moonshot-listing-hna[.]netlify[.]app
“Vote to List — Powered by Moonshot”
Analysis of moonshot-listing-hna.netlify.app indicates an active generic phishing operation hosted on Netlify infrastructure. The domain resolves to IP address 35.157.26.135, a Netlify edge node commonly used for short-lived content delivery. DNS resolution data reports NS_NOT_FOUND, suggesting the site relies on Netlify's default nameserver configuration rather than custom delegations. The domain was submitted to VirusTotal and examined by 91 antivirus and sandbox engines; none of the engines generated a detection, but the absence of flags does not constitute evidence of benign intent.
The site appears on three independent security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, confirming community consensus that the domain is being used for malicious phishing campaigns. Registration details show the domain was provisioned through Netlify, a platform that permits rapid deployment of static sites without extensive verification, a characteristic often abused by threat actors to launch temporary phishing pages. Current status is listed as active, meaning the site is reachable and capable of delivering malicious payloads or credential‑harvesting pages. No additional data such as SSL certificate details, HTTP response codes, Safe Browsing verdicts, OTX indicators, or page titles are presently available, leaving those aspects of the infrastructure unverified.
Defenders should prioritize immediate DNS or URL filtering of the domain, enforce endpoint blocking of the associated IP range, and monitor outbound traffic for connections to the Netlify edge node. Incident response teams are advised to submit takedown requests to Netlify and to share the indicator set with threat‑intelligence sharing platforms to accelerate broader mitigation. Continuous re‑assessment is recommended, as the domain may change hosting or content rapidly, typical of phishing operations hosted on cloud‑based platforms.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Technologies · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of moonshot-listing-hna.netlify.app · checked Aug 6, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive