moonjoin[.]top
moonjoin.top की फ़िशिंग और सुरक्षा जाँच
“KOL – Vote to list on Moonshot”
moonjoin.top — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Moonshot; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 10/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 4 alerts; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. रजिस्ट्रार: Global Domain Group.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain moonjoin.top was registered on June 22 2026 through Global Domain Group LLC and is currently hosted on Cloudflare’s network (AS13335) with the IP address 188.114.96.3 located in the United States. The authoritative name servers are coleman.ns.cloudflare.com and kim.ns.cloudflare.com, and the site presented a TLS certificate issued by Google Trust Services under the WE1 trust store, indicating a valid HTTPS endpoint. The page title observed during the brief live period was “KOL – Vote to list on Moonshot”, and the site was identified as employing AngularJS, Cloudflare Browser Insights, and HTTP/3, all typical of modern web applications served behind Cloudflare. Security telemetry shows that moonjoin.top appears on three public blocklists and has been flagged by the PhishDestroy, MetaMask, and SEAL blocking services.
VirusTotal scans recorded detections from ten of ninety‑one antivirus engines, and AlienVault OTX listed the domain in a single threat‑intelligence pulse. The infrastructure matches a known “Seed Phrase Phishing” kit, which targets cryptocurrency users by prompting them to disclose private recovery phrases. The domain is explicitly described as impersonating the Moonshot brand, a clear case of brand impersonation. The current operational status is offline, and the risk rating assigned by the reporting entity is high.
While the offline state limits immediate exposure, the combination of a recent registration, legitimate‑looking TLS certificate, Cloudflare hosting, and active blocklist listings suggests a purposeful attempt to gain user trust and harvest seed phrases. Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑registration attempts, and add the observed indicators—such as the IP address 188.114.96.3, the Cloudflare name servers, and the TLS fingerprint—to threat‑intel feeds.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | moonslogin.co |
phishing | Phishing Block |
| Hagezi Threat Feed | moonslogin.co |
malicious | Sinkholed |
| DNS4EU | moonslogin.co |
malicious | Sinkholed |
| DNS4EU | moonjoin.top |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 4 identified
AngularJS is a JavaScript-based open-source web application framework led by the Angular Team at Google.
angularjs.org 100% विश्वासCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260624-EAEE83 Recipient: abuse@globaldomaingroup.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।