app[.]moon[.]villas
“app.moon.villas”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
status_split- درجة الإخفاء
- 1/6
ملخص الأدلة
PhishDestroy identifies app.moon.villas as an active cryptocurrency drainer campaign under investigation since seed 739c5a. The domain mimics a legitimate villa booking service to trick victims into connecting wallets and approving malicious token transfers. No specific brand or drainer kit has been attributed yet, but infrastructure overlaps with known fake booking portals observed in Southeast Asia phishing clusters. The page title and SSL certificate (Let’s Encrypt) are consistent with operational phishing pages designed to appear credible during initial access. Further behavioral analysis is ongoing to map this campaign to a wider threat actor group or infrastructure family.
This domain was flagged by PhishDestroy with the following technical indicators: VirusTotal detection score of 1/95 as of the latest scan, hosted on IP 216.150.16.65, using a Let’s Encrypt SSL certificate issued to app.moon.villas. The domain is registered via NameBright.com and was created on March 12, 2024. Google Safe Browsing (GSB) has no current blocklisting, and third-party threat intelligence platforms show zero prior detections. The domain is currently resolving and actively serving a spoofed booking interface that prompts wallet connections under the guise of “secure payment processing.”
The campaign is classified as ACTIVE with a risk level of UNDER_INVESTIGATION. PhishDestroy has initiated takedown coordination with hosting provider Liquid Web and SSL issuer Let’s Encrypt. Users are advised to block the domain at network and endpoint levels and avoid interaction. While the immediate risk is elevated due to active hosting and lack of signature-based detection, the absence of prior abuse history suggests opportunistic deployment rather than sustained targeting. Remaining risk includes potential pivoting to similar domains under the moon.villas namespace. Users should monitor wallets for unauthorized token approvals or transfers and report suspicious domains via PhishDestroy’s portal.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
بلاغات المجتمع
أبلغ عنه عضو واحد في المجتمع؛ شوهد أول مرة في 24/03/2026
- البلاغات المحفوظة
- 1
- عناوين URL الفريدة المبلغ عنها
- 1
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
Registration: moon.villas
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain moon.villas behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب