moremarket[.]ng
“Market Place » MOREMARKET”
moremarket.ng — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 92/100. Реєстратор: AfeesHost.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
moremarket.ng is currently listed as an active high‑risk generic‑phishing site. The landing page returns HTTP 200 and presents the title “Market Place » MOREMARKET”, indicating an attempt to mimic a legitimate marketplace. The site employs a Let’s Encrypt certificate (R12), which provides encrypted transport but does not authenticate the underlying business purpose. The domain is registered through AfeesHost Ltd and is served by the nameservers dns3.afeeshost.com, dns1.afeeshost.ltd, and dns2.afeeshost.ltd. Network analysis shows the domain resolves to 148.72.153.160, an address hosted in the United States and associated with the velia.net provider. The same IP has been observed in other phishing campaigns, and the host appears on a single security blocklist. PhishDestroy has already blocked the domain, confirming its malicious intent. The use of standard hosting and a publicly trusted TLS certificate is consistent with tactics that aim to increase credibility among victims. VirusTotal scans report that 14 of 95 security vendors flag the domain as malicious, reinforcing the suspicion of phishing activity. No evidence of additional payloads or malware distribution has been observed; the primary threat vector is credential harvesting via a counterfeit marketplace interface. The site’s status remains active as of the reporting date, and its page content has not changed since detection. Defenders should add 148.72.153.160 and the domain name to network deny lists and monitor DNS queries for the associated nameservers. Email gateways should be configured to reject or quarantine messages that reference the domain or the “Market Place » MOREMARKET” title. Continuous threat‑intel feeds should be consulted for any future re‑hosting attempts, and incident response teams should be prepared to investigate credential compromise reports linked to this domain.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/9c/common.js |
audit | Hunting_JS_WebAssembly |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога