Known malicious kithighphishing

[X][N].cn Random-Pattern Kit — chunk-vendors

family: letterhex-cn-25f3

7-host operator on .cn TLD with letter+digit random pattern: j3h1k9.cn, m9u6y0.cn, n4c6v5.cn, p4i6o3.cn, q4x9v6.cn, q7e2r6.cn, q8t4y7.cn.

Sightings (14)

HostScanScriptMatchWhen
p4i6o3.cn55ef662chttps://p4i6o3.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-25 00:20
p4i6o3.cn55ef662chttps://p4i6o3.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-25 00:20
q8t4y7.cncd28a4a1https://q8t4y7.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:57
q8t4y7.cncd28a4a1https://q8t4y7.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:57
q4x9v6.cneb59fb3ehttps://q4x9v6.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:49
q4x9v6.cneb59fb3ehttps://q4x9v6.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:49
j3h1k9.cn8370e70ehttps://j3h1k9.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:35
j3h1k9.cn8370e70ehttps://j3h1k9.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:35
q7e2r6.cnb67a349fhttps://q7e2r6.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:32
q7e2r6.cnb67a349fhttps://q7e2r6.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:32
m9u6y0.cn0cc9f574https://m9u6y0.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:21
m9u6y0.cn0cc9f574https://m9u6y0.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:21
n4c6v5.cn3fd545bahttps://n4c6v5.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:15
n4c6v5.cn3fd545bahttps://n4c6v5.cn/static/js/chunk-vendors.3f56995a.jsbyte2026-05-24 23:15