Known malicious kithighother

J365 Gambling Platform — Comet.js

family: j365-gambling-platform

Custom WebSocket C2/heartbeat code (/websocket/Comet.js) used by the J365 illegal-gambling platform. Operator-specific real-time channel for bet placement, balance updates, and admin control.

Provenance

Added by: analyst
Added: 2026-05-26 13:17
Anchor #2 of 3. Strongest behavioural signal — custom WebSocket protocol bundled with all kit landings.

Sightings (12)

HostScanScriptMatchWhen
dxext9.pham.xinb41463behttps://dxext9.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-25 00:50
2hsuoj.yqdkrj.com8afd8d88https://2hsuoj.yqdkrj.com/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-25 00:08
jn5ec4.pham.xind73884d6https://jn5ec4.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 21:12
dxext9.pham.xin544f622chttps://dxext9.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 21:00
huf5as.pham.xin262d732bhttps://huf5as.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:41
da3b55.pham.xin62dfa3a5https://da3b55.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:40
da3b55.pham.xin6c31dc8bhttps://da3b55.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:40
da3b55.pham.xin635fc42fhttps://da3b55.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:39
huf5as.pham.xin6fe623fdhttps://huf5as.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:38
da3b55.pham.xin3f2ed933https://da3b55.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:38
2hsuoj.yqdkrj.com3f1a24b1https://2hsuoj.yqdkrj.com/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:37
da3b55.pham.xine8318d6chttps://da3b55.pham.xin/ftl/commonPage/js/websocket/Comet.jsbyte2026-05-24 20:34