torzon[.]blog
“Torzon Market Blog | Secure Onion Links 2026-02-23 13:20:31”
Сводка доказательств
Analysis of torzon.blog shows a newly created domain (registered 23 Feb 2026) hosted on IP 45.147.197.100, which resolves to a server in the Netherlands under ASN 204601 (NovoServe B.V.). The domain was registered through NameSilo, LLC and uses four nameservers (ns1.zomro.net, ns2.zomro.ru, ns3.zomro.com, ns4.zomro.su). No SSL certificate is presented, indicating the site operated without HTTPS. The page title retrieved from the endpoint reads “Torzon Market Blog | Secure Onion Links 2026-02-23 13:20:31”, suggesting a focus on onion‑linked content but providing no further functional detail.
Threat intelligence classifies the site as a credential‑phishing operation; it has been blocked by PhishDestroy and currently appears on a single security blocklist. VirusTotal reports that the domain was scanned by 93 vendors, none of which flagged it at the time of scanning, though this absence of detections does not constitute a safety assurance. The domain’s status is listed as offline, and no live HTTP response or content snapshot is available for deeper inspection.
Uncertainty remains regarding the exact phishing payload, target audience, and whether the site ever served malicious login pages. Defenders should continue to monitor the IP address and associated ASN for any reactivation, add the domain to internal blocklists, and consider sinkholing the host if infrastructure reuse is observed. Users should be warned that any credential‑collection attempts originating from torzon.blog are untrusted, and organizations should enforce strict verification of login URLs to mitigate credential theft.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260223-A2C8FC- Заголовок сохранённой страницы
- Torzon Market Blog | Secure Onion Links 2026-02-23 13:20:31
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (US):
18 U.S.C. § 1343 - Wire Fraud
18 U.S.C. § 1030 - Computer Fraud and Abuse Act (CFAA)
15 U.S.C. § 45 - FTC Act (Deceptive Practices)
Federal laws prohibit wire fraud, computer fraud, and deceptive business practices.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание