moonpaydesktop[.]com
“MoonPay Desktop — Your Passport to Crypto”
已存储的检测结果
内容伪装警报
- 伪装类型
content_split- 伪装评分
- 1/6
证据摘要
PhishDestroy identifies a newly registered domain, moonpaydesktop.com, actively propagating a sophisticated PayPal-themed phishing campaign designed to harvest payment credentials. The site mimics the official MoonPay desktop application interface, tricking users into entering sensitive financial data under the guise of a software update or security verification. Threat actors leverage Let's Encrypt SSL certificates to enhance credibility, while the domain resolves to IP 216.150.1.1—a server linked to previous malicious infrastructure. Early-stage analysis reveals this operation is still under investigation, with no antivirus signatures yet flagging the threat vector.
This domain was flagged through multiple threat intelligence channels, revealing alarming technical indicators. VirusTotal currently shows 0 out of 95 scanning engines detecting the malicious payload, indicating a fresh or stealthily configured threat. Registrant details trace back to NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for hosting transient domains tied to fraudulent activities. The domain itself was created on April 27, 2026—merely days ago—further suggesting an opportunistic campaign leveraging newly minted domains to evade detection. At present, no public blocklists include this domain, amplifying the risk to unsuspecting users.
If you’ve accessed moonpaydesktop.com, immediately cease any input of credentials or financial details. Disconnect from the site and run a full antivirus scan. Monitor accounts linked to any submitted information and consider enabling two-factor authentication where possible. Report the domain to your IT security team or file a complaint with your local cybercrime unit. Avoid re-accessing the domain, as it remains active and may deploy additional malware. Stay vigilant for phishing attempts using similar lures, especially those impersonating payment processors or software updates.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of moonpaydesktop.com · checked May 3, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控