qr-moonshot[.]com
“404: NOT_FOUND”
Evidence Summary
qr-moonshot.com was registered on June 07, 2026 through Name.com, Inc. Within days of creation the domain appeared on three public security blocklists and has been actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal scans show that 17 of 91 security vendors have raised detections against the domain, indicating a significant malicious signal despite the majority of scanners remaining clean. The blocklist presence and vendor detections together classify the domain as a high‑risk phishing infrastructure.
No additional intelligence such as hosting IP, ASN, or SSL certificate details has been released, and the page title or any landing‑page content has not yet been analyzed publicly. The lack of deeper infrastructure data limits attribution, but the early detection pattern suggests a purposeful campaign aimed at credential harvesting or wallet compromise. Defenders should immediately add qr-moonshot.com to DNS and web‑proxy deny lists, enforce safe‑browsing controls, and monitor outbound connections for any attempts to resolve the domain.
Security teams should also consider enriching future observations with passive DNS, SSL‑certificate transparency logs, and sandbox analysis to capture potential payloads if the site begins serving malicious content. Ongoing observation is advised, as the domain remains active and may evolve its tactics.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
8 monitored external feeds No match
Detection timeline
-
VirusTotal
17 → 18
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
2 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of qr-moonshot.com · checked Jul 29, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive