Analysis of moesax.com indicates a high-risk phishing domain registered on July 28, 2026, two days prior to this report. The domain currently resolves to IP address 172.67.209.123 and is hosted on Cloudflare nameservers (guy.ns.cloudflare.com, lorna.ns.cloudflare.com). Infrastructure analysis reveals the domain was registered through Fewmoretaps OU d/b/a Trustname.com, a registrar commonly associated with newly created malicious domains. As of July 30, 2026, the domain appears on one security blocklist, and PhishDestroy has implemented active blocking measures against it.
VirusTotal scanning results show 2 of 91 security vendors flagging moesax.com as malicious, though the specific detection names and methodologies are not disclosed in available intelligence. The exact content or targeted brand of the phishing page remains unconfirmed, as no page title, kit identification, or brand target details are currently available. The domain's recent creation, combined with its presence on security blocklists and vendor detections, strongly suggests active malicious intent, likely focused on credential harvesting or financial fraud. Defenders should treat this domain as hostile and implement immediate blocking at the DNS and proxy levels.
Network security teams are advised to monitor for connections to 172.67.209.123 and review logs for any prior interactions with moesax.com. Given the domain's use of Cloudflare infrastructure, additional scrutiny of SSL certificates and HTTP headers may be warranted to identify related malicious activity. No evidence currently links this domain to known phishing kits or specific threat actor campaigns, limiting attribution at this time.