Known malicious kitcriticalphishing

Fake-Telegram Phishing Kit — redirect.js

family: fake-telegram-dashan

Massive 139-host Telegram brand-impersonation operation. ONE operator running random-letter hostnames across .icu/.sbs/.xyz/.top/.lat/.homes/.shop/.cn/.com/.org/.love/.life TLDs (dashan.icu, danvato.icu, eldravox.icu, claw111a.xyz, ai123h.xyz, bot789c.xyz, euhe-tg.com, htrx-tg.com, hujli.shop, telegarm-jp.org, yfhmg.love, fdshfgjd.{lat,homes}, …). Pages titled "Telegram" or "Secure Messenger". Operator-built Vue.js SPA. The "-tg" suffix in domain names and Japan/JP brand hints suggest Telegram-Japan credential-harvest focus.

Provenance

Added by: analyst
Added: 2026-05-27 07:26
Anchor #1 of 4. redirect.js — smallest, most diagnostic chunk (60 nodes). 139 hosts in cluster.

Sightings (115)

HostScanScriptMatchWhen
tgleyfgm.com6155ba60https://tgleyfgm.com/redirect.jsbyte2026-05-24 23:45
tgleyfgm.com6155ba60https://tgleyfgm.com/ZH/redirect.jsbyte2026-05-24 23:45
tglegaim.com198137a2https://tglegaim.com/redirect.jsbyte2026-05-24 23:40
tglegaim.com198137a2https://tglegaim.com/ZH/redirect.jsbyte2026-05-24 23:40
tsvlgiam.com0e8035b5https://tsvlgiam.com/redirect.jsbyte2026-05-24 21:52
tsvlgiam.com0e8035b5https://tsvlgiam.com/ZH/redirect.jsbyte2026-05-24 21:52
telopucm.com69f2868ehttps://telopucm.com/redirect.jsbyte2026-05-24 21:27
telopucm.com69f2868ehttps://telopucm.com/ZH/redirect.jsbyte2026-05-24 21:27
teleadom.com519d7e6chttps://teleadom.com/redirect.jsbyte2026-05-24 21:10
teleadom.com519d7e6chttps://teleadom.com/ZH/redirect.jsbyte2026-05-24 21:10
tklegaim.com8fca73a4https://tklegaim.com/redirect.jsbyte2026-05-24 21:08
tklegaim.com8fca73a4https://tklegaim.com/ZH/redirect.jsbyte2026-05-24 21:08
txlegxam.comac851e56https://txlegxam.com/redirect.jsbyte2026-05-24 21:07
txlegxam.comac851e56https://txlegxam.com/ZH/redirect.jsbyte2026-05-24 21:07
tsleglam.come355d308https://tsleglam.com/redirect.jsbyte2026-05-24 21:00
tsleglam.come355d308https://tsleglam.com/ZH/redirect.jsbyte2026-05-24 21:00
teleqtnvbed.com7c5073f9https://teleqtnvbed.com/redirect.jsbyte2026-05-24 20:47
teleqtnvbnet.com57dfdd68https://teleqtnvbnet.com/redirect.jsbyte2026-05-24 20:35
trtegiam.coma4427d64https://trtegiam.com/redirect.jsbyte2026-05-24 20:28
trtegiam.coma4427d64https://trtegiam.com/ZH/redirect.jsbyte2026-05-24 20:28
titegalm.com0b66937chttps://titegalm.com/redirect.jsbyte2026-05-24 20:15
titegalm.com0b66937chttps://titegalm.com/ZH/redirect.jsbyte2026-05-24 20:15
ttlegiam.com193613bahttps://ttlegiam.com/redirect.jsbyte2026-05-24 20:14
ttlegiam.com193613bahttps://ttlegiam.com/ZH/redirect.jsbyte2026-05-24 20:14
teluadrm.com8dcae2f5https://teluadrm.com/redirect.jsbyte2026-05-24 19:57
teluadrm.com8dcae2f5https://teluadrm.com/ZH/redirect.jsbyte2026-05-24 19:57
triegvam.comdcd909a4https://triegvam.com/redirect.jsbyte2026-05-24 19:55
triegvam.comdcd909a4https://triegvam.com/ZH/redirect.jsbyte2026-05-24 19:55
triegvam.comefb27d49https://triegvam.com/redirect.jsbyte2026-05-24 19:54
triegvam.comefb27d49https://triegvam.com/ZH/redirect.jsbyte2026-05-24 19:54
ttlegiam.comdde94a19https://ttlegiam.com/ZH/redirect.jsbyte2026-05-24 19:45
