MALICIOUS — CRITICAL
dark-torzon[.]net
PhishDestroy identifies dark-torzon.net as a phishing site specifically targeting users of the Torzon Market darknet marketplace.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
dark-torzon.net — آخر نشاط معروف (HTTP 200). نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 80/100. مسجّل النطاق: NameCheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
PhishDestroy identifies dark-torzon.net as a phishing site specifically targeting users of the Torzon Market darknet marketplace. The domain masquerades as an official source for verified links, aiming to harvest login credentials, cryptocurrency wallet information, or other sensitive data from visitors. By imitating a known dark market, this threat exploits the trust of users seeking secure access to illicit services, potentially leading to financial theft or account compromise.
Technical analysis reveals that dark-torzon.net was created on May 22, 2026, through NameCheap, Inc., a common registrar for malicious domains. The site resolves to IP address 188.114.97.3 and holds an SSL certificate issued by Google Trust Services, lending a false sense of legitimacy. VirusTotal detection shows 1 out of 95 security vendors flagging the domain as malicious, while AlienVault OTX includes it in one threat intelligence pulse. The domain also appears on one security blocklist. Currently, the site is offline, likely taken down after being reported.
If you visited dark-torzon.net, assume any data entered is compromised. Immediately change passwords for any accounts used on the site, especially your Torzon Market credentials and crypto wallets. Run a full antivirus scan on your device and monitor financial accounts for unauthorized activity. Avoid reusing passwords and enable two-factor authentication where possible. Stay vigilant against similar phishing attempts referencing dark markets.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.