moonshot-listing-vfc[.]netlify[.]app
“Vote to List — Powered by Moonshot”
This domain, moonshot-listing-vfc.netlify.app, is under active investigation as a high-risk phishing site targeting cryptocurrency users. Analysis indicates the domain is hosted on Netlify's infrastructure and resolves to the IP address 35.157.26.135, though no nameservers were identified at the time of assessment. The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, suggesting it is part of a known malicious campaign. Despite these flags, the domain was scanned by 91 vendors on VirusTotal with no current detections, though the absence of detections does not confirm safety and may reflect a lag in vendor updates or evasion techniques.
Infrastructure analysis reveals the domain is registered through Netlify, a legitimate hosting provider often exploited for phishing due to its free tier and ease of deployment. The IP address 35.157.26.135 is associated with Amazon Web Services, a common hosting environment for both legitimate and malicious sites. No specific brand or phishing kit has been confirmed in the available data, and the exact content of the site remains unanalyzed. Defenders should treat this domain as actively malicious based on its presence on multiple blocklists and its association with known phishing indicators.
Organizations are advised to block access to this domain at the network level and monitor for related indicators, such as the IP address or similar Netlify-hosted subdomains. Given the high-risk classification and active status, further investigation into the domain's payload and potential connections to broader phishing campaigns is recommended. The domain remains operational as of August 06, 2026, and should be handled with caution until additional intelligence is available.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Technologies · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of moonshot-listing-vfc.netlify.app · checked Aug 6, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive