trk[.]moonpay4btc[.]com
Zusammenfassung der Beweislage
Analysis of trk.moonpay4btc.com identifies it as a confirmed crypto scam domain, operational since February 22, 2026, and currently offline as of July 24, 2026. The domain was hosted on Amazon Web Services (AS16509) at IP 18.189.164.239, located in the United States. It appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, which classify it as malicious infrastructure targeting cryptocurrency users. One of 95 security vendors on VirusTotal flagged the domain, though the specific detection context remains unverified due to limited public telemetry.
Infrastructure review shows the domain used a low-trust SSL certificate (E7) and was registered through an undisclosed registrar. No page title, phishing kit, or brand impersonation details are available in current intelligence, though the 'moonpay4btc' subdomain suggests a likely association with MoonPay, a cryptocurrency payment service. The absence of additional metadata limits further attribution, but the domain's inclusion on multiple crypto-focused blocklists supports its classification as a high-risk asset for financial fraud. Defenders should treat this domain as compromised infrastructure.
Network-level blocking is recommended, particularly for organizations handling cryptocurrency transactions. Security teams should monitor for related subdomains or IP reuse under the same ASN, as threat actors frequently repurpose hosting providers for successive campaigns. No active payloads or redirects were observed at the time of reporting, but historical exposure may warrant retrospective log analysis for potential compromise indicators.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
8 überwachte externe Feeds Kein Treffer
Forensische Erkenntnisse
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt