PhishDestroy first observed moesax.com on Jul 30, 2026. Stored content metadata identifies ["x.com"] as the apparent target. The captured page title is “Moesax: Most Popular Online Crypto Casino Based on Blockchain”. Stored page analysis classifies the content as impersonation. Campaign clustering links the hostname to the Gambler Scam kit. Current evidence score: 100/100 (critical).
Positive findings are stored from 5 sources: VirusTotal, MetaMask, ScamSniffer, SEAL, and URLScan. VirusTotal recorded 15 detections among 91 engines: alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, SOCRadar, Sophos, VIPRE on Aug 8, 2026 at 02:17 UTC. MetaMask, ScamSniffer, and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 8, 2026 at 06:20 UTC. URLScan returned a malicious verdict with score 100; scan metadata assigned phishing as its category on Aug 1, 2026 at 03:30 UTC. Non-positive and contextual checks: Gridinsoft assigned a trust score of 1/100; no observation timestamp was retained. Google Safe Browsing returned no flag on Jul 30, 2026 at 01:26 UTC.
HTTP 200 was recorded on Aug 7, 2026 at 22:18 UTC. Registration records for the domain list Fewmoretaps OU d/b/a Trustname.com as the registrar and Jul 28, 2026 as the creation date. Registration preceded first observation by 1 day. At collection time, the hostname resolved to 172.67.209.123 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jul 30, 2026 at 02:20 UTC returned 81/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists Google Trust Services as the certificate issuer with validity through Oct 28, 2026; checked Jul 30, 2026 at 13:02 UTC.
The content indicators and 5 positive source findings support the current ["x.com"]-themed impersonation classification.