# PhishDestroy threat dossier — proposal-9.click ================================================================ Fetched: 2026-07-23 17:49:48 UTC Canonical: https://phishdestroy.io/domain/proposal-9.click/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain URLQuery: 2 detections Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 216.227.142.170 (US, Los Angeles) ASN: ASAS30058 FDCSERVERS - FDCservers.net, US Hosting org: AS22612 Namecheap, Inc. Registrar: NAMECHEAP INC Nameservers: dns1.registrar-servers.com, dns2.registrar-servers.com Registered: 2026-07-15 Expires: 2027-07-15 Page title: proposal-9.click is registered at Namecheap HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-15 Status: INVALID chain Fingerprint: 2d27304737c8b8c2ff4465c64059c6f8cc6749c47d964ac0c4c628aacf61d2a9 Subject Alternative Names (related infrastructure — often same operator): - www.proposal-9.click ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-17 07:48:34 UTC (by PhishDestroy tracker) First reported: 2026-07-17 09:13:19 UTC (abuse notice filed) Last verified: 2026-07-23 18:40:20 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f6e9d-1c93-748d-9b35-330eb8ad0217/ URLQuery: https://urlquery.net/report/6246af81-d7d9-4c78-9b49-5a5fe59be9b1 Wayback Machine: https://web.archive.org/web/*/proposal-9.click crt.sh CT logs: https://crt.sh/?q=%25.proposal-9.click Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=proposal-9.click AlienVault OTX: https://otx.alienvault.com/indicator/domain/proposal-9.click URLhaus: https://urlhaus.abuse.ch/host/proposal-9.click/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-17 08:00:58 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] proposal-9.click Generic Phishing Campaign Analysis indicates that the domain proposal-9.click was registered through Namecheap Inc on July 15, 2026 and is currently active. The authoritative name servers are dns1.registrar-servers.com and dns2.registrar-servers.com, and DNS resolution points to the IPv4 address 162.255.119.102. The domain has been submitted to VirusTotal and examined by 95 scanning engines; none of the engines reported a detection at the time of analysis. Although the absence of detections does not confirm benign intent, the classification as generic_phishing suggests the infrastructure is being used for credential‑stealing or information‑gathering campaigns. Publicly available evidence does not reveal the specific brand or service being spoofed, and no page‑level content has been captured. Consequently, the precise lure employed by the site remains unknown. The short registration window (two days before the report date) and the use of generic click‑bait naming patterns are consistent with other fast‑flux phishing operations observed in recent months. Defenders should treat proposal-9.click as malicious. Recommended actions include adding the domain and the associated IP address to block lists at network perimeter devices, updating DNS filtering policies to deny resolution, and configuring email security gateways to flag any messages containing links to this domain. Continuous monitoring of the IP address for additional malicious activity, as well as periodic re‑scanning on VirusTotal or similar platforms, is advised to detect any future changes in the payload or detection status. Incident response teams should also consider investigating any internal logs for prior connections to the domain or its IP to assess potential compromise. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260717-56D6C2 Favicon MD5: e0dc6025f3ad91101529eaab3879cf79 TLS cert SHA-256: 2d27304737c8b8c2ff4465c64059c6f8cc6749c47d964ac0c4c628aacf61d2a9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/proposal-9.click/ JSON API: https://api.destroy.tools/v1/check?domain=proposal-9.click Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 188,933 domains (58,582 alive under monitoring, 128,729 confirmed takedowns/dead). Site: https://phishdestroy.io