moneyfast[.]top
“Moneyfast: Most Popular Online Crypto Casino Based on Blockchain”
moneyfast.top — Контент недоступен. Олицетворение бренда: Genericcrypto; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 11/95 (Criminal IP, alphaMountain.ai, BitDefender, CyRadar, ESET); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 95/100. Регистратор: Web Commerce Communica….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain moneyfast.top was registered on August 28, 2025 through Web Commerce Communications Limited and was taken offline before the report date of July 24, 2026. Analysis shows the site resolved to IP address 69.5.189.57, which belongs to ASN 42624 (Global-Data System IT Corporation) and is geolocated in Switzerland. The domain is listed on one external security blocklist and is specifically blocked by the PhishDestroy service, indicating that it was recognized as malicious by at least one industry‑operated filter. A Gridinsoft trust score of 0 out of 100 further confirms the poor reputation of the host.
No SSL certificate was observed, meaning the site operated over plain HTTP, a common characteristic of low‑effort phishing or scam deployments. The page title retrieved from the site—"Moneyfast: Most Popular Online Crypto Casino Based on Blockchain"—suggests the campaign was positioned as a crypto‑focused gambling platform, and forensic inspection linked the hosting files to the publicly available "Gambler Scam" phishing kit. VirusTotal analysis recorded 11 of 95 scanned security vendors flagging the domain as malicious, providing independent vendor corroboration of its threat status. The nameserver configuration consists of four generic nameserverhub.com entries, which is typical for domains that are quickly provisioned for malicious campaigns.
While the site is currently offline, its infrastructure—particularly the Swiss‑based IP range and the lack of TLS—remains a potential vector for future re‑use. Defenders should continue to block the domain and its associated IP address, monitor the AS42624 range for similar activity, and add the domain to internal blocklists. Ongoing observation of the nameserver set and any re‑registration attempts is advised, as threat actors frequently recycle compromised hosting resources for new campaigns.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание