# PhishDestroy threat dossier — dark-matter-market-url.com ================================================================ Fetched: 2026-05-17 15:04:54 UTC Canonical: https://phishdestroy.io/domain/dark-matter-market-url.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 72/100 (PhishDestroy scoring — see methodology below) Scam classification: unknown Targeted brand: darkmatter ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/92 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.145.32 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Web Commerce Communications Limited dba WebNic.cc Nameservers: harvey.ns.cloudflare.com, rita.ns.cloudflare.com Registered: 2026-05-11 Page title: Darkmatter Market - The Secure Darknet Marketplace ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-07-05 Status: INVALID chain Fingerprint: 39ea40e262b0a46f464bdbc642d187f971c2c937ccf54bfeac9f80ced6c24ac9 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-11 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-11 01:37:02 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-05-10 22:37:45 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-05-15 08:06:46 UTC Neutralised: 2026-05-14 20:55:21 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019e1407-840a-71ea-b712-66885a320bb9/ URLQuery: https://urlquery.net/report/f5832bbd-5d47-4bb4-8e81-c04202aed485 Wayback Machine: https://web.archive.org/web/*/dark-matter-market-url.com crt.sh CT logs: https://crt.sh/?q=%25.dark-matter-market-url.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=dark-matter-market-url.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/dark-matter-market-url.com URLhaus: https://urlhaus.abuse.ch/host/dark-matter-market-url.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-11 01:38:04 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain dark-matter-market-url.com has been identified as an active crypto drainer phishing page currently under investigation for fraudulent activities. This threat involves the unauthorized extraction of cryptocurrency assets from victims' wallets, posing significant financial risks. The campaign remains active as of the latest assessment, with further analysis pending to determine the full scope of operations and impacted users. This domain was flagged by 0 of 95 VirusTotal vendors, indicating a low initial detection rate despite clear malicious intent. It was registered through Web Commerce Communications Limited dba WebNic.cc on April 29, 2023, and resolves to IP address 172.67.145.32. The domain operates with an SSL certificate issued by Google Trust Services, which may contribute to a false sense of legitimacy. Current blocklist counts and trust scores remain unverified, suggesting a potentially emerging but unmitigated threat. The lack of early detection underscores the sophistication of this campaign in evading automated security measures. Given the active status and high-risk nature of crypto drainer phishing, immediate action is required to mitigate exposure. Users are advised to avoid interacting with dark-matter-market-url.com and verify any suspicious links through PhishDestroy’s threat intelligence platform. Organizations should implement network-level blocking for the associated IP (172.67.145.32) and domain to prevent further propagation. Proactive monitoring for similar domains registered via WebNic.cc is recommended due to the registrar’s association with multiple malicious campaigns. Continuous updates to blocklists and endpoint security solutions are critical to reducing the risk of financial loss. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260510-3AEBF4 Favicon MD5: 2ff4cc9512ce55fea3206fadf5a30c3d TLS cert SHA-256: 39ea40e262b0a46f464bdbc642d187f971c2c937ccf54bfeac9f80ced6c24ac9 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/dark-matter-market-url.com/ JSON API: https://api.destroy.tools/v1/check?domain=dark-matter-market-url.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 150,665 domains (30,587 alive under monitoring, 119,786 confirmed takedowns/dead). Site: https://phishdestroy.io