# PhishDestroy threat dossier — prime-market-darknet.click ================================================================ Fetched: 2026-06-21 04:38:29 UTC Canonical: https://phishdestroy.io/domain/prime-market-darknet.click/ ## VERDICT ---------------------------------------------------------------- ACTIVE + CLOAKED — returns HTTP 666 to scanners, real fraudulent site to victims Composite threat score: 75/100 (PhishDestroy scoring — see methodology below) Cloaking: DETECTED — domain returns custom HTTP 666 to scanners while serving fraudulent content to real users (type: content_divergence) (score: 3/6) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/92 security vendors flagged this domain AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 45.147.197.100 Registrar: Dynadot, LLC Nameservers: ["ns1.zomro.net", "ns2.zomro.ru", "ns3.zomro.com", "ns4.zomro.su"] Registered: 2026-05-15 Expires: 2027-03-10 Page title: Prime Market Link 2026 Official – Marketplace ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-08-30 Status: INVALID chain Fingerprint: 751bc0f204283cae374f508db98bbd35f5011594db50b14d14091baf52e5602a ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-15 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-15 23:30:10 UTC (by PhishDestroy tracker) First reported: 2026-06-15 06:35:01 UTC (abuse notice filed) Last verified: 2026-06-21 04:20:34 UTC Neutralised: 2026-05-16 05:03:01 UTC Current status: ACTIVE — cloaked behind HTTP 666 to evade scanners ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-13 13:34:00 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies prime-market-darknet.click as a dangerous phishing site designed to steal login credentials from users of darknet market platforms. The domain mimics the appearance of legitimate market login pages, tricking visitors into entering their usernames and passwords. Once submitted, this sensitive information is captured by malicious actors, who can then use it to access the victims' accounts on real marketplaces, potentially leading to financial loss or further compromise. The site is still active and poses an ongoing threat to anyone who might encounter it through links in forums, emails, or search results. This conclusion is based on concrete technical evidence. The domain was registered through Dynadot, LLC, a known registrar often used by threat actors. VirusTotal analysis shows 0 out of 95 security vendors currently detect this domain as malicious, meaning it has not yet been widely blacklisted—although the threat assessment is under investigation. The domain resolves to IP address 45.147.197.100, which may be associated with other phishing operations. The registration date and other WHOIS details are being reviewed, but the combination of domain name, hosting, and appearance strongly indicates a phishing campaign targeting darknet market users. If you have visited prime-market-darknet.click and entered any credentials, take immediate action. Change the passwords for any accounts that may have been compromised, especially on darknet markets or any other site where you used the same login details. Enable two-factor authentication wherever possible. Run a full antivirus scan on your device to check for any malware. Monitor your financial accounts for unauthorized transactions. Report the domain to relevant authorities or security platforms. Finally, consider using a password manager to generate and store unique passwords for each site, reducing the risk from future phishing attempts. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 241f19664969a743229c71a0b9a8269d TLS cert SHA-256: 751bc0f204283cae374f508db98bbd35f5011594db50b14d14091baf52e5602a ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/prime-market-darknet.click/ JSON API: https://api.destroy.tools/v1/check?domain=prime-market-darknet.click Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 167,157 domains (15,993 alive under monitoring, 150,846 confirmed takedowns/dead). Site: https://phishdestroy.io