الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref 04D95983

MALICIOUS — HIGH

فحص التصيد والأمان للنطاق moonshot-top.fun

moonshot-top[.]fun

The domain moonshot-top.fun was registered on March 07, 2026 through PDR Ltd.

68/100 evidence score · High
VirusTotal
6/94
Blocklists
1 · ScamSniffer
التوفر
المحتوى غير متوفر · HTTP 502
Report / Add Evidence Appeal this listing
2026-03-21 03:44 UTCالمحتوى غير متوفر · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 6. قوائم الحظر العامة التي تبلغ عن تطابق: 1. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

moonshot-top.fun — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Moonshot; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 6/94 (LevelBlue); 1 external blocklist match (ScamSniffer); PhishDestroy score 68/100. مسجّل النطاق: PDR.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref 04D95983

The domain moonshot-top.fun was registered on March 07, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to the Cloudflare‑owned address 104.21.89.15, which is located in Canada and serves content over HTTP/3 with HSTS and Cloudflare Browser Insights enabled. No TLS certificate was observed, indicating the site was operating without HTTPS at the time of capture. The public page title returned by the server reads “Vote to List — Powered by Moonshot”, and the site is classified as a crypto‑related scam that impersonates the Moonshot brand.

Six of ninety‑four VirusTotal scanners flagged the domain as malicious, and the domain appears on two independent blocklists, PhishDestroy and ScamSniffer. Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the malicious assessment. The domain is currently offline, and its status is listed as taken offline in the intelligence feed. Content of the landing page beyond the title has not been captured, so the exact phishing flow, credential collection mechanisms, or cryptocurrency address usage remain unknown.

No evidence of a valid SSL certificate or redirection to a secondary payload host was found, but the use of Cloudflare suggests the operator may switch hosting or enable HTTPS at a later stage. Defenders should add 104.21.89.15 to network‑level deny lists, block the domain moonshot-top.fun in DNS filtering solutions, and monitor for future activity from the same registrar or nameserver pair (razvan.ns.cloudflare.com, rihana.ns.cloudflare.com). Threat‑intel teams should correlate any observed Moonshot‑related credential submissions with this indicator, and incident response teams should treat any communications referencing “Vote to List” as potentially malicious.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
6 det.
شهادة TLS
Let's Encrypt
العمر
5 mo
الحالة المرصودة
المحتوى غير متوفر 502
PhishDestroy
قائمة الإتلاف
مُدرج
Reports Sent
1
نطاق تغطية البيانات12 recorded checks
VirusTotal 6 / 94 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict التقييم غير متاح حجب عناوين DNS 14 تم الفحص — لا يوجد حظر TLS valid certificate, 75d WHOIS 5 mo old لقطة شاشة 3 captures · 3 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
14/14
تم استيعاب التهديد
moonshot-top.fun تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
21/03/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
6/94 recorded on VirusTotal
27/04/2026
Google Safe Browsing
21/03/2026
الكشف عن قوائم الحظر
موجود في 1 blocklist: ScamSniffer
09/08/2026
Brand Impersonation
Impersonation of Moonshot
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
يحتوي التقرير على التكنولوجيا المخزنة أو نتائج تحليل الطب الشرعي.
09/08/2026
VT detections increased by 1
+1 new detection (0 → 1): LevelBlue
21/03/2026
Sent Report Recorded
Stored sent-report record for registrar PDR Ltd. d/b/a PublicDomainRegistry.com, hosting provider
21/03/2026
تم نشر قائمة «DestroyList»
21/03/2026
Content Observed Unavailable
تشير أحدث عمليات التحقق المخزنة إلى أن المحتوى الذي تم الإبلاغ عنه غير متوفر؛ هذا لا يحدد من أو ما سبب التغيير.
03/04/2026
الوقت حتى أول تعذّر للوصول
انقضت ساعات 309 منذ الكشف وحتى أول ملاحظة غير متاحة.

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
Vote to List — Powered by Moonshot
Impersonates
Celer Solana
شهادة TLS
Valid transport encryption · صادرة عن Let's Encrypt · valid for 75 days

معلومات النطاق

النطاق
Telegram IoCs 3 extracted https://t.me/share/url?url=https%3A… text=Vote%20for%20%24JUICE%20on%20M… https://t.me/share/url?url=
الخادم / ASN AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden لا تُنسب سمعة Edge-IP إلى هذا المجال.
مسجّل النطاق PDR DE(DE)
عنوان IP 104.21.89.15 CDN
الموقع الجغرافيCA Toronto, CA
الشبكةAS13335 · Cloudflare, Inc.
يتم إخفاء عنوان IP الأصلي خلف وكيل CDN. تحتوي نتائج IP العكسي لعنوان الحافة على مستأجرين غير مرتبطين؛ يتطلب العثور على المصدر نظام أسماء النطاقات السلبي أو بيانات شفافية الشهادة.
التسجيلتم إنشاؤه 07/03/2026 (155d)
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 13 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف21/03/2026
DOM Analysisanalyzed 29/07/2026score 63/1002 brand signals
IoC Extractionscanned 01/08/20260 wallet · 3 Telegram IoCs
Submitted URLhttp://moonshot-top.fun/
خوادم الأسماءrazvan.ns.cloudflare.comrihana.ns.cloudflare.com
TLS Observationscanned 27/04/2026
Case ID
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.
التقنيات · 4 identified
HSTS
الأمن

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via رادار Cloudflare · Wappalyzer engine
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

6 / قام موردو الأمان 94 بوضع علامة على هذا المجال
View on VT
Last analyzed
LevelBlue
تحليل أداء الموقع

Google PageSpeed Insights — mobile performance audit of moonshot-top.fun · checked Mar 21, 2026

56
Needs Work
Performance
FCP
8.28s
First Contentful Paint
LCP
8.28s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
67ms
Total Blocking Time
SI
8.28s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260321-BA60F9 Recipient: abuse@publicdomainregistry.com
Page title stored with report: Vote to List — Powered by Moonshot
نظام أسماء النطاقات (DNS) والشبكات
تحسين محركات البحث (SEO) والنطاقات
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/moonshot-top.fun"
  title="PhishDestroy threat report for moonshot-top.fun"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.