moonreels[.]one
“Moon Reels”
Résumé des preuves
This domain, moonreels.one, is currently flagged as a generic phishing threat and is under active investigation as of August 06, 2026. The domain remains active and resolves to IP address 172.67.158.196, which is associated with Cloudflare infrastructure, as indicated by its nameservers gwen.ns.cloudflare.com and kip.ns.cloudflare.com. The domain is listed on one security blocklist and is blocked by the PhishDestroy service, confirming that at least one independent security source has identified it as a potential threat.
VirusTotal has scanned the domain with 91 vendors, and none currently flag it as malicious. This absence of detections should not be interpreted as proof that the domain is safe, as phishing domains often evade detection until they are actively used in campaigns. The low blocklist presence and lack of vendor flags may indicate that the domain is either newly registered, not yet widely distributed, or cleverly disguised.
The exact nature of the phishing campaign remains unclear. The domain is classified as generic phishing, but no specific brand, page title, or scam kit has been identified in the available intelligence. Analysts have not yet been able to view the live content of the site, so the precise lure or impersonated service is unknown. This lack of detail is common in early-stage investigations, and further analysis is required to determine the targeting strategy.
Defenders should treat moonreels.one as a potential threat and monitor any traffic to it. Organizations should block the domain at the DNS and proxy levels, and users should be warned against clicking links from unknown sources that direct to this domain. Given the domain's active status and Cloudflare hosting, which can obscure the origin server, investigators should continue to monitor for changes in DNS records, SSL certificate issuance, and any updates to the page content.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Première observation
Première valeur enregistrée : Accessible
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 technologies identifiées avec une forte confiance
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of moonreels.one · checked Aug 6, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif