Threat Hunting

Roster of known malicious kits and campaigns — each anchored to a deterministic structural fingerprint (byte-identical and obfuscation-resistant) or a YARA rule. Every scanned script and page is matched against this roster automatically.

139 kits6,428 total sightings
criticalphishing
gasing777 Indonesian Gambling Kit — uc_login.js
family: gasing777-indonesian-gambling

Login chunk of the Indonesian gambling kit (UC framework: uc_login.js).

556 sightings74 hosts2026-05-25
sha256: 465942d00c4cae69
ast: 729a72785a3cef61
criticalphishing
Gambling Vue PWA Kit — index-v431.js
family: gambling-vue-pwa-1fb0

127-host gambling/casino app Vue PWA kit. ONE operator running random brand hostnames across .shop/.world/.store/.site/.website/.com TLDs. Page titles include "Tower Rush", "Chicken Road", "Lucky Casino", "Chicken Road 2", "BEAST GAMES: ICE FISHING", "Ice Fishing", "Revolut Slots" (Revolut bank brand impersonation in a slots scam). Path pattern /assets/<chunk>-v431.js + PWA service workers (/PwaWorker.js, /push/vapp/VappWorker.js).

537 sightings209 hosts2026-05-24
sha256: 7abf588b07d22725
ast: 1fb0c3766220c5ef
criticalphishing
Gambling Vue PWA Kit — vue-core-v431.js
family: gambling-vue-pwa-1fb0

Vendor bundle of the gambling Vue PWA kit (Vue runtime core, v431 cohort).

528 sightings209 hosts2026-05-24
sha256: 0fe8127f44538ca5
ast: 8a824eec974b6222
criticalphishing
Gambling Vue PWA Kit — MarketPageComponent-v431.js
family: gambling-vue-pwa-1fb0

Marketplace page chunk for the gambling kit — renders the fake-casino game catalogue.

507 sightings202 hosts2026-05-24
sha256: 565876d5dc664fff
ast: 187852cef99fe78e
criticalphishing
gasing777 Indonesian Gambling Kit — page_searchgame.js
family: gasing777-indonesian-gambling

23+ host Indonesian gambling SPA. Brand titles: "Bansos188", "SKYLAR88", "SOGOSLOT", "Dausbet", "CAGURBET" — all Indonesian gambling brand patterns with "Slot Online", "Slot Gacor", "Anti Rungkat", "Maxwin" terminology. Hosts: gasing777tidakindex.shop, apktiptoplock.sbs, babejd.icu, cagurbetkyu.icu, ndxskylar88.click. Extensive feature set: live chat, login, banners, announcements, page searching.

346 sightings58 hosts2026-05-25
sha256: e99282e4269dfcbd
ast: 14c7b803f996cc0f
criticalphishing
gasing777 Indonesian Gambling Kit — root_desktop.js
family: gasing777-indonesian-gambling

Desktop layout module for the Indonesian gambling kit.

334 sightings44 hosts2026-05-25
sha256: 2f75b623b967d92b
ast: 6ea936d43d9c8d15
criticalphishing
Multi-Brand pages.dev Phish Kit — jg.js (universal handler)
family: multibrand-pagesdev-phish

Multi-brand credential-phishing kit deployed across 220+ *.pages.dev hosts under one operator. Brand cohorts: sso-godaddy (100h), update (39h), excel (16h), pdf/adobe/adobe-pdf (19h), 360-yandex-mail (9h), hostinger-mail (7h), nid-naver-mail (6h), zoho-mail, mailhostbox, nate-mail, dropbox, dhl, outlook-mail, office365-mail, we-tl, mail-one-update. Page title "Are you not a robot?" — fake-CAPTCHA pretext. jg.js is the shared handler script across all cohorts.

288 sightings225 hosts2026-06-09
sha256: 9201f2ee02b6b642
ast: bbe80426cb516fd8
criticalphishing
Gambling Vue PWA Kit — VappWorker.js (PWA service worker)
family: gambling-vue-pwa-1fb0

PWA service worker (/push/vapp/VappWorker.js) of the gambling kit. The PWA architecture is distinctive — most kits don't register service workers; this one does (for push notifications / offline-mode fake-app feel).

288 sightings225 hosts2026-05-24
sha256: b37c83b462175f61
ast: 9441f5048c62bfa4
criticalphishing
Multi-Brand pages.dev Phish Kit — js1.js (universal kit-internal)
family: multibrand-pagesdev-phish

Universal kit-internal js1.js across the multi-brand pages.dev operator. 206 hosts.

283 sightings216 hosts2026-06-09
sha256: 8adbc9ca2f539ad6
ast: b462ea640b31bda2
criticalphishing
Gambling Vue PWA Kit — App-v442.js (newer cohort)
family: gambling-vue-pwa-1fb0

Newer cohort build (v442) of the same gambling Vue PWA kit. Same operator, kit upgraded.

192 sightings82 hosts2026-05-24
sha256: 92d1994fbc007c3e
ast: 4dc6aafefd732c15
criticalphishing
Fake-Telegram Phishing Kit — webpack chunk 5193
family: fake-telegram-dashan

Webpack chunk 5193 of the fake-Telegram kit.

159 sightings126 hosts2026-05-24
sha256: 60df5c6365dba1e2
ast: 6163b9d82d607519
criticalphishing
btbuu Kit — Bursa Malaysia Stock-Exchange Extension
family: btbuu-bursa-malaysia-extension-7aa6

Extension of the existing btbuu-fake-crypto-exchange operator family targeting a new brand: Bursa Malaysia (Malaysian stock exchange). 7-host cluster including bursamalaysia.space, served from the same /Public/Static/js/layer/layer.js path the btbuu operator uses on btbuu.com and trade-maxs.com. Same operator, new brand.

135 sightings35 hosts2026-06-10
sha256: 01c1dac4350f12ee
ast: 7aa68afc79d60dc4
criticalphishing
Multi-Brand pages.dev Phish Kit — sso-godaddy js.js
family: multibrand-pagesdev-phish

GoDaddy SSO cohort js.js — 100 hosts.

128 sightings100 hosts2026-05-24
sha256: 4d19a14f029c727d
ast: 5d9aece34dc653ac
criticalphishing
Fake-Telegram Phishing Kit — redirect.js
family: fake-telegram-dashan

Massive 139-host Telegram brand-impersonation operation. ONE operator running random-letter hostnames across .icu/.sbs/.xyz/.top/.lat/.homes/.shop/.cn/.com/.org/.love/.life TLDs (dashan.icu, danvato.icu, eldravox.icu, claw111a.xyz, ai123h.xyz, bot789c.xyz, euhe-tg.com, htrx-tg.com, hujli.shop, telegarm-jp.org, yfhmg.love, fdshfgjd.{lat,homes}, …). Pages titled "Telegram" or "Secure Messenger". Operator-built Vue.js SPA. The "-tg" suffix in domain names and Japan/JP brand hints suggest Telegram-Japan credential-harvest focus.

115 sightings67 hosts2026-05-24
sha256: 375141f2d3f04c73
ast: a7840520d70cbd25
criticalphishing
AMP Futures Brand Impersonation — index.js
family: amp-futures-phish-a637

Brand-impersonation phishing kit targeting AMP Futures (US futures broker, ampfutures.com). Deployed across 62 random-letter .xyz hostnames matching pattern [a-z][0-9][a-z][0-9][a-z].xyz (a2q6w.xyz, a4k7n.xyz, b2k9t.xyz, …). All 62 hosts serve the page title "AMP Futures"; all were graded Low Risk or Medium Risk by the verdict layer.

68 sightings62 hosts2026-05-24
sha256: c5947182321ae741
ast: a637397379fb0f0f
criticalphishing
Multi-Brand pages.dev Phish Kit — update cohort js.js
family: multibrand-pagesdev-phish

"update" generic cohort js.js — 38 hosts.

49 sightings38 hosts2026-05-24
sha256: 925eb2c4c3e7d6da
ast: d0dd708a9d76e831
criticalphishing
Fake-Telegram Phishing Kit — compatTest.js
family: fake-telegram-dashan

Browser-compatibility probe of the fake-Telegram kit.

33 sightings27 hosts2026-05-24
sha256: 3ee5b1443f69c457
ast: 664a589b55e55226
criticalphishing
Fake-Telegram Phishing Kit — webpack chunk 7283
family: fake-telegram-dashan

Webpack chunk 7283 of the fake-Telegram kit.

26 sightings23 hosts2026-05-24
sha256: 1e558fa516560083
ast: fb2faeab79559bb4
criticalphishing
Telcel Mexico Brand Impersonation — index.js #2
family: latam-telcel-mx-phish-52aa

Companion build of the Telcel MX kit — same 23 hosts, second anchor chunk under the same /apps/MX_PT_06/ path.

26 sightings23 hosts2026-05-24
sha256: 11dd561046a293f3
ast: 21d2c7084985c7bb
criticalphishing
Telcel Mexico Brand Impersonation — index.js #1
family: latam-telcel-mx-phish-52aa

Brand-impersonation phishing kit targeting Telcel (Mexico's dominant mobile carrier). 23 hosts on .top/.vip with mx-prefixed names (mxstelcec.top, mxtecelah.top, mxtelelsuy.top, mxtelesvip.vip, …). URL path /apps/MX_PT_06/assets/index-*.js — the "MX_PT_06" naming matches the Tigo SV kit's "SV_PT_01", strong evidence of one operator running localized LATAM carrier kits.

26 sightings23 hosts2026-05-24
sha256: 12d9cc0136e05f8e
ast: 52aa5c54fed1ee67
criticalphishing
Tigo El Salvador Brand Impersonation — index.js #2
family: latam-tigo-sv-phish-1b7d

Companion build of the Tigo SV kit — same 19 hosts, second anchor chunk.

25 sightings19 hosts2026-05-24
sha256: 779fcf56e879ec5d
ast: 291e03be04471f90
criticalphishing
Tigo El Salvador Brand Impersonation — index.js #1
family: latam-tigo-sv-phish-1b7d

Brand-impersonation phishing kit targeting Tigo El Salvador (major LATAM telecom). 19 hosts on .cc/.help/.click/.art/.sbs/.top with tigo-prefixed names (sv-tigo.cc, tigoboss.help, tigosrwvp.help, tigovseop.click, tigovspom.help, …). Page title: "La primera Red 5G de El Salvador | Tigo El Salvador" (direct quote from real Tigo SV marketing). URL path /apps/SV_PT_01/assets/index-*.js — sister to the Telcel MX MX_PT_06 kit, same operator.

25 sightings19 hosts2026-05-24
sha256: b8d61f196248b37a
ast: 1b7de72432be2b3c
criticalphishing
Multi-Brand pages.dev Phish Kit — pdf cohort js.js
family: multibrand-pagesdev-phish

PDF/Adobe cohort js.js — 16 hosts.

21 sightings16 hosts2026-05-25
sha256: bdc585e39a502805
ast: 6cad13f1b0860ed1
criticalphishing
Multi-Brand pages.dev Phish Kit — excel cohort js.js
family: multibrand-pagesdev-phish

Excel/Office365 cohort js.js — 13 hosts.

19 sightings14 hosts2026-06-09
sha256: b3fdd88a11692fa9
ast: cace2b9510cf4905
criticalphishing
COMEX/Tada Cloud-Hosted Trading Kit — chunk-vendors
family: fake-trading-platform-d7a2

6-host operator hosting fake trading platform on Azure Static Web Apps + .top with port: comex309.z1.web.core.windows.net + secondary, tada1912.z23.web.core.windows.net + tada93179, web6699.313675.top:39395. "COMEX" = Commodity Exchange impersonation; "tada" branding signals throwaway cohorts.

14 sightings6 hosts2026-05-24
sha256: dd153fe7cf4e118a
ast: d7a27a645cee0cc8
criticalphishing
Multi-Brand pages.dev Phish Kit — naver cohort js.js
family: multibrand-pagesdev-phish

Naver (Korean) cohort js.js — 8 hosts.

13 sightings8 hosts2026-05-24
sha256: 6c20198ee0753ea1
ast: 8dbd7cc953c984f6
criticalphishing
Multi-Brand pages.dev Phish Kit — yandex js.js
family: multibrand-pagesdev-phish

360-yandex-mail cohort js.js — 9 hosts.

11 sightings9 hosts2026-05-24
sha256: cb289c2c092f0731
ast: c4166bf8d509ff23
criticalphishing
Medtronic Brand Impersonation — chunk-vendors.js
family: medtronic-impersonation

Vendor bundle for the Medtronic brand-impersonation kit. Vue+ElementUI+etc. compiled by the operator's specific webpack build.

11 sightings4 hosts2026-05-24
sha256: a2c9927c37f8d0ec
ast: 803f8f97e7113a41
criticalphishing
Medtronic Brand Impersonation — index.js
family: medtronic-impersonation

Brand-impersonation phishing kit targeting Medtronic (the medical-device manufacturer). Vue.js SPA deployed across 4 sister hosts (medtronicwmn.com, medtronicwrr.cc, medtronicwrz.com, medtronicwtt.cc) under /static/js/ paths. Chunks reveal a fake-login + fake-account-detail flow (pages-login, pages-welcome, pages-account-account-detail, pages-Detail, pages-Particulars).

11 sightings4 hosts2026-05-24
sha256: bd9dc2d635550092
ast: 2a818c058644f8c9
criticalphishing
Medtronic Brand Impersonation — pages-welcome-welcome.js
family: medtronic-impersonation

Welcome-page chunk for the Medtronic brand-impersonation kit. Small, highly diagnostic.

11 sightings4 hosts2026-05-24
sha256: c51ceee5624e7792
ast: 51107f7f0af254a9
criticalphishing
CME/AMEX/NYSE/Schwab Multi-Broker Impersonation — chunk-vendors
family: multi-broker-impersonation-195a

6-host operator running MULTIPLE major financial-brand impersonations from a single template: cmeamex.com, cmeamexs.com, cmenyse.com (CME+AMEX, CME+NYSE), schwabvs.com (Charles Schwab), tradesoksca.com, tradesokscs.com. Single SPA deployed under each broker's name.

8 sightings6 hosts2026-05-24
sha256: 9f011ba91090578d
ast: 195ac2a49d3b05b4
criticalphishing
login-client/metasuite Phishing Kit — main.js
family: login-client-metasuite-54de

4-host operator: login-client-6i5.pages.dev, metasuite-business.com cohort. Numbered "login-client" Cloudflare Pages deployments paired with "metasuite-business" branding — textbook MS 365 / business-suite credential-harvest naming.

7 sightings4 hosts2026-05-23
sha256: d9cb0357bf1752fb
ast: 54de74dfebdc817b
criticalphishing
COMEX/Ortex Trading Impersonation — chunk-vendors
family: comex-ortex-impersonation-61ea

6-host operator: comex-ex.com, comex-glob.com, comex-next.com, comex-next-desk.com, ortexlabs.com, ortexportal.com. COMEX + Ortex (real institutional trading-research firm) impersonation. Sister of the d7a2 cluster.

6 sightings6 hosts2026-05-24
sha256: 453c4ea305349139
ast: 61ea29ba81a626b9
criticalphishing
Chinese WhatsApp Impersonation — main.js
family: whatsapp-cn-bf71

5-host Chinese WhatsApp brand impersonation: it-web-whatsapp.hl.cn, llg-whatsapp.com.cn, etc. Third-region sister of whatsapp-bd-771c (Bangladesh) and whatsapp-pk-96b1 (Pakistan) — same kit-as-a-service operator targeting more countries.

5 sightings5 hosts2026-05-24
sha256: 7dd85aca2c29abbe
ast: bf712e0fcf12f967
criticalphishing
Shopify Brand Impersonation — chunk-vendors
family: shopify-impersonation-5512

1 host (shoopeifyus.com) impersonating Shopify. Triple-vowel "shoopeify" + "us" suffix is a textbook brand-typo phishing pattern.

5 sightings1 hosts2026-05-24
sha256: 01a748c2f61adcce
ast: 5512842a77086f7a
criticalphishing
OneKey Wallet Impersonation — chunk-vendors
family: onekey-impersonation-f866

2-host operator impersonating OneKey (real crypto-wallet brand). onekey1.com cohort. Crypto wallets are high-value phishing targets — credential theft = drained wallets.

5 sightings2 hosts2026-05-23
sha256: be58d76acb3308c6
ast: f86634325a133e48
criticalphishing
BitMart Crypto-Exchange Impersonation — chunk-vendors
family: bitmart-impersonation-cdcd

3-host operator impersonating BitMart (real crypto exchange). Surfaced via cosine pivot on btbuu-fake-crypto-exchange anchors. Hosts include bitmartsweb.com.

4 sightings3 hosts2026-05-23
sha256: 7dd75c6d0850e58c
ast: cdcd24061e2a346c
criticalphishing
ClickFix FakeCAPTCHA — LOLBin variant (msiexec/mshta/wmic/etc.)
family: clickfix-fakecaptcha

Same fake-CAPTCHA flow as the PowerShell variant but the copied command is a non-PowerShell Windows LOLBin (msiexec /i <URL>, mshta, wmic, certutil, regsvr32, curl, iex, Invoke-Expression). First validated live on 00c29c34fd.nxcli.io from threatfox's IClickFix-tagged feed (scan 52b189eb / 2f465516 / f6c071f8). Markup-tolerant string matchers (<b>R</b> / <b>V</b> / <b>Enter</b>) catch kits whose instruction text is HTML-formatted.

3 sightings1 hosts2026-05-27
criticalphishing
MeridianLink Lending-Tech Impersonation — chunk-vendors
family: meridianlink-impersonation-7cbc

3-host operator impersonating MeridianLink (real US lending/banking tech company). meridianlinkgroup.com cohort.

3 sightings3 hosts2026-05-24
sha256: c3f9b21ab5797a83
ast: 7cbc1fb043a7677a
criticalphishing
CME/NYSE Multi-Broker Sister Cohort — chunk-vendors
family: multi-broker-sister-e21c

Sister cohort of multi-broker-impersonation-195a. 3 hosts: cmenyses.com (CME+NYSE), cmekeya.com (CME+Keya). Same operator running additional broker-name combinations.

3 sightings3 hosts2026-05-24
sha256: 351a36c2e0c3153e
ast: e21c25c168f2f502
criticalphishing
FP Markets Forex Impersonation — chunk-vendors
family: fpmarkets-impersonation-3856

2-host operator impersonating FP Markets (real Australian forex broker). fpmarts.com cohort.

2 sightings2 hosts2026-05-22
sha256: 8fc61ae80db8d039
ast: 385699b684c6e16f
criticalphishing
TrustUcoin Crypto-Wallet Impersonation — chunk-vendors
family: trustucoin-impersonation-caba

1 host (trustucoin.com) impersonating Trust Wallet / Trust Coin brand.

2 sightings1 hosts2026-05-24
sha256: b1815d107dd560fb
ast: cabad64b4e940061
criticalphishing
ShinyHunters Okta PassToken
family: okta-passtoken

Okta-themed brand-impersonation phishing kit. Landing URL has the ?passtoken=&redirect=/ signature; backend.php polls for MFA-bypass state; pingServer heartbeat; Telegram-channel credential exfiltration. Attributed to the ShinyHunters cluster.

2 sightings2 hosts2026-05-22
sha256: 8a01bcb70ec1c101
ast: 4a92f5e83fc948d0
criticalphishing
Whale Exchange Impersonation — chunk-vendors
family: whale-exchange-impersonation-50a4

1 host (www.whaleoex.com) impersonating Whale (real crypto-derivatives exchange / similar branding).

1 sightings1 hosts2026-05-24
sha256: 7bc9f4fe65db112d
ast: 50a44be799fb4657
criticalphishing
Tokyo Financial Exchange Impersonation #2 — chunk-vendors
family: tokyo-financial-exchange-5833

Companion build of the Tokyo Financial Exchange impersonation kit. Same host (tokyofinancialexchange.work) but second chunk hash — different cohort build of the same kit.

1 sightings1 hosts2026-05-24
sha256: 5882914cb80ca205
ast: 58336fe7452c1110
criticalphishing
Tokyo Financial Exchange Impersonation #1 — chunk-vendors
family: tokyo-financial-exchange-bd76

1 host so far (tokyofinancialexchange.work) impersonating Tokyo Financial Exchange (real Japanese exchange). Operator-built anchor — canonical_ast_hash trigger will catch any future cohort rebuilds.

1 sightings1 hosts2026-05-24
sha256: 5db10d8472ba73c8
ast: bd765b0d6817de52
criticalphishing
MTS Gold Impersonation — chunk-vendors
family: mts-gold-impersonation-22fc

1 host (mtsgoldr.com) impersonating MTS Gold (real precious-metals broker). The trailing "r" is typo-brand phishing.

1 sightings1 hosts2026-05-22
sha256: 4aad80655719d4e9
ast: 22fc9cb63d94952d
criticalphishing
ClickFix FakeCAPTCHA — PowerShell variant
family: clickfix-fakecaptcha

Fake-CAPTCHA HTML page that copies a `powershell -enc <base64>` command to clipboard for the victim to paste into Win+R. Social-engineering pretext: "Verify you are human" / "Not a robot" / "Verification Steps" / "Press Windows Key + R / Ctrl + V / Enter". YARA rule reports 283 samples matched, >60% zero AV detection at time of analysis.

0 sightings0 hosts
highphishing
Indonesian Gambling Next.js Kit — pages/index #1
family: indonesian-gambling-nextjs

Next.js SPA deployed across 37+ Indonesian-language online gambling sites. Brand+number naming (ammo88jaya, apek88-apk2, banteng328bersama, banteng328goyang.site, bos56.xyz, dragon969resmi.site, elang55b.com, eth77original.site, …). Page titles in Bahasa Indonesia: "Situs Slot Online Gampang Menang", "Login Situs Slot 4d Mahjong yang Pasti Bayar 2025", "RTP Gacor Hari Ini" (slot/mahjong/RTP terminology).

133 sightings37 hosts2026-05-24
sha256: 88fa9fe9bff0cafd
ast: c38e7ac86c6d19db
highphishing
Gambling Rotation Kit (.win/.mom/.vip) — chunk-vendors
family: gambling-vip-win-kit-d0d844

Online-gambling/betting kit deployed across 43 brand-prefixed hostnames on .win/.mom/.vip TLDs. Includes 1xbet-style impersonation (1x-clz.vip, 1x-gzm.vip, 1x-xl.vip) and generic bet/win brands (0227bet.win, 107win.mom, 208win2.vip). All hosts graded "Low Risk" or "Medium Risk".

110 sightings43 hosts2026-05-24
sha256: d16088f9201a6156
ast: d0d844a485875495
highphishing
Random-TLD Multi-Domain Rotation Kit — main.v2.js
family: hevvugu-multi-domain

Single shared main.v2.js deployed across 17 throwaway domains on cheap/suspicious TLDs (.icu, .sbs, .cfd, .cyou, .shop, .wiki, .one, .asia, .club). Includes telegran.one — Telegram brand impersonation. The 17 hosts have inconsistent verdicts (Low Risk → Malicious); the roster catches all of them via a single fingerprint.

84 sightings32 hosts2026-05-24
sha256: 6bf5a0f55daa60a3
ast: fd5ed316ed4cc419
highphishing
Random-Domain Vue Scam Kit (icu/sbs/shop/cyou) — chunk-vendors
family: random-domain-kit-0e990c

Vue.js webpack SPA deployed across 63 random-letter hostnames on .icu/.sbs/.cyou/.shop TLDs. Hostnames are keyboard-mash strings (e.g. baiiwerogkasdfg.sbs, bbqupospdkgkaj.shop, bjioqjksdjkskzx.cyou). Every host in the cluster was graded "Low Risk" or "Medium Risk" by the verdict layer.

75 sightings63 hosts2026-05-25
sha256: 834ae39993dcd84a
ast: 0e990c84e7d4894d
highphishing
Indonesian Gambling Next.js Kit — pages/_app
family: indonesian-gambling-nextjs

Companion pages/_app build for the Indonesian gambling Next.js SPA.

57 sightings30 hosts2026-05-24
sha256: cfc02413fb7cf119
ast: ba5e07a8d93bce1b
highphishing
Random-Domain Vue Scam Kit (cyou/shop/sbs) — chunk-vendors
family: random-domain-kit-9f38c9

Vue.js webpack SPA deployed across 33 random-letter hostnames on .cyou/.shop/.sbs/.icu TLDs (oodjdfuigewjkfdssf.cyou, bcmnrjwyrishfdjdgf.shop, dsfjngfwisdjfoisdjs.shop, …). TLSH body identical to the 0e990c cluster — likely the same template, different operator cohort.

46 sightings33 hosts2026-05-24
sha256: 164eac04259ecb4e
ast: 9f38c99b21913bcd
highphishing
.forum TLD Rotation Kit — chunk-vendors
family: forum-tld-kit-b86d1a

Vue.js webpack SPA deployed across 40 hostnames ALL on the .forum TLD with 8-character random hostnames (cmkpxlpv.forum, lhivtxfx.forum, ruxkxjyybs.forum, …). The uniformity of TLD + filename-length is a strong operator signal.

44 sightings40 hosts2026-05-23
sha256: ce3d2e4fb9f2fc2a
ast: b86d1a00104d2763
highphishing
Chinese Kaiyun Gambling Kit — js/app
family: cn-kaiyun-gambling-7460

42-host Chinese gambling operator running "Kaiyun" brand impersonation across cn-kaiyunapp.vip, zh-kaiyuntiyu.vip, danti4833.com subdomains with random hostname prefixes. Path pattern /js/app.<hash>.js. Kaiyun (开云) is a known Chinese gambling brand frequently impersonated; "kaiyun" naming + Chinese-numeric subdomains is a strong operator signature.

42 sightings42 hosts2026-05-25
sha256: 84782284c7ec7fbf
ast: 746038d26798d27a
highphishing
.forum TLD Rotation Sister Cohort (f96966) — js/app
family: forum-tld-sister-f969

Sister cohort of forum-tld-kit-b86d1a / forum-tld-kit-6ed2. 39 .forum hosts with uniform 8-char random hostnames (bgvwaihj.forum, bosmehqu.forum, …). Path pattern /js/app.<hash>.js — different chunk path than the earlier forum kits.

39 sightings39 hosts2026-05-22
sha256: c5ac711bb2bc1ec9
ast: f96966e057e047f2
highphishing
.click TLD Rotation Kit — chunk-vendors
family: click-tld-kit-a260ef

Vue.js webpack SPA deployed across 31 hostnames ALL on the .click TLD with 8-character random hostnames (aicjgkjk.click, cbcsljlc.click, pshhttokse.click, qhzelnxa.click, …). Uniform TLD + hostname pattern is a strong operator signal.

39 sightings31 hosts2026-05-24
sha256: 456b1a5957805e4a
ast: a260efe80f4a4801
highphishing
Random-Letter Multi-TLD Kit (cyou/shop/qpon/click) — 26h
family: random-letter-multitld-8c1c

Vue.js webpack SPA across 26 random-letter hostnames on .cyou/.shop/.qpon/.click/.icu TLDs (huwhnkjahksjwnak.cyou, klajlkza12jasdjk131.click, mblgfkltkllpuoprfltp.icu, …). Same kit-as-a-service template as the migration-080 random-domain kits.

36 sightings26 hosts2026-05-23
sha256: e724905a3b420276
ast: 8c1c86c077f2e1c0
highphishing
teje-rotating-domain kit — 2976.js
family: teje-rotating-domain

Numeric webpack chunk for the teje-rotating-domain kit.

36 sightings6 hosts2026-05-23
sha256: 259a29a5b25f869b
ast: fc103f2af5d57b5d
highphishing
Random-Domain Vue Scam Kit (sbs/qpon/cyou) — chunk-vendors
family: random-domain-kit-c73042

Vue.js webpack SPA deployed across 32 random-letter hostnames on .sbs/.qpon/.cyou/.click/.icu TLDs (iewyrgajdghfvdhdjs.sbs, jkahskdnzl6kajhmza.qpon, …). Includes the .qpon TLD which is rare and a strong scam-infrastructure marker.

35 sightings32 hosts2026-05-24
sha256: 57b551724bafaf27
ast: c73042d87dee76b1
highphishing
Random-Letter Multi-TLD Kit (icu/cyou/qpon/sbs) — 21h
family: random-letter-multitld-9d69

Vue.js webpack SPA across 21 random-letter hostnames on .icu/.cyou/.qpon/.shop/.click/.sbs TLDs. Sister cohort of the kit-as-a-service template.

30 sightings21 hosts2026-05-24
sha256: 59f2136c658bb9a0
ast: 9d69598d7dc9c06f
highphishing
Random-Letter .com Rotation Sister — js/app
family: random-letter-com-sister-a218

Sister cohort of random-letter-com-199c. 18 hosts with 10-letter random .com hostnames (2zrlupki.com, luckrfbyjg.com, …). Different bundler path (/js/app.<hash>.js) than the original 199c kit.

28 sightings18 hosts2026-05-24
sha256: e08ba4c5bb4b2307
ast: a218803fc5c5e5cc
highphishing
status-account-NNN.pages.dev Scam Kit — index.js
family: status-account-pagesdev-4455

19-host operator running numbered Cloudflare Pages deployments: status-account-{8,10,13,14,16-21,43,53,70,71,75,122,123,124,125}.pages.dev. Hostnames are textbook account-suspended phishing pattern (Microsoft/Google "your account has been suspended" credential harvest).

26 sightings19 hosts2026-05-25
sha256: 7104333d5b7a42fe
ast: 4455ca38966d3e48
highphishing
Portuguese/Brazilian Gambling Rotation — chunk-vendors
family: pt-brazil-gambling-80be

8-host operator running Portuguese/Brazilian-language gambling brands: 54rr.win, 91-earring-pg.vip, muito-777.win ("777" + Portuguese for "a lot"), okokflash.mom, voy-brow-pg.vip, we-operapg.mom ("opera-pg"), wgbetkk.win, wg-relogio.win ("relogio" = watch).

24 sightings8 hosts2026-05-24
sha256: cf7c65b6c64c32af
ast: 80be79f13f588948
highphishing
Meituan Brand Impersonation + Chinese Names — chunk-vendors
family: meituan-impersonation-c171

Operator across 16 hosts impersonating Meituan (Chinese super-app): qiqimeituan.xyz, shengmeituan.xyz, plus generic Chinese-themed names (songsong123.xyz, tangtang123.asia, zhanxupeng6.asia) and qazwsxNNN.asia placeholders.

22 sightings16 hosts2026-05-25
sha256: ed528efb979a5d8d
ast: c171df7eae858756
highphishing
.click TLD Rotation Kit (b) — chunk-vendors
family: click-tld-kit-1f93

Vue.js webpack SPA across 17 hostnames mostly on .click TLD (bpqsfyum.click, deddrvta.click, hxrygdhl.click, …) plus shakti.top and tea01.bahfn.cn. Different operator from a260ef.

22 sightings18 hosts2026-05-25
sha256: dc6aff7b6af74d25
ast: 1f93def433746651
highphishing
Random-Letter Multi-TLD Kit (icu/click/cfd) — 15h
family: random-letter-multitld-4ba7

Vue.js webpack SPA across 15 random-letter hostnames on .icu/.click/.cyou/.cfd/.shop/.sbs TLDs.

21 sightings15 hosts2026-05-24
sha256: d790d7ba2e47a11a
ast: 4ba7a0589a341f3e
highphishing
Random-Letter Multi-TLD Kit (shop/sbs/cyou/icu) — 13h
family: random-letter-multitld-74f3

Vue.js webpack SPA across 13 random-letter hostnames on .shop/.sbs/.cyou/.icu TLDs.

20 sightings13 hosts2026-05-24
sha256: 159e65e8d02e6bb8
ast: 74f3e3d4dbb851b4
highphishing
YJDM Numbered Brand Series — chunk-vendors
family: yjdm-numeric-f7d1

Operator running a numbered series of `yjdm[NNNN].com` + `yjdm[NNN].club` sister hosts (yjdm1371-1395.com, yjdm332-355.club — 18 hosts total). Likely Chinese gambling/lottery brand.

20 sightings18 hosts2026-05-25
sha256: 190acfbeaec13e1f
ast: f7d1a6213697c92b
highphishing
rwusdt/axex/safe Crypto Wallet Impersonation — chunk-vendors
family: rwusdt-axex-safe-e232

Operator running multi-brand crypto-wallet impersonation across 17 hosts: rwusdtc[a-y].com (USDT impersonation), axexclub/axexhub on .com+.top, safeger/safegnr/safetar.com, plus dbecrede.com, exintir.com. Fake-wallet credential harvesting.

20 sightings17 hosts2026-05-25
sha256: 72e50786bc5e7149
ast: e2322b1c7fa3e700
highphishing
Random-Letter .com Rotation — chunk-vendors
family: random-letter-com-199c

11-host operator running 10-letter random .com hostnames (cjnwqvprty.com, dkpvtrmzla.com, fgrtqpxlme.com, …).

19 sightings11 hosts2026-05-24
sha256: bc2afc0a62439d41
ast: 199c83f3dc8f5113
highphishing
Random-Letter Multi-TLD Kit (shop/cyou/icu/sbs) — 16h
family: random-letter-multitld-8999

Vue.js webpack SPA across 16 random-letter hostnames on .shop/.cyou/.icu/.sbs TLDs.

19 sightings16 hosts2026-05-25
sha256: 6299bc4af81c01fe
ast: 89994cadce8a60b2
highphishing
Azure/Tencent Cloud Storage Abuse Kit — chunk-vendors
family: cloud-storage-abuse-72ea

7-host operator abusing free cloud storage to host the SPA: 5 Azure Static Web Apps (*.zNN.web.core.windows.net) + Tencent Cloud Object Storage (*.pichk.myqcloud.com). The cloud-vendor domains lend false legitimacy.

18 sightings7 hosts2026-05-24
sha256: 0e8c5aefedc14ca1
ast: 72ea0edd14bc5180
highphishing
.forum TLD Rotation Kit (b) — chunk-vendors
family: forum-tld-kit-6ed2

Vue.js webpack SPA across 17 .forum TLD hosts (bqetfpng.forum, bvgapqrm.forum, djtzmlwl.forum, …). Distinct operator from the migration-080 b86d1a cluster.

18 sightings17 hosts2026-05-22
sha256: 7269af925516b3e1
ast: 6ed2ce87def9f57e
highphishing
.forum TLD Rotation Sister Cohort (cc0aeb) — js/app
family: forum-tld-sister-cc0a

Sister cohort #2 of the .forum-TLD rotation family. 17 hosts with random 10-char hostnames (hvwvwvjwso.forum, nbilrwodrt.forum, …). Different build hash from f969.

17 sightings17 hosts2026-05-23
sha256: 3b4b47338201582e
ast: cc0aeb09a46919c8
highphishing
Random-Letter Multi-TLD Kit (cyou/icu/shop/sbs) — 16h
family: random-letter-multitld-95ed

Vue.js webpack SPA across 16 random-letter hostnames on .cyou/.icu/.shop/.sbs TLDs.

17 sightings16 hosts2026-05-25
sha256: 00a3c04b868fe2be
ast: 95ed255c605216b6
highphishing
BitMax Crypto-Exchange Impersonation — chunk-vendors
family: bitmax-impersonation-8632

5-host operator impersonating BitMax (real crypto exchange now rebranded to AscendEX). bitmax123.com cohort.

16 sightings5 hosts2026-05-24
sha256: 75e8f139ce332b1f
ast: 8632a2771850661b
highphishing
Random-Letter Multi-TLD Kit (icu/shop/cyou/sbs) — 15h
family: random-letter-multitld-9cba

Vue.js webpack SPA across 15 random-letter hostnames on .icu/.shop/.cyou/.sbs TLDs.

16 sightings15 hosts2026-05-25
sha256: cafe5e1e8ae907cb
ast: 9cbad927fd759031
highphishing
Cimamedia/Speedride Sister-Brand Rotation — chunk-vendors
family: cimamedia-speedride-682f

15-host operator running two parallel brand prefixes: cimamedia[88|92|9i|aa|io|ip|vi|vip|vvip].com and speedride[88|92|9i|ia|io|vi].com.

15 sightings15 hosts2026-05-24
sha256: ba82cc04e52e3e29
ast: 682fef0b99fc7b9a
highphishing
nyedfrt Numbered .top Series — chunk-vendors
family: nyedfrt-top-3af6

10-host numbered series operator: 532810.top, nyadegd[326|517].top, nydash812.com, nyedfrt[017|195|367|591|728|937].top.

15 sightings10 hosts2026-05-23
sha256: 6ac8277c4b729f04
ast: 3af68fe57ddff5f6
highphishing
acce* Prefix Rotation — chunk-vendors
family: acce-prefix-d0ae

12-host operator running acce[afae|afaf|dew|dzz|eann|haiu|kioa|lnn|mfg|mmrk|qrf|rmk].com sister hosts. Uniform `acce` prefix, two-three random suffix characters.

14 sightings12 hosts2026-05-24
sha256: 42cf479e4079992a
ast: d0ae69c765a1748c
highphishing
bbq/carros/ty Portuguese Brand Rotation — chunk-vendors
family: bbq-carros-pt-03a5

9-host operator running Portuguese-language brand impersonation: bbq-kf.com, bbqkf.com, bbqkfpg.com, carros-ty.com, carrosty.com, okcarros.com, ty-carros.com, tycarros.com, vip-carros.com (BBQ + cars).

14 sightings9 hosts2026-05-24
sha256: 73c6cbe13389b504
ast: 03a5675e5dad98b9
highphishing
[X][N].cn Random-Pattern Kit — chunk-vendors
family: letterhex-cn-25f3

7-host operator on .cn TLD with letter+digit random pattern: j3h1k9.cn, m9u6y0.cn, n4c6v5.cn, p4i6o3.cn, q4x9v6.cn, q7e2r6.cn, q8t4y7.cn.

