moonpaylogiin[.]my[.]canva[.]site
“MOONPAY: LOGIN”
moonpaylogiin.my.canva.site — 内容不可用. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 10/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 80/100. 注册商: Gandi SAS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis indicates that the domain moonpaylogiin.my.canva.site is currently offline, returning HTTP 404 for the sole observed endpoint. DNS resolution points to 103.169.142.6, an address owned by Cloudflare (AS209242, London, UK) with the IP geolocated to Australia. The domain is served through Cloudflare's infrastructure, leveraging HTTP/3, and is protected by an SSL certificate issued by Google Trust Services under the WE1 brand. Nameserver delegation uses jean.ns.cloudflare.com and junade.ns.cloudflare.com.
Registration data shows the domain was created on 3 April 2018 through Gandi SAS. The page title captured during the brief observation was "MOONPAY: LOGIN", aligning with a credential-phishing campaign that impersonates the Moonpay service. VirusTotal scans reported ten of ninety-five security vendors flagging the domain as malicious. The domain appears on a single public blocklist and has been actively blocked by PhishDestroy.
The threat is classified as generic phishing with an elevated risk rating. Defenders should add the domain and its resolving IP to blocklists, enforce URL filtering for the observed host, and monitor related Cloudflare name-servers for additional malicious siblings. Continuous re-inspection of the domain is advised in case the site is re-hosted, and any credential-theft attempts targeting Moonpay users should be treated as confirmed. Until further evidence emerges, the available indicators provide sufficient justification for preventive controls.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
Registration: canva.site
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain canva.site behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。