This domain, moonshot-dex.org, was registered on July 22 2026 through Fewmoretaps OU doing business as Trustname.com. The domain resolves to the IPv4 address 186.2.175.109 and is served by four name servers: ares.trustname.com, zeus.trustname.com, ns1.anycastdns.cz, and ns2.anycastdns.cz. Within days of creation it appeared on a single security blocklist and has been actively blocked by the PhishDestroy filter set. VirusTotal analysis shows that five of ninety‑one scanning engines have raised a detection, confirming the presence of malicious activity.
The domain is currently listed as high‑risk and remains active as of the report date, July 30 2026. Available intelligence does not include SSL certificate details, HTTP response codes, or page‑title information, so the exact content delivered to victims cannot be described at this time. Similarly, no public Open Threat Exchange (OTX) entries or Google Safe Browsing hits have been observed. The limited detection footprint—one blocklist entry and five VirusTotal flags—suggests that the infrastructure is newly deployed and may be targeting a narrow audience before broader propagation.
Defenders should add moonshot-dex.org to local deny lists, enforce outbound DNS filtering, and ensure that any security gateway that references PhishDestroy updates its feed to block the domain. Because the domain is hosted on an anycast DNS service, threat‑intel sharing with the hosting provider may help accelerate takedown. Continuous monitoring of the IP address 186.2.175.109 for additional malicious activity is recommended, as well as periodic re‑scans on VirusTotal and other multi‑engine scanners to detect any evolution of the payload. Organizations that employ URL filtering should verify that their solutions block the domain across all categories, and incident response teams should be prepared to investigate any credential or payment data that may be exfiltrated if end users interact with the site.