14 sightings7 hosts2026-05-25
sha256: 1b97eb47489c928a
ast: 25f302f9303d140f
highphishing
Auto-Word-Pair Brand Rotation (shop/com) — chunk-vendors
family: wordpair-shop-0d56

10-host operator running auto-generated word-pair brand names: deeply-marketsearch.com, deeps-datastudy.com, finely-stylecraft.com, quicks-cdbuild.com on .com + findraregive/getfastrun/grabfreshsell/keepgoodsave/makesweetbake/picksmartubuy on .shop. Lure: looks like quick-build / market-research / save-money brand.

13 sightings10 hosts2026-05-25
sha256: ed2a1e88067fdf0b
ast: 0d565e03ac5acc68
highphishing
Brazilian Gambling Sister Cohort (7v-) — chunk-vendors
family: pt-brazil-gambling-sister-9e19

5-host Brazilian Portuguese gambling sister of pt-brazil-gambling-80be. Hosts: 7v-elefante.com, 7v-leao.vip ("elephant", "lion"). Same operator, 7v-prefix cohort.

12 sightings5 hosts2026-05-24
sha256: 56d9f1e60b072a2f
ast: 9e190ec3029d8485
highphishing
teje-rotating-domain kit — compatTest.js
family: teje-rotating-domain

Browser-compatibility probe used by the teje-rotating-domain kit. Tiny but unique.

12 sightings8 hosts2026-05-24
sha256: 15c24ec2b4cb94f2
ast: a275790c6a6dc010
highother
J365 Gambling Platform — CometMarathon.js
family: j365-gambling-platform

Long-poll companion to Comet.js — secondary WebSocket channel used by the J365 illegal-gambling platform.

12 sightings5 hosts2026-05-25
sha256: e2bfb9fc21f2a1a6
ast: 28055543dc238a25
highother
J365 Gambling Platform — Comet.js
family: j365-gambling-platform

Custom WebSocket C2/heartbeat code (/websocket/Comet.js) used by the J365 illegal-gambling platform. Operator-specific real-time channel for bet placement, balance updates, and admin control.

12 sightings5 hosts2026-05-25
sha256: 6cf6e96f51f13834
ast: e038c6256687833b
highother
J365 Gambling Platform — gui-base.js
family: j365-gambling-platform

Chinese-language illegal online-gambling platform served from a rotating set of brand-prefixed landing domains (j365*.xyz, lvs*.vip, hgty*.vip, hg*.vip, usdbetvip*.biz, xpj*.com — including punycoded variants) backed by a small set of operator CDN hosts on pham.xin and yqdkrj.com under the path /ftl/commonPage/. Offers fish-shooter, casino, sports, chess games. gui-base.js is the kit's shared UI framework.

12 sightings5 hosts2026-05-25
sha256: 4370313fa317e441
ast: 3505cf9008ade7dd
highphishing
Random-Domain Vue Sister Cohort (3ed975) — chunk-vendors
family: random-domain-sister-3ed9

Sister cohort of the existing random-letter-multitld-4ba7 kit. 6 hosts: klajlzmopkiak9kanz.{icu,qpon}, myj9qlcd05jj.qpon, nhgijgskjmriaks.icu, yjksnolkdjhikakr.{click,cyou}. Cosine-pivoted at sim=1.0000.

11 sightings6 hosts2026-05-23
sha256: a7e6053eab96dc2d
ast: 3ed975d6df23ad49
highphishing
andes* Prefix Rotation — chunk-vendors
family: andes-prefix-4556

8-host operator running andes-prefixed brands: andekhu5, andesapply24, andesapply8k, andeshsk11, andesiodshuqian22, andesjhsh2, andessdf3, andsskli8 on .com.

11 sightings8 hosts2026-05-23
sha256: 3118af6c53c27589
ast: 45568096f11b3baf
highphishing
Deeply-Nested Random Subdomains — chunk-vendors
family: nested-subdomain-9003

7-host operator using DEEPLY-NESTED random subdomains (4+ labels): cccys.zokide.6x1qko1.com, ccyy.xmsck.jluoo8h.com, cuiu.yw9u2e.esh536.com, cyppt.apxpiff.ztlcsqwf.com, cyqqt.x01jjex.ay9fc.com, cyttp.cokpa.lyaj69w.com, hue.oaiweu.6o99od.com. Wildcard-DNS abuse pattern.

11 sightings7 hosts2026-05-24
sha256: 9820b3d4882221ed
ast: 90039727879e8821
highphishing
hhmh Numbered Brand Series — chunk-vendors
family: hhmh-numeric-891d

10-host numbered series: hanhan12.com + hhmh1[386|387|388|389|390|397|398|399|400].com.

10 sightings10 hosts2026-05-24
sha256: e477b368e396d95f
ast: 891d4e8f15135644
highphishing
btbuu Fake Crypto Exchange — kline.min.js
family: btbuu-fake-crypto-exchange

Fake crypto-derivatives exchange kit. Operator-deployed K-line / Contract / Trade UI across btbuu.com, wbitx.cfd, trade-maxs.com, evergreen-capital.org. Path pattern /Public/Static/js/*, page pattern /Contract/index, /Trade/index?type=buy&symbol=*. Earlier sweep had bounced on the kit's pako.min.js (real zlib library) — these are the operator-specific files.

10 sightings5 hosts2026-05-24
sha256: 6f141e75fb299645
ast: be431f34f2f765fd
highphishing
btbuu Fake Crypto Exchange — ws-deedfeeds.js
family: btbuu-fake-crypto-exchange

WebSocket feed client used by the btbuu fake crypto-exchange UI to render fake real-time price ticks.

10 sightings5 hosts2026-05-24
sha256: 40c8218a42f4dadf
ast: 21e150991f2a87dd
highphishing
htxnadf.top Operator — js/app
family: htxnadf-2503

5-host operator running random-named .top hostnames anchored on htxnadf.top.

9 sightings5 hosts2026-05-24
sha256: 69fcb27026b08ca4
ast: 2503627a0bf781f7
highphishing
Azure Static Web Apps Sister Cohort — chunk-vendors
family: azure-swa-sister-119a

Sister of the existing `cloud-storage-abuse-72ea` kit. 5 hosts on Azure Static Web Apps: abw219, hk3091, london25, nsd90317, xdl719 — geographic-cohort naming (HK=Hong Kong, london, etc.) suggests targeted-region phishing.

9 sightings5 hosts2026-05-24
sha256: d92a79b05f0c944e
ast: 119a352ab882fd25
highphishing
aaoopg/eejjkf Multi-TLD Same-Prefix Kit — chunk-vendors
family: aaoopg-eejjkf-02d6

9-host operator running aaoopg.{app,cc,net,one,vip} + eejjkf.{app,com,net,one}. Same prefix across multiple TLDs — characteristic of bulk-domain phishing.

9 sightings9 hosts2026-05-24
sha256: c86e2531db3c70fd
ast: 02d6854acc416c94
highphishing
xpj/uuyl Numeric Lottery/Gambling — chunk-vendors
family: xpj-uuyl-1a5e

7-host operator: 266229.com, 500698.com, 500798.com, klyl6.net, www.uuyl.net, www.uuyl.xyz, xpj2487.com. Chinese-style numeric gambling/lottery brands.

9 sightings7 hosts2026-05-25
sha256: 47a1e33272718e00
ast: 1a5efee5179866ce
highphishing
chd-suffix .com Random Rotation — chunk-vendors
family: chd-suffix-com-f6c1

7-host operator: aeychdent.com, caichdfdt.com, daochderu.com, ejgchdcbt.com, fjhchdlep.com, gajchdvbt.com, hajchdkru.com. Uniform `chd` substring at positions 4-6 in random-alpha .com hostnames.

9 sightings7 hosts2026-05-24
sha256: 10b4f1400e753ae9
ast: f6c12af645a09a8e
highphishing
teje-rotating-domain kit — main.js
family: teje-rotating-domain

Webpack-bundled SPA deployed across an 8-host rotation that all share the `teje` prefix on cheap/suspicious TLDs (tejehqnfih.work, tejehqzjxt.club, tejeiviusk.asia, tejeiwdeow.cloud, tejeiycpyh.asia, tejeizzifa.wiki, …). Most graded Malicious by the verdict layer, some Low Risk — the roster catches the misses.

9 sightings6 hosts2026-05-23
sha256: ff07595993768488
ast: 0431f7cd7a178c89
highphishing
Wildcard-DNS Port-3443 Cohort — chunk-vendors
family: wildcard-port3443-aa15

4-host wildcard-DNS abuse sister of nested-subdomain-9003, serving on non-standard port 3443: tyyx.dakowe.1bdbr3.com:3443, tyyx.ooios.mgqlfa.com:3443.

8 sightings5 hosts2026-06-09
sha256: 1fe80c98689db948
ast: aa15624d01589eb7
highphishing
xt Prefix .com Rotation — chunk-vendors
family: xt-prefix-295e

7-host operator: xtcuf.com, xtdli.com, xtfue.com, xtjvn.com, xtlwh.com, xtnmc.com, xtpxd.com. Uniform xt[CCC].com pattern.

8 sightings7 hosts2026-05-24
sha256: 5441732c97b13508
ast: 295e6e76305e02a7
highphishing
Random-Alphanumeric .vip Kit — chunk-vendors
family: random-vip-alphanum-0165

7-host operator running long random alphanumeric .vip hostnames: cxwf0r2o9t9w1o9w7.vip, hiut9h0v4l2d7a7v0.vip, ijne8g2c1f5q0f9l5.vip, kmkf1e3z8z8s5q2k0.vip, vbja9y9n8u0w5s2b6.vip, vbjk2x2t9z3m6g7s2.vip, vcve2mcixbkl3kfd32fg.vip.

8 sightings7 hosts2026-05-24
sha256: f52d36e50bdde79b
ast: 0165362030b69da3
highphishing
Pionex Crypto-Bot Brand Impersonation — chunk-vendors
family: pionex-impersonation-b14b

5-host operator impersonating Pionex (real crypto trading bot platform): pioddnexqye.com, pionexadv.com, etc. The "pionex" substring is the operator's mimicry of the brand.

7 sightings5 hosts2026-05-23
sha256: 127f1c7fd5f4352b
ast: b14b11e28b278e34
highphishing
Pages.dev + .top Mixed Rotation — chunk-vendors
family: pagesdev-top-1b9a

7-host mix of Cloudflare Pages + .top TLDs: elmapp.pages.dev, ggzszfl.top, ghtsmr.top, hptsmn.top, mgtred.top, qnqb61.top, sizeg.top.

7 sightings7 hosts2026-05-24
sha256: 813f5be7488249a4
ast: 1b9addc68e62635e
highphishing
WhatsApp Brand Impersonation — chunk-vendors
family: whatsapp-bd-771c

7-host operator impersonating WhatsApp: bd1whatsapp.com, bd2wapp.com, bd2whatsapp.com, bd3wapp.com, bd3whatsapp.com, bdwhatsapp.com, pk6wagetmoney.com. The "bd"/"pk" prefixes suggest Bangladesh/Pakistan targeting.

7 sightings7 hosts2026-05-24
sha256: e5cba98752db082d
ast: 771cbd9ee0d126e1
highphishing
Pages.dev Vue Investment Scam — vindax index.js
family: pagesdev-vue-investment-scam

Entry chunk for the Pages.dev Vue investment-scam kit (vindax cohort build).

7 sightings3 hosts2026-05-23
sha256: 1d10b3652b773c82
ast: db03fe660d6e837c
highphishing
Pages.dev Vue Investment Scam — vindax cohort chunk-vendors
family: pagesdev-vue-investment-scam

Cloudflare-Pages-hosted Vue.js fake-investment kit. ONE operator running brand cohorts (vindax/mint/digtal/pimco impersonation) on *.pages.dev, all sharing the same Vue.js webpack skeleton with cohort-specific branding strings. This anchor catches the vindax-1xy / vindax-9io / mint-5st cohort.

7 sightings3 hosts2026-05-23
sha256: 2a329bc31db7cd82
ast: a0d231cf5829f876
highphishing
Pages.dev Vue Investment Scam — vindax pages-index-index.js
family: pagesdev-vue-investment-scam

Index page chunk for the Pages.dev Vue investment-scam kit (vindax cohort build). Shows the fake exchange order book.

7 sightings3 hosts2026-05-23
sha256: aee9cf33d68c9f8d
ast: 6e5fd4de1c98138f
highphishing
Random-Letter Multi-TLD Sister Cohort (3cdd1b) — chunk-vendors
family: random-letter-sister-3cdd

6-host sister cohort of the random-letter-multitld kit family. Random keyboard-mash hostnames on .icu/.shop.

6 sightings6 hosts2026-05-24
sha256: feb8fc67f986ed5b
ast: 3cdd1bbb090720fc
highphishing
crimsonagility Numbered Brand Rotation — chunk-vendors
family: crimsonagility-2724

6-host numbered-brand series: crimsonagility[22|33|55|…].com.

6 sightings6 hosts2026-05-23
sha256: d0139214d19ab601
ast: 2724d49cfa5fc2d4
highphishing
Cimamedia/Speedride Sister Cohort — chunk-vendors
family: cimamedia-speedride-sister-5f2e

Sister cohort of the existing `cimamedia-speedride-682f` kit: cimamedia0i.com, cimamedia99.com, cimamediaia.com, speedride0i.com, speedridecc.com, speedridezz.com. Same operator, second build hash.

6 sightings6 hosts2026-05-24
sha256: 780f720c4be1039d
ast: 5f2eb35d9064c8ed
highphishing
Wildcard-DNS Multi-Subdomain Sister Cohort — chunk-vendors
family: nested-subdomain-sister-86c0

Sister of the existing `nested-subdomain-9003` kit using wildcard-DNS abuse with deeply-nested random subdomains: lycl.cjilea.b7ryzkx.com, lypz.j9ado3.ikxoxfjp.com, uicl.oiusnx0w0.c7m26j3n2k.com:3443 (also serving on non-standard port 3443).

6 sightings6 hosts2026-05-24
sha256: 6184aec1ea2fc303
ast: 86c0cf3defc9e36d
highphishing
Pakistan WhatsApp Impersonation — chunk-vendors
family: whatsapp-pk-96b1

Pakistan-targeting WhatsApp brand impersonation: pak2whatsapp.com, pak3whatsapp.com, pakwhatsapp.com, pk2wapp.com, pk3wagetmoney.com, pk7wagetmoney.com. Sister of the existing `whatsapp-bd-771c` Bangladesh cohort — same kit-as-a-service operator targeting different countries.

6 sightings6 hosts2026-05-23
sha256: 8abaae6bd2da7d74
ast: 96b19170f3dadc62
highphishing
mailNNN.com Credits Scam — index.js
family: mail-credits-scam

Vue.js single-page application deployed across mailNNN.com sister hosts (mail238/279/799 known) as a fake credits / fake banking platform. Users register, "recharge" (deposit), see fabricated balances, and cannot actually withdraw. Chunk names: pages-login-login, pages-recharge-index, pages-withdrawal-index, pages-record-index, pages-user-address-index. index.js is the SPA's entry chunk.

6 sightings3 hosts2026-05-23
sha256: ac1ccd9d40727c2f
ast: 41c9ab4ebe71fd9a
highphishing
mailNNN.com Credits Scam — pages-home-index.js
family: mail-credits-scam

Home/dashboard chunk showing fabricated account balances after login.

