Known malicious kithighphishing

Random-TLD Multi-Domain Rotation Kit — main.v2.js

family: hevvugu-multi-domain

Single shared main.v2.js deployed across 17 throwaway domains on cheap/suspicious TLDs (.icu, .sbs, .cfd, .cyou, .shop, .wiki, .one, .asia, .club). Includes telegran.one — Telegram brand impersonation. The 17 hosts have inconsistent verdicts (Low Risk → Malicious); the roster catches all of them via a single fingerprint.

Provenance

Added by: analyst
Added: 2026-05-26 14:39
Single anchor — the kit serves the same main.v2.js across all 17 known sister domains.

Sightings (84)

HostScanScriptMatchWhen
hua456t.xyz22ccda8bhttps://hua456t.xyz/main.v2.jsstructure2026-05-24 17:46
hua456t.xyz22ccda8bhttps://hua456t.xyz/main.v2.jsstructure2026-05-24 17:46
hua456t.xyz22ccda8bhttps://hua456t.xyz/main.v2.jsstructure2026-05-24 17:46
claw111a.xyzfca24554https://claw111a.xyz/main.v2.jsstructure2026-05-24 17:18
bot789c.xyz1bb0a9e8https://bot789c.xyz/main.v2.jsstructure2026-05-24 17:17
bot789c.xyz1bb0a9e8https://bot789c.xyz/main.v2.jsstructure2026-05-24 17:17
bot789c.xyz5ea2425ahttps://bot789c.xyz/main.v2.jsstructure2026-05-24 17:14
testxyz123.topef98f6a6https://testxyz123.top/main.v2.jsstructure2026-05-24 17:10
testxyz123.topef98f6a6https://testxyz123.top/main.v2.jsstructure2026-05-24 17:10
tech000f.xyz8b13fe1bhttps://tech000f.xyz/main.v2.jsstructure2026-05-24 16:55
ai123h.xyzf06ed6dchttps://ai123h.xyz/main.v2.jsstructure2026-05-24 16:54
ai123h.xyzf06ed6dchttps://ai123h.xyz/main.v2.jsstructure2026-05-24 16:54
ai123h.xyzf06ed6dchttps://ai123h.xyz/main.v2.jsstructure2026-05-24 16:54
hua456t.xyzaa693d07https://hua456t.xyz/main.v2.jsstructure2026-05-24 16:48
hua456t.xyzaa693d07https://hua456t.xyz/main.v2.jsstructure2026-05-24 16:48
testxyz123.top195a93b1https://testxyz123.top/main.v2.jsstructure2026-05-24 16:40
zeltrixx.top8ea84911https://zeltrixx.top/main.v2.js?v=2structure2026-05-24 13:27
zeltrixa.top051e944fhttps://zeltrixa.top/main.v2.js?v=2structure2026-05-24 13:24
zeltrinz.tope2219d47https://zeltrinz.top/main.v2.js?v=2structure2026-05-24 13:24
zeltrinz.topa99cc459https://zeltrinz.top/main.v2.js?v=2structure2026-05-24 13:05
zeltrinz.topa99cc459https://zeltrinz.top/main.v2.js?v=2structure2026-05-24 13:05
zeltrinz.topa99cc459https://zeltrinz.top/main.v2.js?v=2structure2026-05-24 13:05
zeltrinz.topa99cc459https://zeltrinz.top/main.v2.js?v=2structure2026-05-24 13:05
zeltrixx.topc50b5049https://zeltrixx.top/main.v2.js?v=2structure2026-05-24 13:02
zeltrixx.topc50b5049https://zeltrixx.top/main.v2.js?v=2structure2026-05-24 13:02
zeltrixx.topc50b5049https://zeltrixx.top/main.v2.js?v=2structure2026-05-24 13:02
telegran.onefa3ccd07https://telegran.one/main.v2.jsbyte2026-05-24 12:54
zeltrixa.tope2132556https://zeltrixa.top/main.v2.js?v=2structure2026-05-24 12:54
zeltrixa.tope2132556https://zeltrixa.top/main.v2.js?v=2structure2026-05-24 12:54
zeltrixo.top93d3bdd1https://zeltrixo.top/main.v2.js?v=2structure2026-05-24 12:46
zeltrixo.top93d3bdd1https://zeltrixo.top/main.v2.js?v=2structure2026-05-24 12:46
hurvovo.cyou0619c150https://hurvovo.cyou/main.v2.jsbyte2026-05-24 12:43
zelviro.top8d672d59https://zelviro.top/main.v2.js?v=2structure2026-05-24 12:42
munvigo.cfd31416df6https://munvigo.cfd/main.v2.jsbyte2026-05-24 12:40
munvigo.cfd31416df6https://munvigo.cfd/main.v2.jsbyte2026-05-24 12:40
862m23.icu12e6d172https://862m23.icu/main.v2.jsbyte2026-05-24 12:40
hevvugu.icu1216a1b0https://hevvugu.icu/main.v2.jsbyte2026-05-24 12:34
hevvugu.icu1216a1b0https://hevvugu.icu/main.v2.jsbyte2026-05-24 12:34
hevvugu.icu1216a1b0https://hevvugu.icu/main.v2.jsbyte2026-05-24 12:34
hevvugu.icu1216a1b0https://hevvugu.icu/main.v2.jsbyte2026-05-24 12:34
hevvugu.icu1216a1b0https://hevvugu.icu/main.v2.jsbyte2026-05-24 12:34
karvexo.cfda188ca39https://karvexo.cfd/main.v2.js?v=2structure2026-05-24 12:34
karvexo.cfda188ca39https://karvexo.cfd/main.v2.js?v=2structure2026-05-24 12:34
karvexo.cfda188ca39https://karvexo.cfd/main.v2.js?v=2structure2026-05-24 12:34
selnixzfo.shope9e48b50https://selnixzfo.shop/main.v2.jsbyte2026-05-24 12:31
selnixzfo.shope9e48b50https://selnixzfo.shop/main.v2.jsbyte2026-05-24 12:31
selnixzfo.shope9e48b50https://selnixzfo.shop/main.v2.jsbyte2026-05-24 12:31
selnixzfo.shopb0c47292https://selnixzfo.shop/main.v2.jsbyte2026-05-24 12:29
selnixzfo.shopb0c47292https://selnixzfo.shop/main.v2.jsbyte2026-05-24 12:29
gnvrog.cfd8dd907dahttps://gnvrog.cfd/main.v2.jsbyte2026-05-24 12:29
narviko.top26829e4fhttps://narviko.top/main.v2.js?v=2structure2026-05-24 12:27
pernixzga.shop20a5fbc8https://pernixzga.shop/main.v2.jsbyte2026-05-24 12:24
pernixzga.shop20a5fbc8https://pernixzga.shop/main.v2.jsbyte2026-05-24 12:24
pernixzga.shop20a5fbc8https://pernixzga.shop/main.v2.jsbyte2026-05-24 12:24
sevvopa.cfde384b945https://sevvopa.cfd/main.v2.jsbyte2026-05-24 12:22
sevvopa.cfde384b945https://sevvopa.cfd/main.v2.jsbyte2026-05-24 12:22
sevvopa.cfde384b945https://sevvopa.cfd/main.v2.jsbyte2026-05-24 12:22
sevvopa.cfde384b945https://sevvopa.cfd/main.v2.jsbyte2026-05-24 12:22
sevvopa.cfde384b945https://sevvopa.cfd/main.v2.jsbyte2026-05-24 12:22
dulvici.sbs815b338dhttps://dulvici.sbs/main.v2.jsbyte2026-05-24 12:19
morvixzde.shop93880b9ahttps://morvixzde.shop/main.v2.jsbyte2026-05-24 12:19
keriox.sbs9fe2d8dahttps://keriox.sbs/main.v2.jsbyte2026-05-24 12:16
keriox.sbs9fe2d8dahttps://keriox.sbs/main.v2.jsbyte2026-05-24 12:16
keriox.sbs9fe2d8dahttps://keriox.sbs/main.v2.jsbyte2026-05-24 12:16
dulvici.sbs5469a919https://dulvici.sbs/main.v2.jsbyte2026-05-24 12:13
wusmula.icuabfb3586https://wusmula.icu/main.v2.jsbyte2026-05-24 12:13
wusmula.icuabfb3586https://wusmula.icu/main.v2.jsbyte2026-05-24 12:13
wusmula.icuabfb3586https://wusmula.icu/main.v2.jsbyte2026-05-24 12:13
wusmula.icuabfb3586https://wusmula.icu/main.v2.jsbyte2026-05-24 12:13
senvaro.topbac2b01dhttps://senvaro.top/main.v2.js?v=2structure2026-05-24 12:12
melviro.cfd3c02e9e9https://melviro.cfd/main.v2.js?v=2structure2026-05-24 12:11
worvicu.icuca24535fhttps://worvicu.icu/main.v2.jsbyte2026-05-24 12:11
worvicu.icuca24535fhttps://worvicu.icu/main.v2.jsbyte2026-05-24 12:11
norvaxzbi.shopa437ba98https://norvaxzbi.shop/main.v2.jsbyte2026-05-24 12:11
norvaxzbi.shopa437ba98https://norvaxzbi.shop/main.v2.jsbyte2026-05-24 12:11
gnvrog.cfdfe375148https://gnvrog.cfd/main.v2.jsbyte2026-05-24 12:09
gnvrog.cfdfe375148https://gnvrog.cfd/main.v2.jsbyte2026-05-24 12:09
norvaxzbi.shop946623f5https://norvaxzbi.shop/main.v2.jsbyte2026-05-24 12:09
pelvaro.cfda56f1e76https://pelvaro.cfd/main.v2.js?v=2structure2026-05-24 12:06
pelvaro.cfda56f1e76https://pelvaro.cfd/main.v2.js?v=2structure2026-05-24 12:06
marvona.top34e41554https://marvona.top/main.v2.js?v=2structure2026-05-24 12:03
hevvugu.icu168ab89ahttps://hevvugu.icu/main.v2.jsbyte2026-05-24 12:01
hevvugu.icu168ab89ahttps://hevvugu.icu/main.v2.jsbyte2026-05-24 12:01
hevvugu.icu168ab89ahttps://hevvugu.icu/main.v2.jsbyte2026-05-24 12:01