Known malicious kithighphishing

teje-rotating-domain kit — main.js

family: teje-rotating-domain

Webpack-bundled SPA deployed across an 8-host rotation that all share the `teje` prefix on cheap/suspicious TLDs (tejehqnfih.work, tejehqzjxt.club, tejeiviusk.asia, tejeiwdeow.cloud, tejeiycpyh.asia, tejeizzifa.wiki, …). Most graded Malicious by the verdict layer, some Low Risk — the roster catches the misses.

Provenance

Added by: analyst
Added: 2026-05-26 14:39
Anchor #1 of 3. main.74a858e950b3cb360b11.js — entry bundle, 85,463 nodes.

Sightings (9)

HostScanScriptMatchWhen
tejeiycpyh.asia10cab597https://tejeiycpyh.asia/main.74a858e950b3cb360b11.jsbyte2026-05-23 20:49
tejehqzjxt.clubce8f6e31https://tejehqzjxt.club/main.74a858e950b3cb360b11.jsbyte2026-05-23 15:57
tejehqzjxt.club537500adhttps://tejehqzjxt.club/main.74a858e950b3cb360b11.jsbyte2026-05-23 08:51
tejeiwdeow.cloud1f6d6553https://tejeiwdeow.cloud/main.74a858e950b3cb360b11.jsbyte2026-05-23 02:55
tejeiviusk.asia5a3ee199https://tejeiviusk.asia/main.74a858e950b3cb360b11.jsbyte2026-05-23 02:15
tejeizzifa.wiki1d034446https://tejeizzifa.wiki/main.74a858e950b3cb360b11.jsbyte2026-05-23 01:57
tejehqnfih.work645bfe7ahttps://tejehqnfih.work/main.74a858e950b3cb360b11.jsbyte2026-05-23 01:42
tejeiwdeow.cloud2270b1f9https://tejeiwdeow.cloud/main.74a858e950b3cb360b11.jsbyte2026-05-22 23:41
tejeiwdeow.cloud2270b1f9https://tejeiwdeow.cloud/main.74a858e950b3cb360b11.jsbyte2026-05-22 23:41