moonshot-voting-6zx[.]netlify[.]app
“Vote to List — Powered by Moonshot”
moonshot-voting-6zx.netlify.app — İçerik kullanılamıyor. Marka kimliğine bürünme: Moonshot; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 2/91 (ESET, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Kayıt kuruluşu: Netlify.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies moonshot-voting-6zx.netlify.app as an active generic phishing domain impersonating a voting portal. This domain was flagged under investigation with a generic phishing threat type and remains active as of the latest analysis. The infrastructure leverages Netlify's hosting service, a common tactic among threat actors seeking to exploit legitimate cloud platforms for malicious hosting. No known drainer kit or advanced obfuscation techniques have been identified during initial assessments, suggesting a relatively straightforward phishing campaign rather than a sophisticated operation. The domain's naming convention hints at opportunistic targeting, likely aimed at unsuspecting users via phishing emails, social media, or other social engineering vectors. This domain exhibits several concerning technical indicators. VirusTotal currently reports 2 out of 95 detections, indicating it has evaded detection by mainstream security vendors. The domain resolves to IP address 63.176.8.218, a Netlify-hosted infrastructure within the cloud provider's range. The domain was registered through Netlify, a serverless platform provider, which is frequently abused for phishing due to its ease of deployment and low barrier to entry. Google Safe Browsing (GSB) status is not flagged, and no third-party blocklists have been identified as containing this domain. The lack of immediate detections underscores the need for proactive threat hunting and domain monitoring. As of the latest assessment, moonshot-voting-6zx.netlify.app remains active and operational. Immediate response actions should include adding the domain and its resolving IP (63.176.8.218) to organizational blocklists and security controls such as firewalls, DNS filters, and endpoint protection platforms. Users should be warned against interacting with this domain, and any potential victims should be advised to reset credentials if any interaction occurred. The remaining risk is classified as under investigation, pending further behavioral analysis or additional intelligence. Organizations are advised to monitor this domain closely and share telemetry to improve collective defense. The low detection rate on VirusTotal highlights the importance of behavioral analysis and threat intelligence sharing to identify emerging threats before they escalate.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com %100 güvenHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenVirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin