moonpay-widget-navy[.]vercel[.]app
“Create Next App”
Збережене виявлення
Виявлено маскування
- Тип маскування
content_split- Оцінка маскування
- 1/6
Зведення доказів
This domain, moonpay-widget-navy.vercel.app, is flagged as a high-risk crypto credential theft operation targeting users of a widely recognized cryptocurrency payment gateway. Analysis indicates the threat actor has deployed a credential harvesting interface disguised as a legitimate widget, likely leveraging a Next.js framework given the page title 'Create Next App.' No direct association with a known drainer kit has been confirmed, though the infrastructure aligns with common credential theft tactics observed in recent campaigns impersonating crypto payment processors.
Infrastructure analysis reveals the domain is hosted on IP 64.29.17.195 within Amazon.com, Inc.'s AS16509, a frequent choice for malicious hosting due to its ephemeral nature. The domain was registered through Tucows Domains Inc. on February 21, 2026, though this date may reflect a falsified record or placeholder. VirusTotal detection stands at 2/95 security vendors, while three independent blocklists—PhishDestroy, MetaMask, and SEAL—have already classified the domain as malicious. The SSL certificate, issued by Google Trust Services (WR1), provides minimal legitimacy but does not mitigate the underlying threat. No Google Safe Browsing (GSB) flags were observed at the time of analysis, suggesting either recent deployment or evasion of automated detection systems.
As of the latest assessment, the domain remains active and unresolved, posing an ongoing risk to users who may encounter it through phishing links or compromised platforms. Response actions by security providers have included blocklisting, though the domain's Vercel-based hosting allows for rapid redeployment under new subdomains. Users are advised to verify payment gateway URLs directly through official sources and avoid interacting with unsolicited widget interfaces. Organizations should monitor for this domain in logs and implement real-time blocking of the IP and associated indicators to prevent credential exposure.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of moonpay-widget-navy.vercel.app · checked Mar 7, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога