moremarket[.]ng
“Market Place » MOREMARKET”
Riepilogo delle prove
moremarket.ng is currently listed as an active high‑risk generic‑phishing site. The landing page returns HTTP 200 and presents the title “Market Place » MOREMARKET”, indicating an attempt to mimic a legitimate marketplace. The site employs a Let’s Encrypt certificate (R12), which provides encrypted transport but does not authenticate the underlying business purpose. The domain is registered through AfeesHost Ltd and is served by the nameservers dns3.afeeshost.com, dns1.afeeshost.ltd, and dns2.afeeshost.ltd. Network analysis shows the domain resolves to 148.72.153.160, an address hosted in the United States and associated with the velia.net provider. The same IP has been observed in other phishing campaigns, and the host appears on a single security blocklist. PhishDestroy has already blocked the domain, confirming its malicious intent. The use of standard hosting and a publicly trusted TLS certificate is consistent with tactics that aim to increase credibility among victims. VirusTotal scans report that 14 of 95 security vendors flag the domain as malicious, reinforcing the suspicion of phishing activity. No evidence of additional payloads or malware distribution has been observed; the primary threat vector is credential harvesting via a counterfeit marketplace interface. The site’s status remains active as of the reporting date, and its page content has not changed since detection. Defenders should add 148.72.153.160 and the domain name to network deny lists and monitor DNS queries for the associated nameservers. Email gateways should be configured to reject or quarantine messages that reference the domain or the “Market Place » MOREMARKET” title. Continuous threat‑intel feeds should be consulted for any future re‑hosting attempts, and incident response teams should be prepared to investigate credential compromise reports linked to this domain.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/9c/common.js |
audit | Hunting_JS_WebAssembly |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo