moonbirds-nft-al4[.]pages[.]dev
“Suspected phishing site | Cloudflare”
moonbirds-nft-al4.pages.dev — Контент недоступен. Олицетворение бренда: Genericcloudflare; Тип мошенничества: Nft Scam. Сводка доказательств: VirusTotal 12/93 (ChainPatrol, alphaMountain.ai, BitDefender, CyRadar, Fortinet); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 86/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain moonbirds-nft-al4.pages.dev was registered on February 21 2026 through Cloudflare, Inc. and is hosted on Cloudflare’s network (AS13335) with the IP address 172.66.47.65 located in the United States. DNS resolution uses the Cloudflare‑provided nameservers rustam.ns.cloudflare.com and bingo.ns.cloudflare.com. The site presents an HTTPS certificate issued by Google Trust Services under the WE1 root, and the HTTP response currently returns a 403 status code. Automated scans detect the presence of HSTS and HTTP/3, confirming modern Cloudflare edge settings.
Multiple security services have flagged the domain: three independent blocklists list it, and it is explicitly blocked by PhishDestroy, MetaMask, and SEAL. Google Safe Browsing classifies the URL as a social‑engineering threat, and VirusTotal reports that 12 of 93 scanners label it malicious. The page title returned by the server is “Suspected phishing site | Cloudflare,” matching the classification of an NFT‑related scam. Gridinsoft assigns a trust score of 0 / 100, indicating a complete lack of confidence in the host.
The domain is currently taken offline, which limits direct observation of any payload or credential‑ harvesting mechanisms. Because the underlying content cannot be retrieved, the exact method of crypto draining—whether through malicious smart‑contract interaction, wallet‑address substitution, or other techniques—remains unverified. Defenders should continue to block the domain at DNS and proxy layers, add it to internal threat‑intel feeds, and monitor for any resurgence using the same IP or Cloudflare‑owned nameservers. Ongoing vigilance is advised for any future subdomains that may reuse the same infrastructure, given the low trust score and the confirmed presence on multiple reputable blocklists.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of moonbirds-nft-al4.pages.dev · checked Apr 21, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание