moonshot-voting-vul[.]netlify[.]app
“Vote to List — Powered by Moonshot”
moonshot-voting-vul.netlify.app — Контент недоступний. Уособлення бренду: Moonshot; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/91 (ESET, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Реєстратор: Netlify.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
moonshot-voting-vul.netlify.app has been flagged as an active phishing site designed to mimic legitimate voting portals and trick users into surrendering sensitive credentials. The domain leverages Netlify’s infrastructure to appear credible while hosting a spoofed interface that closely resembles a real voting platform. Initial telemetry indicates redirection to external data collection endpoints, suggesting a coordinated attempt to harvest login details and personal information under the guise of an official voting process. Given its current active status and lack of detection coverage, this domain poses a tangible risk to users who may believe they are interacting with a legitimate election-related service.
This domain was identified through automated monitoring and flagged for hosting a fake voting portal. PhishDestroy’s analysis reveals that it resolves to IP address 35.157.26.135 and is currently served via Netlify’s hosting platform. VirusTotal currently reports 0 detections out of 95 engines, indicating it remains undetected by most antivirus and security vendors. The domain remains active and has not yet been listed on major threat intelligence blocklists or reputation databases. Given its recent creation and active deployment, there is a high likelihood of continued operation until flagged by security researchers or automated systems.
To mitigate exposure to this threat, users should immediately block moonshot-voting-vul.netlify.app at the network and endpoint levels. Organizations are advised to update firewall rules and DNS blocklists to include the domain and its resolving IP (35.157.26.135). Security teams should also deploy content filtering rules to prevent access to Netlify-hosted subdomains that mimic official services. Employees and the public should be alerted through security awareness training to recognize suspicious domain patterns and avoid entering credentials on non-official voting websites. In the event of suspected interaction, users must reset passwords immediately and monitor accounts for signs of credential stuffing or unauthorized access.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога