moon-voting[.]xyz
“Moonshot - Vote To List”
moon-voting.xyz — Erreur de serveur (HTTP 502). Usurpation de l'identité de la marque : Moonshot; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 2/94 (Fortinet, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Bureau d’enregistrement: NiceNIC.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
moon-voting.xyz is a confirmed brand impersonation phishing domain that targeted users of the Moonshot platform. The site posed as a legitimate voting interface with the title 'Moonshot - Vote To List' and was designed to trick visitors into connecting their wallets or entering credentials. The domain is now taken offline, but it posed an elevated risk due to its convincing design and presence on security blocklists.
Technical indicators show that moon-voting.xyz was flagged by 2 of 95 VirusTotal vendors, including Fortinet and SOCRadar, and appeared on 3 security blocklists: PhishDestroy, MetaMask, and SEAL. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 20, 2026, and resolved to IP address 188.114.97.3, which is located in CA and hosted by CloudFlare, Inc. The site used HSTS, Cloudflare Browser Insights, Cloudflare, and HTTP/3 technologies, and had no SSL certificate. Its Gridinsoft trust score was 0/100, and Google Safe Browsing did not flag it.
Although moon-voting.xyz is now offline, users who interacted with it should take immediate safety steps. If any cryptocurrency wallet was connected, revoke all token approvals and move funds to a new wallet. If credentials were entered, change passwords for all associated accounts, enable two-factor authentication, and monitor for unauthorized activity. Report the domain to relevant authorities or blocklist maintainers to help protect others from similar scams.
Renseignements sur la sécurité réseau Registrar context
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 18:56:28 UTC
Analyse forensique
Technologies · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of moon-voting.xyz · checked Mar 23, 2026
Données factuelles et rapports externes
PD-20260324-CA79EC Recipient: abuse@nicenic.net, abuse@gen.xyz, compliance@icann.org Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif