MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق moonvoteshot.com
moonvoteshot[.]
This domain, moonvoteshot.com, is currently flagged as an active high-risk phishing operation specifically designed to harvest decentralized finance (DeFi) wallet credentials and private keys.
- VirusTotal
- 14/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- يمكن الوصول إليها · الوصول مقيد · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-contact@publicdomainregistry.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
moonvoteshot.com — يمكن الوصول إليها · الوصول مقيد (HTTP 403). انتحال العلامة التجارية: Cloudflare; نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET); 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 92/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, moonvoteshot.com, is currently flagged as an active high-risk phishing operation specifically designed to harvest decentralized finance (DeFi) wallet credentials and private keys. Analysis indicates the site impersonates legitimate cryptocurrency platforms to deceive users into disclosing sensitive authentication details. The threat type is classified as credential phishing with financial fraud objectives, targeting users of blockchain-based applications. Infrastructure analysis reveals the domain was registered on June 16, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, an uncommon registrar for legitimate financial services. It resolves to IP address 104.21.93.164, which is protected by Cloudflare infrastructure, obscuring the true origin server. The domain appears on three security blocklists and is flagged by 16 of 95 security vendors in aggregated scanning platforms. A Gridinsoft trust score of 0/100 further corroborates malicious classification. The SSL certificate is issued by Google Trust Services, providing a false sense of security while the underlying content remains fraudulent. Detected technologies include HTTP/3 protocol support, indicating modern infrastructure used to evade traditional detection mechanisms. Current assessment confirms the domain remains operational and poses an immediate risk to users of decentralized applications. Users are strongly advised to block all connections to 104.21.93.164 and moonvoteshot.com at the network level. Security teams should update web filtering rules to include this domain and associated IP in deny lists. End-users who may have interacted with the site should immediately revoke any active sessions, rotate credentials, and monitor connected wallet addresses for unauthorized transactions. Organizations handling cryptocurrency transactions should implement additional verification steps for any communication referencing this domain or similar infrastructure patterns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of moonvoteshot.com · checked Jun 25, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260617-7AB750 Recipient: abuse-contact@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.