darkmatter-dnm[.]com
Forensic brief
PhishDestroy identifies darkmatter-dnm.com, a recently activated crypto drainer kit posing as a Dark Matter portal. The domain directs victims to a counterfeit interface designed to siphon cryptocurrency assets by tricking users into connecting their wallets and authorizing malicious smart-contract transactions. Behavioral analysis suggests the drainer leverages a custom JavaScript payload to intercept wallet connections and prompt fraudulent signature requests, a common tactic among active crypto-draining operations targeting decentralized finance users. This domain was flagged on April 11, 2026, with a VirusTotal detection score of 0 out of 95 engines at the time of analysis. It resolves to IP address 172.67.213.20 and is registered through Internet Domain Service BS Corp. The domain holds a valid SSL certificate issued by Google Trust Services, which increases credibility to unsuspecting visitors. As of this assessment, the domain remains unlisted on major blocklists, allowing it to operate openly without widespread interruption. The domain is currently active and under active monitoring by PhishDestroy. While the immediate risk is evaluated as under investigation due to the absence of detections, the combination of a newly registered domain, low VT score, and use of a trusted SSL issuer creates a high-risk environment for cryptocurrency users. Users are strongly advised to avoid visiting darkmatter-dnm.com and to verify any Dark Matter-related domains through PhishDestroy’s real-time scanner before engaging with wallet connections. Remaining risk is classified as moderate-to-high pending further intelligence and blocklist inclusion.
Threat response pipeline
Cloudflare Radar
Forensic Evidence Collectionabuse@internet.bs with forensic evidence (metadata, screenshots, PDF).Evidence capture
Domain Intelligence
Internet Domain Service BS Corp
Technical details
Public blocklist status
Technologies
Technologies · 2 identified
VirusTotal consensus
Aggregated detection across 95 security vendors.
Site performance
Site performance analysis
Google PageSpeed Insights — mobile audit of darkmatter-dnm.com
Evidence & external reports
Were you affected by this site?
Were You Affected?
Recommendations & Advice for Victims
- Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
- Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
- Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
- Report to authorities (see section 15 below) — even small reports help build case patterns.
- Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
Report to your local authorities
Email template — registrar abuse
abuse@internet.bs
Registrar: Internet Domain Service BS Corp Case: PD-PD-20260515-8AA7EB
Embed this report
About this report
About this report: darkmatter-dnm.com
This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 1 public blocklists.
The site displays a page titled “Dark Matter Market Link Database & Onion Verification”.
darkmatter-dnm.com has been flagged by 0 security vendors as of May 17, 2026.
If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.