9659aap19.vip
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.
Description of 9659aap19.vip
The domain 9659aap19.vip appears to host a sparse Chinese-language landing page that promotes access links related to online betting or gambling-style services. The page title is a generic "welcome!", and the visible content includes promotional text about bonuses, deposits, and route links, which suggests the site may be functioning as a gateway or referral page rather than a full standalone business website.
Based on the domain format, the .vip extension, and the minimal branding shown in the screenshot, the site does not appear to represent a clearly identified organization or established operator. The content references gambling-oriented offers and access paths, but ownership and business details are not evident from the page itself, which limits transparency about who runs the website.
Safety Assessment for 9659aap19.vip
This domain shows several notable risk indicators at the time of this scan. It was flagged by 10 out of 91 security engines, and multiple web-classification providers categorized it as phishing, fraud, or closely related abuse. In addition, the page content appears inconsistent with a trustworthy consumer-facing service: it uses a generic title, limited branding, and promotional gambling-style language with bonus offers and access-route links, which may be associated with deceptive traffic funnels or credential-harvesting campaigns.
The malware scan also reported suspicious elements, including flagged page resources and a referenced external IP-based link marked as suspicious. While major content-malice databases listed in the scan were not all triggered, the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal but still worth noting. The domain is also very new, not ranked for traffic, and lacks clear operator identification, all of which add to the uncertainty.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, and traffic appears to be proxied through Cloudflare infrastructure. The resolved server IP is 104.21.40.174, with Cloudflare nameservers in use, which can help with availability and basic transport encryption but does not by itself indicate legitimacy. The certificate was valid at the time of the scan, though the exact negotiated protocol details were not provided.
From a domain-security perspective, the domain is relatively new at 158 days old and DNSSEC is not enabled. The site is hosted behind a reverse-proxy service, which can obscure origin hosting details. Additional concerns include suspicious outbound references identified during scanning and the use of an unsigned DNS configuration, although the latter is common and not inherently harmful on its own.
Share your experience with this website. Was it safe? Did you encounter any issues?