moonshot-listing-ivb.netlify.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonshot-listing-ivb.netlify.app
This website appears to be a cryptocurrency-themed voting page branded as “Vote to List — Powered by Moonshot.” Based on the page title, on-screen text, and layout, it presents a token listing vote for a project called “nunu” on the Solana ecosystem, with prompts encouraging users to vote and connect a wallet. The page also references Moonshot XP and suggests that positive votes could influence whether a token is reviewed or listed within an app ecosystem.
The domain is hosted on a Netlify subdomain rather than a dedicated branded domain, which may indicate a temporary campaign page, a prototype, or an unofficial deployment. While the branding suggests an association with “Moonshot,” the available scan data does not independently confirm who operates this specific subdomain or whether it is officially connected to any legitimate crypto platform. The overall category is most consistent with a cryptocurrency-related web page.
Safety Assessment for moonshot-listing-ivb.netlify.app
Multiple security signals raise concern about this domain at the time of the scan. It was categorized by several web-classification providers as phishing or fraud-related, and 15 out of 91 security engines flagged it, with most detections describing phishing activity. Although the page visually presents itself as a crypto voting interface rather than a malware delivery page, phishing pages often rely on convincing branding and wallet-connection prompts rather than downloadable malicious files.
The malware scan itself did not identify flagged files, and major content-focused threat databases listed in the scan were largely clean at the time checked. However, the domain's IP address was listed on one mail-reputation blocklist, which is a weaker signal than direct phishing detections but still worth noting. In this case, the stronger concern comes from the multi-engine phishing consensus and the page’s wallet-interaction theme.
Given the combination of repeated phishing classifications, lack of established traffic ranking, and a crypto-themed interface that may solicit wallet interaction, this website may pose potential risks to visitors at the time of this scan.
Technical Description
The site is served over HTTPS with a valid TLS certificate issued by DigiCert, expiring in March 2027. It is hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany, and resolves to IP address 35.157.26.135. The page appears to use a modern JavaScript frontend structure, including Next.js-style static asset paths under /_next/static/.
DNSSEC is unsigned, which is common but means DNS responses do not benefit from DNSSEC validation. No malicious files or flagged external links were identified in the page scan, and no iframes were present. Even so, valid TLS and mainstream hosting should not be treated as proof of legitimacy, since phishing pages may also use reputable cloud platforms and properly configured certificates.
Share your experience with this website. Was it safe? Did you encounter any issues?