moonpay-widget-navy[.]vercel[.]app
“Create Next App”
moonpay-widget-navy.vercel.app — ढका हुआ · पहुंच योग्य. घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 3/91 (ChainPatrol, alphaMountain.ai, Forcepoint ThreatSeeker); cloaking observed; PhishDestroy score 98/100. रजिस्ट्रार: Tucows.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, moonpay-widget-navy.vercel.app, is flagged as a high-risk crypto credential theft operation targeting users of a widely recognized cryptocurrency payment gateway. Analysis indicates the threat actor has deployed a credential harvesting interface disguised as a legitimate widget, likely leveraging a Next.js framework given the page title 'Create Next App.' No direct association with a known drainer kit has been confirmed, though the infrastructure aligns with common credential theft tactics observed in recent campaigns impersonating crypto payment processors.
Infrastructure analysis reveals the domain is hosted on IP 64.29.17.195 within Amazon.com, Inc.'s AS16509, a frequent choice for malicious hosting due to its ephemeral nature. The domain was registered through Tucows Domains Inc. on February 21, 2026, though this date may reflect a falsified record or placeholder. VirusTotal detection stands at 2/95 security vendors, while three independent blocklists—PhishDestroy, MetaMask, and SEAL—have already classified the domain as malicious. The SSL certificate, issued by Google Trust Services (WR1), provides minimal legitimacy but does not mitigate the underlying threat. No Google Safe Browsing (GSB) flags were observed at the time of analysis, suggesting either recent deployment or evasion of automated detection systems.
As of the latest assessment, the domain remains active and unresolved, posing an ongoing risk to users who may encounter it through phishing links or compromised platforms. Response actions by security providers have included blocklisting, though the domain's Vercel-based hosting allows for rapid redeployment under new subdomains. Users are advised to verify payment gateway URLs directly through official sources and avoid interacting with unsolicited widget interfaces. Organizations should monitor for this domain in logs and implement real-time blocking of the IP and associated indicators to prevent credential exposure.
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of moonpay-widget-navy.vercel.app · checked Mar 7, 2026
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।