moonpay-widget-navy[.]vercel[.]app
“Create Next App”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
content_split- Gizleme puanı
- 1/6
Kanıt özeti
This domain, moonpay-widget-navy.vercel.app, is flagged as a high-risk crypto credential theft operation targeting users of a widely recognized cryptocurrency payment gateway. Analysis indicates the threat actor has deployed a credential harvesting interface disguised as a legitimate widget, likely leveraging a Next.js framework given the page title 'Create Next App.' No direct association with a known drainer kit has been confirmed, though the infrastructure aligns with common credential theft tactics observed in recent campaigns impersonating crypto payment processors.
Infrastructure analysis reveals the domain is hosted on IP 64.29.17.195 within Amazon.com, Inc.'s AS16509, a frequent choice for malicious hosting due to its ephemeral nature. The domain was registered through Tucows Domains Inc. on February 21, 2026, though this date may reflect a falsified record or placeholder. VirusTotal detection stands at 2/95 security vendors, while three independent blocklists—PhishDestroy, MetaMask, and SEAL—have already classified the domain as malicious. The SSL certificate, issued by Google Trust Services (WR1), provides minimal legitimacy but does not mitigate the underlying threat. No Google Safe Browsing (GSB) flags were observed at the time of analysis, suggesting either recent deployment or evasion of automated detection systems.
As of the latest assessment, the domain remains active and unresolved, posing an ongoing risk to users who may encounter it through phishing links or compromised platforms. Response actions by security providers have included blocklisting, though the domain's Vercel-based hosting allows for rapid redeployment under new subdomains. Users are advised to verify payment gateway URLs directly through official sources and avoid interacting with unsolicited widget interfaces. Organizations should monitor for this domain in logs and implement real-time blocking of the IP and associated indicators to prevent credential exposure.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 12.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of moonpay-widget-navy.vercel.app · checked Mar 7, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin