# PhishDestroy threat dossier — 777lucky9.top ================================================================ Fetched: 2026-07-26 09:09:30 UTC Canonical: https://phishdestroy.io/domain/777lucky9.top/ ## VERDICT ---------------------------------------------------------------- ACTIVE THREAT — multiple warning signs Composite threat score: 49/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 4/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker, SOCRadar, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: Gname.com Pte. Ltd. Nameservers: ["davina.ns.cloudflare.com.", "hugh.ns.cloudflare.com."] HTTP response: 200 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-19 13:00:02 UTC (by PhishDestroy tracker) Last verified: 2026-07-26 08:20:27 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-22 11:57:14 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] 777lucky9.top hosts high‑risk generic phishing Analysis of 777lucky9.top shows an active infrastructure delivering generic phishing content. The site responds with HTTP 200, indicating a live web server, and is served through Amazon Web Services behind an Nginx/OpenResty stack that also loads jQuery and Amazon CloudFront. The SSL certificate is issued by Amazon, which is typical for AWS‑hosted sites. DNS resolution is delegated to Cloudflare nameservers davina.ns.cloudflare.com. and hugh.ns.cloudflare.com., confirming use of Cloudflare's DNS and potentially its DDoS protection services. Registration was performed via Gname.com Pte. Ltd., a registrar known for providing privacy‑focused registrations. Security‑vendor scans on VirusTotal report that four of ninety‑one scanners flagged the domain, indicating that at least a minority of AV engines have identified malicious behavior. The domain appears on one public blocklist and is actively blocked by the PhishDestroy service, demonstrating that threat‑intelligence feeds have already recognized it as hostile. While the exact phishing lure (e.g., login credential harvest, financial fraud) is not disclosed, the classification as generic phishing suggests a broad targeting approach. Uncertainties remain regarding the specific payload, any credential‑stealing forms, and the IP addresses serving the content, as those details were not provided. Defenders should immediately add 777lucky9.top to URL filtering and DNS block lists, enforce TLS inspection to capture any credential submissions, and monitor outbound traffic for connections to the associated AWS and CloudFront endpoints. Continuous re‑scanning on VirusTotal and correlation with internal proxy logs are recommended to detect any emerging variants or related domains that share the same hosting infrastructure. [Updates since narrative was generated:] - Public blocklists: now listed on 1 feed ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: d6c17b688f661f2eab41d6071ce164d2 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/777lucky9.top/ JSON API: https://api.destroy.tools/v1/check?domain=777lucky9.top Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 196,405 domains (66,039 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io