Known malicious kithighphishing

mailNNN.com Credits Scam — index.js

family: mail-credits-scam

Vue.js single-page application deployed across mailNNN.com sister hosts (mail238/279/799 known) as a fake credits / fake banking platform. Users register, "recharge" (deposit), see fabricated balances, and cannot actually withdraw. Chunk names: pages-login-login, pages-recharge-index, pages-withdrawal-index, pages-record-index, pages-user-address-index. index.js is the SPA's entry chunk.

Provenance

Added by: analyst
Added: 2026-05-26 13:35
Anchor #1 of 3. Entry chunk index.3795b380.js — 6,895 nodes. Zero leakage to legitimate hosts.

Sightings (6)

HostScanScriptMatchWhen
mail238.com269ee6c7https://mail238.com/static/js/index.3795b380.jsbyte2026-05-23 23:34
mail279.com4ae65998https://mail279.com/static/js/index.3795b380.jsbyte2026-05-23 23:28
mail799.com34f4e927https://mail799.com/static/js/index.3795b380.jsbyte2026-05-23 23:22
mail799.com34f4e927https://mail799.com/static/js/index.3795b380.jsbyte2026-05-23 23:22
mail799.com99a68785https://mail799.com/static/js/index.3795b380.jsbyte2026-05-23 21:54
mail279.com36a59f71https://mail279.com/static/js/index.3795b380.jsbyte2026-05-23 21:54