At first I thought this was just a cute way to advertise gambling websites, but it wasn't until someone had began messaging me accusing me of taking over their account that I got suspicious the websites were mischievous or fraudulent. After dorking with the domain for a while and receiving nothing interesting, I decided to send a blind XSS payload and hop offline for a few hours in vain hopes that the website wasn't sanitizing HTML and would therefore allow me to execute arbitrary JS in the scammers instance which would allow me to see the panel that held credentials.