dark-matter-market-link[.]cc
“Dark Matter Market Link | Official 2026”
dark-matter-market-link.cc — No verificado. Tipo de estafa: Generic Phishing. Resumen de las pruebas: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 83/100. Registrador: NameSilo.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain dark-matter-market-link.cc was registered on May 09, 2026 through NameSilo, LLC and remains active. It resolves to the IPv4 address 45.147.197.100, which is allocated to a hosting provider in the Netherlands (Podaon SIA). The site returns HTTP status code 200 and presents a TLS certificate issued by Let’s Encrypt (R13). Infrastructure analysis shows the domain is served by four nameservers – ns1.zomro.net, ns2.zomro.ru, ns3.zomro.com, and ns4.zomro.su – a pattern commonly observed in malicious hosting clusters. The Gridinsoft trust score of 0 out of 100 further indicates a lack of reputation. VirusTotal records two detections out of ninety‑five scanners, and the domain is listed on a single public blocklist, which has already been incorporated into the PhishDestroy feed. AlienVault OTX contains one pulse referencing this indicator. Content inspection reveals the page title “Dark Matter Market Link | Official 2026”, matching the typical branding of the legitimate Dark Matter Market platform. The classification as a cloned_site phishing campaign suggests the page is intended to mimic the official market’s login or transaction interface in order to harvest credentials or financial information. The high risk rating aligns with the use of a freshly registered domain, a low‑trust score, and active hosting of a fraudulent front‑end. Defenders should immediately add 45.147.197.100 and dark-matter-market-link.cc to web‑filter blocklists and ensure that any outbound connections to the domain are denied. Continuous monitoring of DNS queries for the four zomro nameservers can reveal additional domains that share the same hosting infrastructure. Where possible, sinkholing the IP address or redirecting traffic to a safe landing page can disrupt the phishing campaign. Incident response teams should also correlate user reports of credential‑theft attempts with this indicator and advise affected users to reset passwords and review account activity.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Análisis de VirusTotal
Análisis de la configuración del sitio
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.