# PhishDestroy threat dossier — torzonmarketofficial.com ================================================================ Fetched: 2026-04-19 11:51:23 UTC Canonical: https://phishdestroy.io/domain/torzonmarketofficial.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 75/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/94 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Gridinsoft ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 Registrar: NameCheap, Inc. Nameservers: ["ben.ns.cloudflare.com", "savanna.ns.cloudflare.com"] Registered: 2026-04-17 Page title: Torzon Market | Official Onion Links & Mirrors HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-06-14 Status: INVALID chain Fingerprint: ba8e1dec685fb77393a8dae0c0c682a62c84fd258e87b48806ef9a8e0444090e ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-17 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-17 07:04:09 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-17 04:05:38 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-04-19 14:45:51 UTC Current status: ACTIVE / observable Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019d999a-fed0-76a2-8cb1-1e5dd0424317/ URLQuery: https://urlquery.net/report/3610a93e-60ab-4ca8-9012-634a2f874444 Wayback Machine: https://web.archive.org/web/*/torzonmarketofficial.com crt.sh CT logs: https://crt.sh/?q=%25.torzonmarketofficial.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=torzonmarketofficial.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/torzonmarketofficial.com URLhaus: https://urlhaus.abuse.ch/host/torzonmarketofficial.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-17 07:05:09 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies torzonmarketofficial.com as an active credential theft domain impersonating the legitimate Torzon Market platform. This site is currently under investigation but remains operationally active, posing immediate risk to users seeking cryptocurrency-related services. The domain leverages brand impersonation to harvest credentials and sensitive financial data under the guise of a legitimate marketplace. This domain exhibits multiple red flags consistent with active malicious infrastructure. VirusTotal currently reports 0/95 detections, indicating no current antivirus or security vendor flagging despite clear malicious intent. Registered through NAMECHEAP INC on March 16, 2026, the domain resolves to IP 188.114.96.3 and utilizes a Let's Encrypt SSL certificate, which attackers commonly exploit to appear legitimate. The domain's recent creation date—just days ago—suggests a rapidly deployed campaign designed to evade historical detection mechanisms. Analysis shows no current presence on major blocklists or threat intelligence platforms, increasing the likelihood of successful user compromise before defensive measures can be updated. Users should immediately block torzonmarketofficial.com at DNS and network levels to prevent access. Organizations should update firewall rules to block IP 188.114.96.3 and inspect proxy logs for recent connections to the domain. Users who may have entered credentials should rotate all related passwords immediately and enable multi-factor authentication on the actual Torzon Market platform. Report any suspicious login attempts or unauthorized transactions to Torzon Market’s official support channels. Exercise extreme caution with any unsolicited links referencing Torzon Market, especially those arriving via email or social media. [Updates since narrative was generated:] - VirusTotal detections: now 2/94 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260417-9A5337 Favicon MD5: 9dc4d8cd865959b09f28dddfaae23d5f TLS cert SHA-256: ba8e1dec685fb77393a8dae0c0c682a62c84fd258e87b48806ef9a8e0444090e ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/torzonmarketofficial.com/ JSON API: https://api.destroy.tools/v1/check?domain=torzonmarketofficial.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io