Known malicious kithighphishing

Chinese Kaiyun Gambling Kit — js/app

family: cn-kaiyun-gambling-7460

42-host Chinese gambling operator running "Kaiyun" brand impersonation across cn-kaiyunapp.vip, zh-kaiyuntiyu.vip, danti4833.com subdomains with random hostname prefixes. Path pattern /js/app.<hash>.js. Kaiyun (开云) is a known Chinese gambling brand frequently impersonated; "kaiyun" naming + Chinese-numeric subdomains is a strong operator signature.

Provenance

Added by: analyst
Added: 2026-05-27 07:09
42 hosts. Single anchor. Largest single-build kit in this batch.

Sightings (42)

HostScanScriptMatchWhen
h3rg75zs.cn-kaiyunapp.vip96841b4ahttps://h3rg75zs.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-25 00:23
wwjho0lhg6y88bn.cn-kaiyunapp.vip48e8a18ahttps://wwjho0lhg6y88bn.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-25 00:18
3vx9n5ynvic.cn-kaiyunapp.vipfcda6cd8https://3vx9n5ynvic.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-25 00:12
ieuqnbkqkllwa.cn-kaiyunapp.vip7f3d65b9https://ieuqnbkqkllwa.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-25 00:11
kvutdavspglizjtconly.cn-kaiyunapp.vip7b32250fhttps://kvutdavspglizjtconly.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-25 00:04
71my8nl9c0c4pw70lh.cn-kaiyunapp.vip7fd78457https://71my8nl9c0c4pw70lh.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:57
sfmmk154lf0q26.cn-kaiyunapp.vipf5eb2c71https://sfmmk154lf0q26.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:42
gd767atf42dc5brxf.cn-kaiyunapp.vip5cc83228https://gd767atf42dc5brxf.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:40
gf5kfkfva6ghe88.cn-kaiyunapp.vip3a098fb5https://gf5kfkfva6ghe88.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:38
hyoaj2fzuoyuce.cn-kaiyunapp.vipd43a76bbhttps://hyoaj2fzuoyuce.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:34
xv61p71y4b35.cn-kaiyunapp.vip72cec0d5https://xv61p71y4b35.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:28
hidhmm.cn-kaiyunapp.vip75073a44https://hidhmm.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:23
313r6ur.cn-kaiyunapp.vip3e5df2f9https://313r6ur.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:12
03ujeew3m9c7f4fam43y.cn-kaiyunapp.vipe1c7373dhttps://03ujeew3m9c7f4fam43y.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:10
ubipi51nizex.cn-kaiyunapp.vip0a464a39https://ubipi51nizex.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 23:07
z9v8ezqqdm0rs6xhpe.cn-kaiyunapp.vip1e92065fhttps://z9v8ezqqdm0rs6xhpe.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:58
8v3za452rj.cn-kaiyunapp.vip0f6da7b1https://8v3za452rj.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:55
e860a73joatv87pg.cn-kaiyunapp.vip38749e12https://e860a73joatv87pg.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:55
tx70esyvg.cn-kaiyunapp.vip131dd26ehttps://tx70esyvg.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:46
ukrjb7nl1hw.cn-kaiyunapp.viped157e77https://ukrjb7nl1hw.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:42
57a10j7jhmupuui.cn-kaiyunapp.vip7ded28cfhttps://57a10j7jhmupuui.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:25
1otv801.cn-kaiyunapp.vip007e9104https://1otv801.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:24
4l8nu3cv4eh2tbpf9q6.cn-kaiyunapp.vip8be974b2https://4l8nu3cv4eh2tbpf9q6.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:13
0018a1pyp5xa.cn-kaiyunapp.vip9751d167https://0018a1pyp5xa.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:07
mcpnlv1j.cn-kaiyunapp.vip78ee9ddchttps://mcpnlv1j.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 22:00
8b92jc1xdm.cn-kaiyunapp.vip51e2e924https://8b92jc1xdm.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 20:33
az0cy876jretx4a.cn-kaiyunapp.vipafbc302fhttps://az0cy876jretx4a.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 20:31
h7uczpt.cn-kaiyunapp.vip6c36e1cchttps://h7uczpt.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 20:22
4pt7qj.cn-kaiyunapp.vip25ae2843https://4pt7qj.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 20:15
5l9a9cp4vna7oml8rir.cn-kaiyunapp.vip58b96a54https://5l9a9cp4vna7oml8rir.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 19:58
yfpwtf8hffubm3x39e.cn-kaiyunapp.vip2d2e241ahttps://yfpwtf8hffubm3x39e.cn-kaiyunapp.vip/js/app.26836e23.jsbyte2026-05-24 19:33
zrx51ead3zwu23.rod947321.com4a717b4ehttps://zrx51ead3zwu23.rod947321.com/js/app.26836e23.jsstructure2026-05-24 18:47
gwq552mioa0qeybj59n.rod947321.come1012d9dhttps://gwq552mioa0qeybj59n.rod947321.com/js/app.26836e23.jsstructure2026-05-24 18:22
7y9uv59mdio2ml8pthz.rod947321.com4df82ccahttps://7y9uv59mdio2ml8pthz.rod947321.com/js/app.26836e23.jsstructure2026-05-24 18:18
nzurrzta.zh-kaiyuntiyu.vipad1a1a47https://nzurrzta.zh-kaiyuntiyu.vip/js/app.26836e23.jsbyte2026-05-24 14:52
2z8lz9wn.zh-kaiyuntiyu.vip07c3ec54https://2z8lz9wn.zh-kaiyuntiyu.vip/js/app.26836e23.jsbyte2026-05-24 14:23
scny8sxt0tw3netx5cz.wdfr5432.com482df1aehttps://scny8sxt0tw3netx5cz.wdfr5432.com/js/app.26836e23.jsstructure2026-05-24 13:09
w7md7vj1mcr2k3.wdfr5432.com729c4d6ehttps://w7md7vj1mcr2k3.wdfr5432.com/js/app.26836e23.jsstructure2026-05-24 11:48
zp8hayjzta6w2gc.abei53434.com4ce0ed83https://zp8hayjzta6w2gc.abei53434.com/js/app.26836e23.jsbyte2026-05-24 00:17
tojagdrjakcm5h.danti4833.com1d5a0c5ahttps://tojagdrjakcm5h.danti4833.com/js/app.26836e23.jsbyte2026-05-22 20:08
pugw1a.danti4833.com8bb8da75https://pugw1a.danti4833.com/js/app.26836e23.jsbyte2026-05-22 17:29
0pmfml59vs7.danti4833.com6bf1b020https://0pmfml59vs7.danti4833.com/js/app.26836e23.jsbyte2026-05-22 17:24