Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@godaddy.com.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
telegramwebs.com
“TK Store | buy, sell and discover on TK”
telegramwebs.com — Непроверенный. Олицетворение бренда: Telegram; Тип мошенничества: Social Media Phishing. Сводка доказательств: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); CF Radar malicious; PhishDestroy score 95/100. Регистратор: GoDaddy.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain is flagged for elevated-risk brand impersonation, specifically targeting Telegram, a widely used messaging platform. Analysis indicates the site operated under the guise of a marketplace or storefront, as evidenced by the page title "TK Store | buy, sell and discover on TK," which closely mimics Telegram’s branding and functionality. Such impersonation schemes are frequently leveraged to deceive users into divulging sensitive information, engaging in fraudulent transactions, or downloading malicious payloads under the pretense of legitimate services.
Infrastructure analysis reveals multiple high-risk indicators. The domain telegramwebs.com was registered on February 21, 2026, through GoDaddy.com, LLC, and resolves to the IP address 45.135.237.33, hosted by OWGELS INTERNATIONAL CO., LIMITED (AS153656) in Hong Kong. The SSL certificate is issued by Let's Encrypt (identifier: E8), a common choice for both legitimate and malicious domains. Security vendors on VirusTotal flagged the domain as malicious, with 21 out of 95 engines detecting it. The domain appears on at least one security blocklist and was taken offline following detection by automated threat intelligence systems. The combination of a recently registered domain, a hosting provider with a history of abuse, and a high detection rate among security vendors underscores the elevated risk.
Mitigation steps for this type of brand impersonation threat include immediate domain blacklisting across enterprise and consumer security tools. Organizations should monitor for user interactions with the domain or its associated IP address (45.135.237.33) in network logs and proxy data. End-users should be educated on recognizing impersonation tactics, such as verifying domain names for subtle misspellings or unusual TLDs, and cross-referencing official brand communications for legitimacy. Security teams are advised to review historical DNS records and SSL certificate transparency logs to identify potential collateral domains registered under the same infrastructure or certificate authority. Proactive monitoring for similar impersonation attempts targeting Telegram or other high-profile brands is recommended.
Данные сетевой безопасности
Хронология обнаружения
-
VirusTotal
21 → 19 (-2)
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
VirusTotal
21 → 19 (-2)
-
VirusTotal
21 → 19 (-2) (Added: Yandex Safebrowsing) (Removed: Emsisoft, Netcraft, Trustwave)
Процесс реагирования на угрозы
Статус в публичных блок-листах
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260205-63CFB0
Проверка по блок-листам
11 внешних источников под наблюдением · снимок от 09.09.2026
11 внешних источников под наблюдением Совпадений нет
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of telegramwebs.com · checked Mar 1, 2026
Доказательства и внешние отчеты
PD-20260205-63CFB0 Recipient: abuse@godaddy.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание