xn--monshot-nmb[.]net
“Vote to List — Powered by Moonshot”
Registered just three days ago, xn--monshot-nmb[.]net is hosted on an IP address (104.21.10.179) that has been associated with malicious activities. The domain has also been blocklisted once, indicating prior concerns about its reliability and purpose. Such factors suggest that it may be targeting users for credential theft or other malicious intents.
PhishDestroy is actively monitoring this domain to mitigate potential risks. It remains operational at this time, and further investigation is crucial to prevent any harmful outcomes related to this phishing attempt.
Threat Response Pipeline
Public Blocklist Status
Evidence Capture
Domain Intelligence
priscilla.ns.cloudflare.com
http://whois.nicenic.com/?page=whoisform
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If you have interacted with this domain, entered personal information, or connected a cryptocurrency wallet — take immediate action. Below are resources to help you report the incident and protect yourself.
Report to Your Local Authorities
Select your country to see local cybercrime reporting contacts and complaint templates.
Related Domain Reports
More Domains at NICENIC INTERNATIONAL GROUP CO., LIMITED
Other Moonshot Impersonation Domains
These domains also target Moonshot users. View all Moonshot threats →
About This Report: xn--monshot-nmb.net
This domain security report for xn--monshot-nmb.net is maintained by PhishDestroy's automated threat intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal, 1 public blocklists, URLScan.io.
The site displays a page titled “Vote to List — Powered by Moonshot”, which may be designed to impersonate Moonshot.
xn--monshot-nmb.net has been flagged by 3 security vendors as of February 27, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.
Stay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive




URLScan Report