Highscore 46 · flagged Friday, September 4, 2026

tele-history.fun

Appeared in the .fun zone on Friday, September 4, 2026; by the end of that day the census found active website. Full domain report

Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.

Own one of these names and think the listing is wrong? Tell us and a person will look.

What matched

TLD with a high abuse rate
matched: fun
+8
brand in page title, not in the name
matched: telegram
+20
form on a brand-styled page
matched: has_form
+18
Registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
Nameserver provider
Nameservers
ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org, ns4.timeweb.org
First-day state
active website
HTTP status
200
Page title
TeleHistory — Аналитика Telegram и OSINT Досье
Has a form
yes
Brand echoed

Model opinions

Second opinionlooks like a scamconfidence 72%· claude-opus-5

Russian-language "TeleHistory PRO" site promises to reveal hidden phone numbers, private chats and contact graphs of any Telegram account via 100+ 'closed databases' — a classic probiv/OSINT-dossier fraud lure that funnels victims to an operator-controlled bot (@TeleHist_bot / t.me links) for payment or Telegram session capture; it uses Telegram's logo and product name as decoration but presents itself as a third-party service rather than as Telegram, so it is fraud rather than brand impersonati

First passlooks like phishingtarget: Telegramconfidence 95%· claude-haiku-4-5

The page impersonates Telegram by using its logo, branding, and language to deceive visitors into believing this is an official Telegram service. It displays a form requesting Telegram usernames/IDs with promises of hidden data retrieval, and directs users to a Telegram bot (@TeleHist_bot) for credential/payment capture—a classic sealed-room phishing pattern where the form posts to itself with no legitimate offsite verification.

A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.

What the page looked like on Friday, September 4, 2026

Screenshot of tele-history.fun taken by the zone census on 2026-09-04

Same data as JSON: /api/zone/domain/tele-history.fun. This page is not indexed by search engines and does not link to the site it describes.