moonshot-voting-fu[.]netlify[.]app
“Moonshot – Vote your token to get listed!”
moonshot-voting-fu.netlify.app — Контент недоступен (HTTP 404). Олицетворение бренда: Moonshot; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 1/91 (Forcepoint ThreatSeeker); URLScan malicious verdict; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 83/100. Регистратор: Netlify.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis conducted on 7 August 2026 indicates that the host moonshot-voting-fu.netlify.app is currently active and associated with a high‑risk generic phishing campaign. The domain is hosted on Netlify’s infrastructure, as indicated by the registrar information, and resolves to the IPv4 address 35.157.26.135, which belongs to Netlify’s shared hosting pool. The domain appears on three independent security blocklists; it is explicitly blocked by the PhishDestroy, MetaMask, and SEAL blocklist providers. This multi‑vendor presence suggests that the site has been observed delivering malicious content or phishing pages. VirusTotal scanning recorded a single detection out of ninety‑one submitted security engines, confirming at least one vendor’s classification of the domain as malicious.
No DNS NS records were returned, as indicated by the “NS_NOT_FOUND” flag, which may reflect a misconfiguration or intentional obfuscation of name‑server information. The available evidence does not include a retrieved page title, SSL certificate details, HTTP response codes, or any content‑level analysis, leaving the exact phishing vector undefined. The lack of additional telemetry such as URL paths or payload samples limits the ability to attribute a specific campaign or to map the full attack surface. Nevertheless, the convergence of blocklist listings, the Netlify hosting context, and the single VirusTotal flag constitute sufficient indicators for defensive operators to treat the domain as malicious.
Defenders are advised to immediately block outbound connections to 35.157.26.135 and to add moonshot-voting-fu.netlify.app to local allow‑list exclusions. Email gateways, web proxies, and endpoint security solutions should enforce the blocklists that already flag this domain. Continuous monitoring of Netlify‑hosted subdomains for similar patterns is recommended, as the provider’s shared infrastructure can be leveraged for rapid redeployment of phishing sites.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of moonshot-voting-fu.netlify.app · checked Aug 7, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание