moonshot-voting-6zx[.]netlify[.]app
“Vote to List — Powered by Moonshot”
moonshot-voting-6zx.netlify.app — 内容不可用. 品牌冒充:Moonshot; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 2/91 (ESET, Kaspersky); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 注册商: Netlify.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies moonshot-voting-6zx.netlify.app as an active generic phishing domain impersonating a voting portal. This domain was flagged under investigation with a generic phishing threat type and remains active as of the latest analysis. The infrastructure leverages Netlify's hosting service, a common tactic among threat actors seeking to exploit legitimate cloud platforms for malicious hosting. No known drainer kit or advanced obfuscation techniques have been identified during initial assessments, suggesting a relatively straightforward phishing campaign rather than a sophisticated operation. The domain's naming convention hints at opportunistic targeting, likely aimed at unsuspecting users via phishing emails, social media, or other social engineering vectors. This domain exhibits several concerning technical indicators. VirusTotal currently reports 2 out of 95 detections, indicating it has evaded detection by mainstream security vendors. The domain resolves to IP address 63.176.8.218, a Netlify-hosted infrastructure within the cloud provider's range. The domain was registered through Netlify, a serverless platform provider, which is frequently abused for phishing due to its ease of deployment and low barrier to entry. Google Safe Browsing (GSB) status is not flagged, and no third-party blocklists have been identified as containing this domain. The lack of immediate detections underscores the need for proactive threat hunting and domain monitoring. As of the latest assessment, moonshot-voting-6zx.netlify.app remains active and operational. Immediate response actions should include adding the domain and its resolving IP (63.176.8.218) to organizational blocklists and security controls such as firewalls, DNS filters, and endpoint protection platforms. Users should be warned against interacting with this domain, and any potential victims should be advised to reset credentials if any interaction occurred. The remaining risk is classified as under investigation, pending further behavioral analysis or additional intelligence. Organizations are advised to monitor this domain closely and share telemetry to improve collective defense. The low detection rate on VirusTotal highlights the importance of behavioral analysis and threat intelligence sharing to identify emerging threats before they escalate.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。