darkfail[.]io
Analyse phishing et sécurité de darkfail.io
“DarkFail: What darknet markets are online? ✅”
darkfail.io — Dernier actif connu (HTTP 200). Résumé des preuves: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Bureau d’enregistrement: Eranet International.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
This domain, darkfail.io, is flagged as a generic phishing site designed to impersonate legitimate darknet market tracking services. Analysis indicates the site mimics the branding and functionality of DarkFail, a known resource for verifying the operational status of darknet markets. The phishing infrastructure appears tailored to harvest user credentials, payment details, or other sensitive information under the guise of providing market status updates. No evidence of a drainer kit was observed, but the site’s deceptive design and targeted impersonation elevate its risk profile. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 104.21.45.108 and was registered on May 15, 2026, suggesting a recently deployed phishing campaign. VirusTotal detection rates show 3 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is associated with a Google Trust Services SSL certificate, which may lend a false sense of legitimacy. The page title, 'DarkFail: What darknet markets are online? ✅,' directly mirrors the branding of the legitimate service, increasing the likelihood of successful deception. Currently, darkfail.io is offline, having been taken down following detection by threat intelligence systems. Despite its inactive status, residual risk remains due to the potential for re-deployment under a similar domain or infrastructure. Users who interacted with the site prior to takedown may still be at risk of credential compromise or financial fraud. Actionable guidance includes monitoring for unauthorized account access, revoking any credentials entered on the site, and verifying the authenticity of darknet market resources through trusted, verified channels. The domain’s creation date and rapid inclusion in threat intelligence pulses suggest a coordinated phishing operation, warranting continued vigilance.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of darkfail.io · checked Jun 26, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.