telegram2[.]com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of telegram2[.]com
telegram2[.]com appears to present itself as a Chinese-language download and information portal for the Telegram messaging platform. The page title, metadata, and screenshot indicate that it offers Telegram downloads for Windows, Mac, Android, and iPhone/iPad, along with blog and FAQ sections. The visual design prominently uses Telegram branding, including the paper-plane logo and interface imagery, and the homepage text refers to it as an official Telegram site in Chinese.
Based on the domain name and page content, this site does not appear to be the primary official Telegram domain. The domain closely resembles telegram.org while adding an extra character, and the site seems aimed at users seeking localized Telegram downloads and related content. No clear evidence in the provided scan identifies the operator, so ownership and authorization to distribute Telegram software remain unclear based on available data.
Safety Assessment for telegram2[.]com
This domain shows multiple risk indicators at the time of this scan. It was flagged by 15 out of 94 security engines, with detections broadly describing phishing, malware, or malicious activity. In addition, the domain closely resembles telegram.org and may be a look-alike intended to capture users searching for Telegram downloads, which materially increases the risk of impersonation or deceptive distribution.
Although one malware scan reported no directly flagged files in its file-level summary, the same scan context also associated the domain and many internal links with generic suspicious or malicious-object labels. The site is very new, has no Tranco ranking, and the screenshot shows strong use of Telegram branding while operating from a different domain, which may mislead visitors into believing it is an official source.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid Let's Encrypt SSL certificate and is served over HTTPS from an nginx web server. It resolves to an IP hosted by NetLab Global in Hong Kong. The domain is approximately 108 days old at the time of this scan, uses Name.com nameservers, and DNSSEC appears to be unsigned.
From a security posture perspective, HTTPS alone should not be treated as a trust signal. The combination of a very recent registration, lack of DNSSEC, no observed ranking, and multiple scanner detections raises concern. The domain similarity to a well-known messaging service and the apparent hosting of download-related pages are notable technical risk factors in this case.
Share your experience with this website. Was it safe? Did you encounter any issues?