MALICIOUS — HIGH
فحص التصيد والأمان للنطاق moonshot-top.fun
moonshot-top[.]
The domain moonshot-top.fun was registered on March 07, 2026 through PDR Ltd.
- VirusTotal
- 6/94
- Blocklists
- 1 · ScamSniffer
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
moonshot-top.fun — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Moonshot; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 6/94 (LevelBlue); 1 external blocklist match (ScamSniffer); PhishDestroy score 68/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
The domain moonshot-top.fun was registered on March 07, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to the Cloudflare‑owned address 104.21.89.15, which is located in Canada and serves content over HTTP/3 with HSTS and Cloudflare Browser Insights enabled. No TLS certificate was observed, indicating the site was operating without HTTPS at the time of capture. The public page title returned by the server reads “Vote to List — Powered by Moonshot”, and the site is classified as a crypto‑related scam that impersonates the Moonshot brand.
Six of ninety‑four VirusTotal scanners flagged the domain as malicious, and the domain appears on two independent blocklists, PhishDestroy and ScamSniffer. Gridinsoft assigned a trust score of zero out of one hundred, reinforcing the malicious assessment. The domain is currently offline, and its status is listed as taken offline in the intelligence feed. Content of the landing page beyond the title has not been captured, so the exact phishing flow, credential collection mechanisms, or cryptocurrency address usage remain unknown.
No evidence of a valid SSL certificate or redirection to a secondary payload host was found, but the use of Cloudflare suggests the operator may switch hosting or enable HTTPS at a later stage. Defenders should add 104.21.89.15 to network‑level deny lists, block the domain moonshot-top.fun in DNS filtering solutions, and monitor for future activity from the same registrar or nameserver pair (razvan.ns.cloudflare.com, rihana.ns.cloudflare.com). Threat‑intel teams should correlate any observed Moonshot‑related credential submissions with this indicator, and incident response teams should treat any communications referencing “Vote to List” as potentially malicious.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of moonshot-top.fun · checked Mar 21, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260321-BA60F9 Recipient: abuse@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.