Known malicious kithighother

J365 Gambling Platform — gui-base.js

family: j365-gambling-platform

Chinese-language illegal online-gambling platform served from a rotating set of brand-prefixed landing domains (j365*.xyz, lvs*.vip, hgty*.vip, hg*.vip, usdbetvip*.biz, xpj*.com — including punycoded variants) backed by a small set of operator CDN hosts on pham.xin and yqdkrj.com under the path /ftl/commonPage/. Offers fish-shooter, casino, sports, chess games. gui-base.js is the kit's shared UI framework.

Provenance

Added by: analyst
Added: 2026-05-26 13:17
Anchor #1 of 3 for the family. Seen on da3b55/dxext9/huf5as/jn5ec4.pham.xin and 2hsuoj.yqdkrj.com. Zero leakage to legitimate hosts in the corpus.

Sightings (12)

HostScanScriptMatchWhen
dxext9.pham.xinb41463behttps://dxext9.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-25 00:50
2hsuoj.yqdkrj.com8afd8d88https://2hsuoj.yqdkrj.com/ftl/commonPage/js/gui-base.jsbyte2026-05-25 00:08
jn5ec4.pham.xind73884d6https://jn5ec4.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 21:12
dxext9.pham.xin544f622chttps://dxext9.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 21:00
huf5as.pham.xin262d732bhttps://huf5as.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:41
da3b55.pham.xin62dfa3a5https://da3b55.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:40
da3b55.pham.xin6c31dc8bhttps://da3b55.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:40
da3b55.pham.xin635fc42fhttps://da3b55.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:39
huf5as.pham.xin6fe623fdhttps://huf5as.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:38
da3b55.pham.xin3f2ed933https://da3b55.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:38
2hsuoj.yqdkrj.com3f1a24b1https://2hsuoj.yqdkrj.com/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:37
da3b55.pham.xine8318d6chttps://da3b55.pham.xin/ftl/commonPage/js/gui-base.jsbyte2026-05-24 20:34