moonpay-commerce-jql3k2i1g-heliofi[.]vercel[.]app
“MoonPay Commerce | Sell more with crypto ⚡️”
moonpay-commerce-jql3k2i1g-heliofi.vercel.app — ढका हुआ · पहुंच योग्य. साक्ष्य सारांश: VirusTotal 22/91 (ChainPatrol, Criminal IP, AILabs (MONITORAPP), alphaMountain.ai, BitDefender); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. रजिस्ट्रार: Vercel.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, moonpay-commerce-jql3k2i1g-heliofi.vercel.app, is flagged as an active crypto-focused phishing site targeting users under the guise of a legitimate payment service. Analysis indicates the domain is hosted on Vercel infrastructure and resolves to 64.29.17.195 (AS16509, Amazon.com, Inc., US). The SSL certificate is issued by Google Trust Services, a common but not inherently trustworthy indicator, and the domain enforces HSTS, which may complicate takedown efforts. The page title, 'MoonPay Commerce | Sell more with crypto ⚡️,' explicitly mimics MoonPay, a known cryptocurrency payment processor, suggesting intent to deceive users into entering credentials or transferring funds. No nameservers are currently detected, which is atypical for legitimate services and may indicate evasion tactics. The domain is blocked by multiple security vendors, including PhishDestroy, MetaMask, and SEAL, and appears on three security blocklists. Gridinsoft assigns a trust score of 0/100, reinforcing its high-risk classification. While 14 of 91 security vendors on VirusTotal flag the domain, this does not constitute definitive proof of malicious activity but aligns with broader detection patterns. Technologies detected include Vercel hosting and Google Analytics, the latter of which is often abused for tracking victim interactions. Defenders should treat this domain as a confirmed phishing threat. Immediate actions include blocking resolution at the DNS level, adding the domain to web filtering rules, and monitoring for related infrastructure (e.g., subdomains, IP reuse). Given the crypto-themed branding, security teams should prioritize alerts for wallet interactions or credential submissions linked to this domain. Further analysis of the site’s content and backend infrastructure is recommended to identify additional indicators of compromise, though the current evidence is sufficient to justify proactive mitigation.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of moonpay-commerce-jql3k2i1g-heliofi.vercel.app · checked Jul 4, 2026
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।