moonshot-listing-ken.netlify.app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of moonshot-listing-ken.netlify.app
This domain appears to host a cryptocurrency-themed landing page branded as “Vote to List — Powered by Moonshot.” Based on the page title, on-screen text, and screenshot, it presents a token voting interface for a Solana-based asset called “nunu,” showing vote totals, a contract snippet, and prompts such as “Vote to list” and “Not now.” The page suggests that users may connect a wallet or participate in a listing-related decision tied to a crypto platform or token promotion workflow.
The site is served from a Netlify subdomain rather than a standalone branded domain, which may indicate a quickly deployed campaign page, promotional microsite, or temporary app front end. The branding references “Moonshot,” but the scanned domain itself is not an obvious primary corporate domain for that name. Based on the available categories and scan context, the page appears to fall within the cryptocurrency sector, while also showing characteristics commonly associated with phishing or fraudulent crypto lures.
Safety Assessment for moonshot-listing-ken.netlify.app
Multiple independent security signals raise concern about this domain at the time of the scan. It was flagged by 14 out of 91 security engines, and several web-classification providers categorized it as phishing or fraud-related. In addition, one phishing-focused threat database listed the domain, which is a stronger warning sign than a generic heuristic alone. Although the malware scan did not report infected files, it did attach a generic suspicious label to the domain and linked assets, which may reflect unusual page behavior rather than confirmed malware delivery.
There are also contextual risk factors. The page is hosted on a free hosting subdomain and presents a crypto voting flow that may encourage wallet interaction, a pattern often seen in credential-harvesting or wallet-drain campaigns. The domain's IP address is also listed on one mail-reputation blocklist; that signal is weaker than phishing detections and may relate to shared infrastructure, but it still adds a small amount of caution. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry shown in 2027. It is hosted on Netlify infrastructure backed by AWS EC2 in Frankfurt, Germany, and resolves to IP address 63.176.8.218. The page appears to be built with a modern JavaScript framework, as indicated by multiple _next/static asset paths.
From a domain-configuration perspective, the registration is relatively old for a hosted subdomain context, but DNSSEC is unsigned. No direct evidence of malicious file payloads was reported in the file scan, yet the broader reputation data is unfavorable, and the use of a hosted app subdomain for a crypto-branded voting page may increase abuse potential.
Share your experience with this website. Was it safe? Did you encounter any issues?