sso--moonpay-login---m--auth[.]mystrikingly[.]co
“mystrikingly.co”
sso--moonpay-login---m--auth.mystrikingly.co — 콘텐츠를 사용할 수 없음. 사기 유형: Credential Phishing. 증거 요약: VirusTotal 6/91 (ChainPatrol, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 9 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. 등록기관: Spaceship.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, sso--moonpay-login---m--auth.mystrikingly.co, is flagged as an active credential phishing site targeting users through a subdomain hosted on Mystrikingly. Registered on July 13, 2025, via Spaceship, Inc., the domain remains operational as of July 21, 2026, resolving to IP address 103.224.182.244. Infrastructure analysis reveals nameservers linked to AboveDomains (581.ns1.abovedomains.com, 581.ns2.abovedomains.com, ns1.abovedomains.com, ns2.abovedomains.com), a provider frequently associated with low-reputation or abusive domains. The domain appears on one security blocklist, specifically PhishDestroy, and is detected by 3 of 95 security vendors on VirusTotal, indicating confirmed malicious activity. The subdomain structure (sso--moonpay-login---m--auth) suggests an attempt to mimic a single sign-on (SSO) or authentication portal, likely targeting users of MoonPay or a related cryptocurrency service. However, the exact content and brand impersonation have not been fully analyzed, and no additional kit or vendor details are available. The domain’s registration age (over one year) and persistence on hosting infrastructure further support its classification as a high-risk threat. Defenders should prioritize blocking this domain at the DNS and network level, particularly in environments where cryptocurrency-related authentication portals are in use. Monitoring for similar subdomain patterns (e.g., sso--[brand]--login) on Mystrikingly or other free hosting platforms may help identify related campaigns. No SSL or HTTP status anomalies were reported, but the domain’s continued activity warrants immediate action to mitigate credential theft risks.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
| DNS4EU | sso--moonpay-login---m--auth.mystrikingly.co |
malicious | Sinkholed |
| DigiCert UltraDNS | obseu.northwavepoint.com |
malicious | Sinkholed |
| Cloudflare DNS | realtimesearchresults.com |
malicious | Sinkholed |
| DNS4EU | realtimesearchresults.com |
malicious | Sinkholed |
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| DNS4EU | ww38.sso--moonpay-login---m--auth.mystrikingly.co |
malicious | Sinkholed |
| DNS4EU | d.delivery.consentmanager.net |
malicious | Sinkholed |
| DigiCert UltraDNS | euob.northwavepoint.com |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
증거 및 외부 보고서
PD-20260721-BB5137 Recipient: abuse@trellian.com 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.