6 sightings3 hosts2026-05-23
sha256: 908dfba02fa1a2e0
ast: b30fdf0a494c0532
highphishing
Golden Shield AI Investment Scam — chunk-vendors
family: goldenshieldai-47907a

4-host operator running "Golden Shield AI" investment-scam brand across multi-TLD: goldenshieldai.homes, goldenshieldai.lat, goldenshieldai.online. Same brand, throwaway TLDs.

5 sightings4 hosts2026-05-25
sha256: a362881fca1e9fe3
ast: 47907aea0ff497ab
highphishing
DDEX DEX Impersonation — chunk-vendors
family: ddex-impersonation-a692

4-host operator impersonating DDEX (decentralized exchange brand): ddex319.top, ddex329.top, plus raw IP 112.213.125.56:35971. The raw-IP serving is suspicious infrastructure.

5 sightings4 hosts2026-05-24
sha256: 5c520023c4fea99d
ast: a6920bca60e00824
highphishing
mailNNN.com Credits Scam — pages-login-login.js
family: mail-credits-scam

Login page chunk for the mailNNN.com fake-credits Vue SPA. Renders the credential-harvesting form.

5 sightings3 hosts2026-05-23
sha256: 93985698a0c8a72c
ast: e2fab8cf60b56403
highphishing
tuops Sister Cohort — chunk-vendors
family: tuops-sister-eab1

3-host random-domain sister cohort surfaced via cosine pivot. tuops.top cohort.

4 sightings3 hosts2026-05-24
sha256: 02b0ee964ef23d8c
ast: eab170e2226f7f6e
highphishing
.click TLD Vue Sister Cohort (6287713d) — chunk-vendors
family: click-tld-sister-6287

Sister cohort of the existing click-tld-kit-a260ef. 2 hosts: manwasite.cc, mwxz10.cc. Cosine-pivoted at sim=1.0000.

4 sightings2 hosts2026-05-24
sha256: 0cde578ea2c8975d
ast: 6287713dd6e3e352
highphishing
dhptgo Multi-TLD Same-Prefix — chunk-vendors
family: dhptgo-multitld-ea03

4-host same-prefix multi-TLD operator: dhptgo.cc, dhptgo.sbs, dhptgo.top.

4 sightings4 hosts2026-05-24
sha256: 0fed425ab0366b22
ast: ea035b1a53a008e4
highphishing
ldwebsync Numbered .top Series — chunk-vendors
family: ldwebsync-numeric-ba2a

4-host numbered brand series: ldwebsync[32|73|78|…].top.

4 sightings4 hosts2026-05-23
sha256: d5998518256f3519
ast: ba2a7c44c21c40cd
highphishing
nyadegd/nyduehs Numbered Sister Cohort — chunk-vendors
family: nyadegd-nyduehs-sister-244b

4-host numbered brand sister of the existing nyedfrt-top-3af6 kit. Hosts: nyadegd856.top, nyduehs598.top, nyduehs621.top.

4 sightings4 hosts2026-05-23
sha256: 967e15be66e36a6a
ast: 244b28272ed4efd3
highphishing
aazzkf Multi-TLD Same-Prefix Kit — chunk-vendors
family: aazzkf-multitld-36df

4-host same-prefix multi-TLD operator: aazzkf.cc, aazzkf.com, aazzkf.org, aazz-kf.com. Sister pattern to aaoopg-eejjkf-02d6.

4 sightings4 hosts2026-05-24
sha256: 8db8cd38410b5a6f
ast: 36dfc2978517092d
highphishing
slh Numbered Series + slhofworld — chunk-vendors
family: slh-numeric-9aa7

4-host numbered brand series: slh005.com, slh006.com, …, slhofworld.vip.

4 sightings4 hosts2026-05-25
sha256: a00fa06622b5a7a8
ast: 9aa7de68ebff3b16
highphishing
Huawei Brand Impersonation — chunk-vendors
family: huawei-impersonation-788f

4-host operator running Huawei brand impersonation: huaw3.cn, huaw3.com plus wzg56.cc, wzg71.cc sister hosts. "huaw" is the operator-chosen prefix mimicking "huawei".

4 sightings4 hosts2026-05-24
sha256: 1e5c80e0f1a6e95d
ast: 788f2038605749ee
highphishing
Pages.dev Vue Investment Scam — pimco cohort chunk-vendors
family: pagesdev-vue-investment-scam

PIMCO-impersonation cohort of the Pages.dev Vue investment-scam kit. PIMCO (Pacific Investment Management Company) is a major real-world asset manager — this kit lures users into a fake investment platform under that brand.

4 sightings4 hosts2026-05-25
sha256: d828a06ac368de17
ast: 631b10c1fb95cf74
highphishing
Random-Domain Vue Sister Cohort (aec05b) — chunk-vendors
family: random-domain-sister-aec0

Sister cohort of the random-letter-multitld kit family. 3 hosts: hjuiwansdjjsdjks.cyou, nbjiwuqnskdkza.icu, nuhjsjjjskwjaksjs.icu. Cosine-pivoted from existing 9d69 and 4ba7 anchors.

3 sightings3 hosts2026-05-24
sha256: 070253c66f110335
ast: aec05be5cdaf797c
highphishing
zhesinc/zhesinr Sister Cohort #2 — chunk-vendors
family: zhesin-sister-f221

Companion build of the zhesin-sister kit.

2 sightings2 hosts2026-05-23
sha256: 28e8ad9c93737621
ast: f22163e7b66b5885
highphishing
zhesinc/zhesinr Sister Cohort #1 — chunk-vendors
family: zhesin-sister-f125

2-host operator: zhesinc.com, zhesinr.com (variants of "zhesin" brand prefix). Surfaced via cosine pivot.

2 sightings2 hosts2026-05-23
sha256: 4b17561e0d471732
ast: f1250c96b5228c49
highphishing
Pages.dev Vue Investment Scam — mint-b1v cohort chunk-vendors
family: pagesdev-vue-investment-scam

mint-b1v.pages.dev cohort build of the Pages.dev Vue investment-scam kit.

2 sightings1 hosts2026-05-23
sha256: ab194d8bb832a34b
ast: 5a84fb2d53300269
highphishing
Minexus VIP Impersonation — chunk-vendors
family: minexus-impersonation-beb4

1 host (minexusvip.com) — Minexus is a real crypto-mining brand. The "vip" suffix is operator-added.

1 sightings1 hosts2026-05-24
sha256: cd3c314c872baf82
ast: beb497b84a323b25
highphishing
Mufolio Portfolio Impersonation — chunk-vendors
family: mufolio-portfolio-c376

1 host (mufolio-portal-x.com) impersonating a portfolio/asset-management brand. "Mufolio" is operator-coined.

1 sightings1 hosts2026-05-23
sha256: 521e97b8b6e292df
ast: c376671c613e9722
highphishing
Pages.dev Vue Investment Scam — mint-bnq cohort chunk-vendors
family: pagesdev-vue-investment-scam

mint-bnq.pages.dev cohort build of the Pages.dev Vue investment-scam kit.

1 sightings1 hosts2026-05-23
sha256: 2ccad86e1df97d02
ast: fac56bfb0b2cccb9
highphishing
Pages.dev Vue Investment Scam — digtal-du cohort chunk-vendors
family: pagesdev-vue-investment-scam

digtal-du.pages.dev cohort build of the Pages.dev Vue investment-scam kit. "Digital" finance brand impersonation (misspelt).

1 sightings1 hosts2026-05-22
sha256: 52b834c1e3fc8eaa
ast: 3c5bee1029ab2344
highphishing
Pages.dev Vue Investment Scam — mint-34z cohort chunk-vendors
family: pagesdev-vue-investment-scam

mint-34z.pages.dev cohort build of the Pages.dev Vue investment-scam kit.

1 sightings1 hosts2026-05-24
sha256: f4b560e4eb554c7b
ast: 27cde52d0e53d5c2