# PhishDestroy threat dossier — 9ifashion.com ================================================================ Fetched: 2026-07-26 05:32:16 UTC Canonical: https://phishdestroy.io/domain/9ifashion.com/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 86/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 1/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/93 security vendors flagged this domain Flagging vendors: SOCRadar Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 47.119.28.120 (CN, Shenzhen) ASN: ASAS37963 ALIBABA-CN-NET Hangzhou Alibaba Advertising Co.,Ltd., CN Hosting org: AS37963 Hangzhou Alibaba Advertising Co.,Ltd. Registrar: Shanghai Meicheng Technology Information Development Co., Ltd. Nameservers: ["a.ezdnscenter.com", "b.ezdnscenter.com"] Registered: 2026-02-26 Expires: 2025-11-16 Page title: 关注最前沿的时尚消费,这里是时尚的选择. - 小轩窗 HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-05-21 Status: INVALID chain Fingerprint: 85eb989f51beed5861b1fdd0d76d2e88637bc2b473ce8881cc4acc682b60bb50 Subject Alternative Names (related infrastructure — often same operator): - www.9ifashion.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-26 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-02-26 17:38:09 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-02-26 14:41:46 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-07-26 04:21:15 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019c9a60-dc1d-76fe-bf5c-68c67d5160eb/ URLQuery: https://urlquery.net/report/4df9d9f1-5540-4e45-9427-3d737b048f74 Wayback Machine: https://web.archive.org/web/*/9ifashion.com crt.sh CT logs: https://crt.sh/?q=%25.9ifashion.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=9ifashion.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/9ifashion.com URLhaus: https://urlhaus.abuse.ch/host/9ifashion.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-13 00:46:57 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is 9ifashion.com Safe? This report analyzes 9ifashion.com, a domain flagged as a generic phishing threat with a high risk level as of July 12, 2026. The domain was registered on February 26, 2026, through Shanghai Meicheng Technology Information Development Co., Ltd., and resolves to IP address 47.119.28.120, hosted in China on AS37963 (Hangzhou Alibaba Advertising Co., Ltd.). The page title is '关注最前沿的时尚消费,这里是时尚的选择. - 小轩窗', indicating a Chinese-language fashion-oriented site. Infrastructure analysis reveals the use of Nginx, jQuery, Clipboard.js, and Baidu Analytics, with an SSL certificate from Let's Encrypt. The domain is currently active and appears on three security blocklists: PhishDestroy, MetaMask, and SEAL. VirusTotal data shows 1 out of 93 security vendors flagging this domain. The Gridinsoft trust score is 0/100, suggesting high suspicion. The HTTP status is 301 (redirect), which may be used to obfuscate the final destination. The exact nature of the phishing content has not been analyzed, and no specific brand or scam category is confirmed from the available data. Defenders should block this domain at the network level, monitor for any associated subdomains or IP changes, and educate users about potential phishing risks from unknown fashion-related sites. [Updates since narrative was generated:] - VirusTotal detections: now 1/93 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260226-C201F0 TLS cert SHA-256: 85eb989f51beed5861b1fdd0d76d2e88637bc2b473ce8881cc4acc682b60bb50 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/9ifashion.com/ JSON API: https://api.destroy.tools/v1/check?domain=9ifashion.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,454 domains (65,088 alive under monitoring, 128,816 confirmed takedowns/dead). Site: https://phishdestroy.io