ttlegiam.comdde94a19https://ttlegiam.com/redirect.jsbyte2026-05-24 19:45
tleigiam.come579ca23https://tleigiam.com/redirect.jsbyte2026-05-24 19:38
tleigiam.come579ca23https://tleigiam.com/ZH/redirect.jsbyte2026-05-24 19:38
telegarm-jp.org5f77026chttps://telegarm-jp.org/redirect.jsbyte2026-05-24 19:21
telogykm.com67e92e91https://telogykm.com/redirect.jsbyte2026-05-24 18:07
telogykm.com67e92e91https://telogykm.com/ZH/redirect.jsbyte2026-05-24 18:07
telegge.club3b035e1fhttps://telegge.club/redirect.jsbyte2026-05-24 17:48
tege.club8131e581https://tege.club/redirect.jsbyte2026-05-24 17:33
telanigm.com42e54b1chttps://telanigm.com/redirect.jsbyte2026-05-24 17:28
telanigm.com581cc9eahttps://telanigm.com/redirect.jsbyte2026-05-24 17:22
tege.club18d16c05https://tege.club/redirect.jsbyte2026-05-24 17:13
teielrom.coma28372f7https://teielrom.com/redirect.jsbyte2026-05-24 17:12
teielrom.coma28372f7https://teielrom.com/ZH/redirect.jsbyte2026-05-24 17:12
telrotgm.com4dc63ae0https://telrotgm.com/redirect.jsbyte2026-05-24 17:10
telrotgm.com4dc63ae0https://telrotgm.com/ZH/redirect.jsbyte2026-05-24 17:10
telqging.comc897d45fhttps://telqging.com/redirect.jsbyte2026-05-24 17:09
telqging.comc897d45fhttps://telqging.com/ZH/redirect.jsbyte2026-05-24 17:09
tileganm.com6d6091cchttps://tileganm.com/redirect.jsbyte2026-05-24 16:12
tileganm.com6d6091cchttps://tileganm.com/ZH/redirect.jsbyte2026-05-24 16:12
bztgtest.top51483c00https://bztgtest.top/redirect.jsbyte2026-05-24 15:36
bztgtest.top51483c00https://bztgtest.top/ZH/redirect.jsbyte2026-05-24 15:36
trlegaim.com8031c543https://trlegaim.com/redirect.jsbyte2026-05-24 15:31
trlegaim.com8031c543https://trlegaim.com/ZH/redirect.jsbyte2026-05-24 15:31
telrogdm.com3dfeb702https://telrogdm.com/ZH/redirect.jsbyte2026-05-24 14:52
telrogdm.com3dfeb702https://telrogdm.com/redirect.jsbyte2026-05-24 14:52
tielrglm.com2cd1959fhttps://tielrglm.com/ZH/redirect.jsbyte2026-05-24 14:46
tielrglm.com2cd1959fhttps://tielrglm.com/redirect.jsbyte2026-05-24 14:46
tielrglm.com20f7078bhttps://tielrglm.com/ZH/redirect.jsbyte2026-05-24 14:43
tielrglm.com20f7078bhttps://tielrglm.com/redirect.jsbyte2026-05-24 14:43
telrougm.come46c320ahttps://telrougm.com/ZH/redirect.jsbyte2026-05-24 14:40
telrougm.come46c320ahttps://telrougm.com/redirect.jsbyte2026-05-24 14:40
telrougm.com43cbd373https://telrougm.com/redirect.jsbyte2026-05-24 14:15
telrougm.com43cbd373https://telrougm.com/ZH/redirect.jsbyte2026-05-24 14:15
euhe-tg.comc64b5a99https://euhe-tg.com/redirect.jsbyte2026-05-24 14:14
tg-tnnr.comb9e32ec7https://tg-tnnr.com/redirect.jsbyte2026-05-24 14:03
telagirm.com7d2b688fhttps://telagirm.com/redirect.jsbyte2026-05-24 13:44
telagirm.com7d2b688fhttps://telagirm.com/ZH/redirect.jsbyte2026-05-24 13:44
telrohlg.com57737401https://telrohlg.com/redirect.jsbyte2026-05-24 13:27
telrohlg.com57737401https://telrohlg.com/ZH/redirect.jsbyte2026-05-24 13:27
teleglvm.com1f1610eehttps://teleglvm.com/redirect.jsbyte2026-05-24 13:24
teleglvm.com1f1610eehttps://teleglvm.com/ZH/redirect.jsbyte2026-05-24 13:24
teleglom.combffc5ac7http://teleglom.com/redirect.jsbyte2026-05-24 13:16
teleglom.combffc5ac7http://teleglom.com/ZH/redirect.jsbyte2026-05-24 13:16
teidqglm.comcb42409ehttps://teidqglm.com/redirect.jsbyte2026-05-24 13:16
teidqglm.comcb42409ehttps://teidqglm.com/ZH/redirect.jsbyte2026-05-24 13:16
telopymg.com465ae762https://telopymg.com/ZH/redirect.jsbyte2026-05-24 13:03
telopymg.com465ae762https://telopymg.com/redirect.jsbyte2026-05-24 13:03
govlexta.onead34edc0https://govlexta.one/redirect.jsbyte2026-05-24 12:51
teliagivg.com5fef05achttps://teliagivg.com/redirect.jsbyte2026-05-24 12:44
teliagivg.com5fef05achttps://teliagivg.com/ZH/redirect.jsbyte2026-05-24 12:44
mornvex.lol7b370d83https://mornvex.lol/redirect.jsbyte2026-05-24 11:46
sylvornex.sbs1ba6eddfhttps://sylvornex.sbs/redirect.jsbyte2026-05-24 11:24
eldravox.icu03b394a3https://eldravox.icu/redirect.jsbyte2026-05-24 11:22
mornvex.lol73a0a3f1https://mornvex.lol/redirect.jsbyte2026-05-24 11:19
treantboz.cfd2c920261https://treantboz.cfd/redirect.jsbyte2026-05-24 11:17
teleqarnn.comf2b1e965https://teleqarnn.com/redirect.jsbyte2026-05-24 00:47
teleqarnn.coma5f9878ahttps://teleqarnn.com/redirect.jsbyte2026-05-24 00:29
ufhsmijgfkjbk.lolaf1e0d4bhttp://ufhsmijgfkjbk.lol/redirect.jsbyte2026-05-23 23:46
gsdrtkllkjln.xyz36bfddd8https://gsdrtkllkjln.xyz/redirect.jsbyte2026-05-23 22:22
gsdrtkllkjln.xyz8aea3ccfhttps://gsdrtkllkjln.xyz/redirect.jsbyte2026-05-23 21:51
gsdrtkllkjln.buzzb6330be2https://gsdrtkllkjln.buzz/redirect.jsbyte2026-05-23 21:50
fdshfgjd.homesaca97805https://fdshfgjd.homes/redirect.jsbyte2026-05-23 21:45
fdshdfjghkf.latb5710354https://fdshdfjghkf.lat/redirect.jsbyte2026-05-23 21:41
fdshfgjd.lat9e3d4162https://fdshfgjd.lat/redirect.jsbyte2026-05-23 21:39
fdshfsjd.latce801f24https://fdshfsjd.lat/redirect.jsbyte2026-05-23 21:22
hujli.shop7bb75002https://hujli.shop/redirect.jsbyte2026-05-23 08:27
sdfc-tg.com1ce2befdhttps://sdfc-tg.com/redirect.jsbyte2026-05-23 06:40
yfhmg.love6fa48a57https://yfhmg.love/redirect.jsbyte2026-05-23 05:45
yfhmg.love61d25463https://yfhmg.love/redirect.jsbyte2026-05-23 03:42
wulpg.helpe465ecc8https://wulpg.help/redirect.jsbyte2026-05-23 02:25
hudf.qpond92d2630http://hudf.qpon/redirect.jsbyte2026-05-23 01:54
usjgf.click4bb685d7https://usjgf.click/redirect.jsbyte2026-05-23 01:52
wulpg.help353d31bahttps://wulpg.help/redirect.jsbyte2026-05-23 01:40
kdgaj.loved81e4af2https://kdgaj.love/redirect.jsbyte2026-05-23 01:34
zhongwen.love6439699chttps://zhongwen.love/redirect.jsbyte2026-05-22 20:18
zhongwen.love6439699chttps://zhongwen.love/redirect.jsbyte2026-05-22 20:18
wanghaha.click7e5ab7bdhttps://wanghaha.click/redirect.jsbyte2026-05-22 18:01
htrx-tg.com47736ef0https://htrx-tg.com/redirect.jsbyte2026-05-22 17:56
zhongwen.loved69f4d92https://zhongwen.love/redirect.jsbyte2026-05-22 17:35
yangguang.my.idecad07f3https://yangguang.my.id/redirect.jsbyte2026-05-22 17:14
wangghj.clubaa6156efhttps://wangghj.club/redirect.jsbyte2026-05-22 15:23
dashan.icua659ca5fhttps://dashan.icu/redirect.jsbyte2026-05-22 14:41
hkaiyinn.my.idc45292d6https://hkaiyinn.my.id/redirect.jsbyte2026-05-22 13:49
hujiang.me2e247b97https://hujiang.me/redirect.jsbyte2026-05-22 13:06