Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
moonshot-vote[.]click
“Moonshot vote - All Chains”
Сводка доказательств
Analysis of the domain moonshot-vote.click indicates it was registered on February 21, 2026, through Tucows Domains Inc. and is currently offline. Infrastructure review shows the domain resolved to IP 172.67.209.169, hosted on Cloudflare (AS13335), with nameservers carmelo.ns.cloudflare.com and gail.ns.cloudflare.com. The SSL certificate is issued by Google Trust Services (WE1). At the time of assessment, the HTTP status returned a 403 Forbidden error, and the page title was 'Moonshot vote - All Chains,' suggesting an attempt to impersonate the Moonshot brand, likely targeting cryptocurrency users.
Six of 95 security vendors on VirusTotal flagged this domain as malicious, and it appears on one security blocklist, specifically PhishDestroy. The domain is classified as a crypto scam, though no further details about the specific mechanics of the scam (e.g., token drainer, fake airdrop, governance fraud) are available in the provided data. The use of Cloudflare is consistent with phishing infrastructure, as it can obscure hosting origins and complicate takedown efforts. Defenders should treat this domain as elevated risk due to its brand impersonation, detection by multiple security vendors, and classification as a crypto scam.
While the domain is currently offline, historical DNS and WHOIS records should be preserved for further investigation. If this domain resurfaces, defenders should prioritize blocking it at the DNS or network level and monitor for related infrastructure (e.g., similar domains, shared IPs, or reused SSL certificates). Given the targeting of Moonshot, users of the platform should be alerted to potential scams leveraging this or similar domains. No additional evidence links or payload samples are available at this time.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260120-8A151F- Заголовок сохранённой страницы
- Moonshot vote - All Chains
- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Acceptable Use Policy (AUP): The domain moonshot-vote.click is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities and fraud.
Terms of Service (TOS): The use of this domain for deceptive practices constitutes a violation of your TOS, which reserves the right to suspend or terminate services for such infractions.
Applicable Laws (KN):
Computer Misuse Act, 2013: This law criminalizes unauthorized access to computer systems and data, which is relevant given the phishing nature of the domain.
Electronic Transactions Act, 2015: This act includes provisions against fraudulent electronic communications, applicable to the phishing schemes associated with this domain.
Regulatory Note: Non-compliance with your AUP and TOS, as well as local laws, may expose your organization to legal liabilities and regulatory scrutiny. Immediate action is recommended to mitigate these risks.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | moonshot-vote.click |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Недоступен → Доступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлена 1 технология с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание