moonshot-listing-9z2.netlify.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonshot-listing-9z2.netlify.app
This domain appears to host a cryptocurrency-themed landing page branded as “Vote to List — Powered by Moonshot.” Based on the page title, on-screen text, and imagery, the site presents a token-voting interface where visitors are encouraged to vote on whether a token called “nunu” should be listed, with references to Solana, wallet connectivity, and reward-style language such as earning XP.
The site is delivered from a Netlify subdomain rather than a standalone branded domain, which may indicate a temporary campaign page, a prototype, or an unofficial deployment. The operator is not clearly identified in the provided scan data beyond the visible “Moonshot” branding, so ownership and affiliation cannot be independently confirmed from this scan alone.
Safety Assessment for moonshot-listing-9z2.netlify.app
Multiple security signals raise concern around this domain at the time of the scan. It was flagged by 13 out of 91 security engines, and several web-classification sources categorized it as phishing or fraud-related. In addition, one phishing-focused threat database listed the domain, and the domain's IP address appears on one mail-reputation blocklist. While a heuristic malware scan did not report confirmed malicious files, its generic suspicious-object findings on page assets do not offset the broader phishing-related detections.
The page content also shows patterns commonly associated with crypto-targeted social engineering, including a token-listing vote flow, wallet-related participation language, and incentive-style messaging. The use of a hosted subdomain rather than a clearly established primary brand domain may further increase uncertainty about authenticity. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry extending to 2027-03-19. It is hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany, and resolves to IP address 63.176.8.218. The page appears to use a modern JavaScript framework build, with multiple static assets served from _next paths.
DNSSEC is not enabled for the domain, which is common but means DNS responses do not benefit from that additional integrity layer. From a technical standpoint, the certificate and hosting setup appear standard for a cloud-hosted web app, but those factors alone should not be treated as proof of legitimacy when phishing-related detections are present.
Share your experience with this website. Was it safe? Did you encounter any issues?