teletran[.]teiegtm[.]top
“进入首页”
teletran.teiegtm.top — Non verificato. Simulazione del marchio: Telegram; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 14/95 (BitDefender, Certego, CRDF, CyRadar, ESET); CF Radar malicious; PhishDestroy score 92/100. Registrar: Gname.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, teletran.teiegtm.top, was identified as a fraudulent infrastructure designed to impersonate the Telegram messaging platform. Analysis indicates its primary objective was credential harvesting, where unsuspecting users would be tricked into entering their login details on a fake interface mimicking the legitimate service. The site's page title, "进入首页" (translated as "Enter Homepage"), suggests targeting Chinese-speaking users, while its infrastructure and registration patterns align with known phishing campaigns. The risk posed extends beyond credential theft, as compromised accounts could be leveraged for further social engineering attacks, unauthorized access to private communications, or distribution of malicious content under the guise of a trusted contact. Infrastructure analysis reveals multiple technical indicators confirming the domain's malicious nature. The domain was registered on September 25, 2025, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolved to the IP address 172.245.67.31, hosted on AS36352 (HostPapa), a network segment with a history of abuse. Security vendors flagged the domain in 14 out of 95 scans on VirusTotal, a detection rate consistent with active phishing sites. Additionally, the SSL certificate was issued for 172.245.67.50, an unusual practice for legitimate services, which typically use domain-validated certificates. The domain appeared on one security blocklist and was proactively taken offline, though its infrastructure may still pose residual risks. Users who visited teletran.teiegtm.top should take immediate corrective actions to mitigate potential compromise. First, assume any credentials entered on the site have been exposed and reset passwords for Telegram and any other accounts where the same credentials were reused. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access. Monitor linked devices and active sessions for suspicious activity, such as unrecognized logins or unusual message history. If financial or sensitive personal information was shared, consider placing a fraud alert on credit reports and reviewing transaction histories for unauthorized activity. Finally, ensure endpoint security tools are updated and perform a full system scan to detect any secondary infections, as phishing sites often redirect to malware distribution pages or exploit kits.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: teiegtm.top
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain teiegtm.top behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo