merchantmoe[.]cc
“Merchant Moe | Leading Decentralized Exchange on Mantle Network”
merchantmoe.cc — Conteúdo indisponível (HTTP 502). Representação da marca: Mantle; Tipo de golpe: Fake Exchange. Resumo das evidências: VirusTotal 1/91 (Gridinsoft); PhishDestroy score 71/100. Registrador: GoDaddy.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, merchantmoe.cc, is actively posing as a decentralized exchange (DEX) on the Mantle Network to deceive cryptocurrency users. Analysis indicates the site is designed to function as a crypto drainer, a type of phishing attack that tricks victims into connecting their wallets, enabling attackers to siphon funds without authorization. The page title, 'Merchant Moe | Leading Decentralized Exchange on Mantle Network,' mimics legitimate platforms to gain trust, while the underlying infrastructure is engineered for malicious financial extraction. Infrastructure analysis reveals several critical red flags. The domain was registered on March 28, 2025, through GoDaddy.com, LLC, a registrar frequently exploited for phishing operations due to its accessibility. It currently resolves to the IP address 186.2.175.35, which has no prior association with legitimate crypto services. Detection metrics further confirm its malicious nature: as of the latest scan, 3 out of 95 security vendors on VirusTotal have flagged merchantmoe.cc, a low but notable detection rate that aligns with newly deployed phishing campaigns before broader recognition. Users who have interacted with merchantmoe.cc should take immediate action to mitigate potential losses. First, disconnect any wallets linked to the site using a trusted blockchain explorer or wallet interface. Next, revoke all smart contract approvals granted to the domain via tools designed for this purpose. Monitor connected wallets for unauthorized transactions and consider transferring remaining assets to a new, secure wallet. Report the domain to relevant platforms, including crypto security trackers and the registrar, to aid in takedown efforts. Vigilance is critical, as phishing sites often reappear under similar domains.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
PD-20260629-4A93D8 Recipient: abuse@iqweb.io Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo