moonshots-pump[.]net
Проверка домена moonshots-pump.net на фишинг и безопасность
“Vote to List — Powered by Moonshot”
moonshots-pump.net — Контент недоступен (HTTP 502). Олицетворение бренда: Celer; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 9/93 (alphaMountain.ai, CRDF, CyRadar, Ermes, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 95/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of moonshots-pump.net shows a newly registered infrastructure that aligns with a cryptocurrency‑focused impersonation campaign targeting the celer brand. The domain was created on February 21, 2026 and is hosted behind Cloudflare’s AS13335 network, resolving to IP address 172.67.166.174. Both authoritative nameservers, dean.ns.cloudflare.com and priscilla.ns.cloudflare.com, are Cloudflare‑provided, indicating the operator is leveraging a reputable CDN to mask origin. No TLS certificate is presented, leaving HTTP connections unencrypted, a common trait in fast‑deployed scam sites.
The registrar listed as NiceNIC International Group Co., Limited does not provide any protective services, and the Gridinsoft trust score of 0 out of 100 reflects an extremely low reputation. Multiple threat‑intelligence sources have flagged the domain: PhishDestroy, MetaMask, ScamSniffer, and SEAL have blocked it, and VirusTotal reports nine of ninety‑three scanners flagging the host as malicious. The domain appears on four independent blocklists, reinforcing the consensus that it is associated with malicious activity. The observed page title, “Vote to List — Powered by Moonshot,” does not directly reference the celer brand, and no further page content has been captured, leaving the exact visual luring technique unknown.
Given the confirmed impersonation of celer, the crypto‑scam classification, and the convergence of detection signals, defenders should treat moonshots-pump.net as high‑risk. Recommended actions include adding the domain and its resolving IP to outbound and inbound blocklists, updating URL filtering policies, monitoring for derivative domains registered with similar patterns, and ensuring that any internal references to celer‑related services are protected by strict domain whitelisting.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:08:11 UTC
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
PD-20260120-DDC0C6 Recipient: abuse@nicenic.net Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание