polymarket[.]special[.]markets
“ERR_NGROK_3200 - The endpoint polymarket.special.markets is offline.”
polymarket.special.markets — No verificado. Resumen de las pruebas: VirusTotal 12/95 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); PhishDestroy score 88/100. Registrador: Cloudflare.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis conducted on July 25, 2026 identifies polymarket.special.markets as a phishing endpoint that was recently taken offline. Infrastructure analysis reveals the domain was hosted behind Cloudflare (AS13335) and resolved to the IPv6 address 2606:4700:3037::6815:59f0, geolocated in the United States. The domain was registered through Cloudflare, Inc., and no nameservers were detected at the time of assessment, indicated by the NS_NOT_FOUND status. The SSL certificate was issued by Google Trust Services under the WE1 intermediate, a common configuration for Cloudflare-proxied domains.
The endpoint returned an HTTP 404 status with the page title ERR_NGROK_3200 - The endpoint polymarket.special.markets is offline, suggesting prior use of ngrok tunneling for hosting, though the exact phishing payload or targeted brand remains unconfirmed. Detection data shows the domain appeared on one security blocklist, specifically PhishDestroy, and was flagged by 12 of 95 security vendors on VirusTotal, indicating moderate detection coverage. Technologies detected include Cloudflare and HTTP/3, consistent with modern phishing infrastructure designed to evade IP-based blocking. Defenders should treat this domain as part of a broader phishing campaign leveraging Cloudflare’s CDN and ngrok for temporary hosting.
The absence of nameservers and the offline status suggest the campaign may have been short-lived or disrupted. Network administrators are advised to block the resolved IPv6 address and monitor for related domains registered through Cloudflare with similar naming patterns. Further investigation into the ngrok tunnel logs, if accessible, could reveal additional compromised endpoints or campaign infrastructure. The domain’s current offline status limits deeper forensic analysis, but the available indicators align with known phishing tactics observed in 2026.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: special.markets
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain special.markets behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
“I am writing to report a confirmed wallet compromise that resulted in the theft of funds from my Polymarket-connected wallet. The attacker drained my USDC balance via a malicious phishing site mimicking your platform. ### Incident Details: - Phishing Site Used: https://polymarket.special.markets (Note: I mistakenly attempted to log in multiple times, believing it was official.) - Compromised Wallet Address (please blacklist):`0x4F46459146b7Bf7572eC82235136399a0c906687` - Theft Tran”
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.