Analysis of moriarty-vhod-site.com, first observed on July 19, 2026, indicates that the domain is currently active and associated with a generic phishing campaign. The domain was registered through Fewmoretaps OU d/b/a Trustname.com, and its authoritative DNS is hosted on Cloudflare, using the nameservers igor.ns.cloudflare.com and jean.ns.cloudflare.com. Network resolution points to the IP address 104.21.70.116, which is consistent with Cloudflare's edge infrastructure.
VirusTotal records show that the domain has been scanned by 91 security vendors, none of which reported a detection at the time of analysis; this lack of detections does not imply safety, as the payload or hosting may be transient. The domain appears on a single security blocklist and is actively blocked by PhishDestroy, reinforcing the suspicion of malicious intent. No additional public intelligence such as page title, SSL certificate details, HTTP response codes, or brand targeting has been disclosed, leaving those aspects unverified.
Given the recent creation date, active status, and inclusion on a phishing‑focused blocklist, defenders should treat moriarty-vhod-site.com as a high‑confidence phishing indicator. Recommended mitigation steps include adding the domain to local deny lists, enforcing DNS‑level blocking, monitoring outbound traffic for connections to 104.21.70.116, and reviewing any user reports that reference the domain. Continuous re‑evaluation is advised, as threat actors may modify the underlying content or infrastructure without notice.