moremarket[.]ng
“Market Place » MOREMARKET”
moremarket.ng — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 92/100. 注册商: AfeesHost.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
moremarket.ng is currently listed as an active high‑risk generic‑phishing site. The landing page returns HTTP 200 and presents the title “Market Place » MOREMARKET”, indicating an attempt to mimic a legitimate marketplace. The site employs a Let’s Encrypt certificate (R12), which provides encrypted transport but does not authenticate the underlying business purpose. The domain is registered through AfeesHost Ltd and is served by the nameservers dns3.afeeshost.com, dns1.afeeshost.ltd, and dns2.afeeshost.ltd. Network analysis shows the domain resolves to 148.72.153.160, an address hosted in the United States and associated with the velia.net provider. The same IP has been observed in other phishing campaigns, and the host appears on a single security blocklist. PhishDestroy has already blocked the domain, confirming its malicious intent. The use of standard hosting and a publicly trusted TLS certificate is consistent with tactics that aim to increase credibility among victims. VirusTotal scans report that 14 of 95 security vendors flag the domain as malicious, reinforcing the suspicion of phishing activity. No evidence of additional payloads or malware distribution has been observed; the primary threat vector is credential harvesting via a counterfeit marketplace interface. The site’s status remains active as of the reporting date, and its page content has not changed since detection. Defenders should add 148.72.153.160 and the domain name to network deny lists and monitor DNS queries for the associated nameservers. Email gateways should be configured to reject or quarantine messages that reference the domain or the “Market Place » MOREMARKET” title. Continuous threat‑intel feeds should be consulted for any future re‑hosting attempts, and incident response teams should be prepared to investigate credential compromise reports linked to this domain.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/9c/common.js |
audit | Hunting_JS_WebAssembly |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。