Known malicious kithighphishing
mailNNN.com Credits Scam — index.js
family: mail-credits-scam
Vue.js single-page application deployed across mailNNN.com sister hosts (mail238/279/799 known) as a fake credits / fake banking platform. Users register, "recharge" (deposit), see fabricated balances, and cannot actually withdraw. Chunk names: pages-login-login, pages-recharge-index, pages-withdrawal-index, pages-record-index, pages-user-address-index. index.js is the SPA's entry chunk.
Fingerprint anchors
Provenance
Added by: analyst
Added: 2026-05-26 13:35
Anchor #1 of 3. Entry chunk index.3795b380.js — 6,895 nodes. Zero leakage to legitimate hosts.
Sightings (6)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| mail238.com | 269ee6c7… | https://mail238.com/static/js/index.3795b380.js | byte | 2026-05-23 23:34 |
| mail279.com | 4ae65998… | https://mail279.com/static/js/index.3795b380.js | byte | 2026-05-23 23:28 |
| mail799.com | 34f4e927… | https://mail799.com/static/js/index.3795b380.js | byte | 2026-05-23 23:22 |
| mail799.com | 34f4e927… | https://mail799.com/static/js/index.3795b380.js | byte | 2026-05-23 23:22 |
| mail799.com | 99a68785… | https://mail799.com/static/js/index.3795b380.js | byte | 2026-05-23 21:54 |
| mail279.com | 36a59f71… | https://mail279.com/static/js/index.3795b380.js | byte | 2026-05-23 21:54 |