Security Scan Report: moonskyo.run

Redirected to:
https://www.noticeofpleadings.net/lumma/domainseizurenotice.htm
Submitted: Sep 13, 2026, 2:47:39 PMCompleted: Sep 13, 2026, 2:48:09 PMpubliccompleted

Summary

This website contacted 3 IPs in 1 country across 2 domains to perform 1 HTTP transaction. The main domain is noticeofpleadings.net and was registered 1 year 5 months ago.

Submitted URL: https://moonskyo.run

Effective URL: https://www.noticeofpleadings.net/lumma/domainseizurenotice.htmRedirected

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Redirects to a fake Microsoft seizure notice served from infrastructure linked to a Lumma Stealer command-and-control domain; IDS and threat-intel both confirm malware C2.

Risk Factors
Critical IDS alerts classify the serving domain as a Win32/Lumma Stealer command-and-control node
Content-malware Indicators of Compromise (lummac2) on the primary domain, multi-feed corroborated
Microsoft-branded seizure notice presented on a non-Microsoft domain (brand impersonation)
Entry domain has no Cisco Umbrella ranking despite being an 8-year-old registration, consistent with repurposed infrastructure
Domain age information unavailable

Details

Page Title

This website domain has been seized by Microsoft

Scan Type

public

Language

🇺🇸

English

(56% confidence)

Category

technology software

(71%)

Domain Information

Within the .run top-level domain, 'moonskyo.run' is registered with no subdomain. The core label 'moonskyo' covers 8 characters containing 3 vowels alongside five consonants. Splitting it apart reveals two words: moons, kyo. Expect four characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://moonskyo.run

Page Load Overview

9.45s
Total Load Time
12
HTTP Requests
2
Domains
2.7 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:56%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:56%
Script Type:Latin
Text Length:1,000 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software71% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
71%
corporate business
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
440.91.108.115Azure · CLOUDUnited States
AS8075Microsoft Corporation
4150.171.110.49Azure · CLOUDUnited States
AS8075Microsoft Corporation
4150.171.110.54Azure · CLOUDUnited States
AS8075Microsoft Corporation
123--

Page Statistics

12
Requests
2
Unique Domains
2.7 MB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CFA17601E5D5762BB04284C056273FA53BC84107C36E89A4B5E563AD1FC7CD6C6B3798

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:qewe5LfAnARZab+1wJDkev3oa5Zwj3yAWuo6OXpryDv8UV3m:qeBtfPRd6wa5XI8UV2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4766:AMAABIFgBiABCeAICjAgEIAWAlIIQBAgAAAAACAKIYIgAEEgggwgQDBAgAJcIKJBAmBAAEIQgACAAQwCwQRAYgLIgRBgQAPg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e700ff0fffffffff
Perceptual Hash:b33266e6b2b3a2c4
Difference Hash:0c22313900080008
Wavelet Hash:e7000000ffffff81
Color Hash:#612d86

Scan History

Scan history not available

Unable to load historical scan data