app[.]moon[.]villas
“app.moon.villas”
Deteksi tersimpan
Peringatan penyamaran
- Jenis penyamaran
status_split- Skor penyamaran
- 1/6
Ringkasan bukti
PhishDestroy identifies app.moon.villas as an active cryptocurrency drainer campaign under investigation since seed 739c5a. The domain mimics a legitimate villa booking service to trick victims into connecting wallets and approving malicious token transfers. No specific brand or drainer kit has been attributed yet, but infrastructure overlaps with known fake booking portals observed in Southeast Asia phishing clusters. The page title and SSL certificate (Let’s Encrypt) are consistent with operational phishing pages designed to appear credible during initial access. Further behavioral analysis is ongoing to map this campaign to a wider threat actor group or infrastructure family.
This domain was flagged by PhishDestroy with the following technical indicators: VirusTotal detection score of 1/95 as of the latest scan, hosted on IP 216.150.16.65, using a Let’s Encrypt SSL certificate issued to app.moon.villas. The domain is registered via NameBright.com and was created on March 12, 2024. Google Safe Browsing (GSB) has no current blocklisting, and third-party threat intelligence platforms show zero prior detections. The domain is currently resolving and actively serving a spoofed booking interface that prompts wallet connections under the guise of “secure payment processing.”
The campaign is classified as ACTIVE with a risk level of UNDER_INVESTIGATION. PhishDestroy has initiated takedown coordination with hosting provider Liquid Web and SSL issuer Let’s Encrypt. Users are advised to block the domain at network and endpoint levels and avoid interaction. While the immediate risk is elevated due to active hosting and lack of signature-based detection, the absence of prior abuse history suggests opportunistic deployment rather than sustained targeting. Remaining risk includes potential pivoting to similar domains under the moon.villas namespace. Users should monitor wallets for unauthorized token approvals or transfers and report suspicious domains via PhishDestroy’s portal.
Data Coverage
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber eksternal dipantau · snapshot tersimpan 12/08/2026
Laporan komunitas
Dilaporkan oleh 1 anggota komunitas; pertama terlihat 24/03/2026
- Laporan tersimpan
- 1
- URL unik yang dilaporkan
- 1
Tangkapan tersimpan
Intelijen Domain
Detail teknisDNS, nama TLS, dan stempel waktu
ICANN OVERSIGHT
Registration: moon.villas
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain moon.villas behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive