moonshot-voting-vul[.]netlify[.]app
“Vote to List — Powered by Moonshot”
moonshot-voting-vul.netlify.app — Conteúdo indisponível. Representação da marca: Moonshot; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 2/91 (ESET, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: Netlify.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
moonshot-voting-vul.netlify.app has been flagged as an active phishing site designed to mimic legitimate voting portals and trick users into surrendering sensitive credentials. The domain leverages Netlify’s infrastructure to appear credible while hosting a spoofed interface that closely resembles a real voting platform. Initial telemetry indicates redirection to external data collection endpoints, suggesting a coordinated attempt to harvest login details and personal information under the guise of an official voting process. Given its current active status and lack of detection coverage, this domain poses a tangible risk to users who may believe they are interacting with a legitimate election-related service.
This domain was identified through automated monitoring and flagged for hosting a fake voting portal. PhishDestroy’s analysis reveals that it resolves to IP address 35.157.26.135 and is currently served via Netlify’s hosting platform. VirusTotal currently reports 0 detections out of 95 engines, indicating it remains undetected by most antivirus and security vendors. The domain remains active and has not yet been listed on major threat intelligence blocklists or reputation databases. Given its recent creation and active deployment, there is a high likelihood of continued operation until flagged by security researchers or automated systems.
To mitigate exposure to this threat, users should immediately block moonshot-voting-vul.netlify.app at the network and endpoint levels. Organizations are advised to update firewall rules and DNS blocklists to include the domain and its resolving IP (35.157.26.135). Security teams should also deploy content filtering rules to prevent access to Netlify-hosted subdomains that mimic official services. Employees and the public should be alerted through security awareness training to recognize suspicious domain patterns and avoid entering credentials on non-official voting websites. In the event of suspected interaction, users must reset passwords immediately and monitor accounts for signs of credential stuffing or unauthorized access.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo