat; Telegram-channel credential exfiltration. Attributed to the ShinyHunters cluster.

2 sightings2 hosts2026-05-22
sha256: 8a01bcb70ec1c101
ast: 4a92f5e83fc948d0