Перейти до звіту про безпеку
Checked 09.08.2026 Ref 8364386C

MALICIOUS — CRITICAL

darkfail[.]io

This domain, darkfail.io, is flagged as a generic phishing site designed to impersonate legitimate darknet market tracking services.

76/100 evidence score · Critical
VirusTotal
4/91
Blocklists
No stored match
Доступність
Останній відомий активний · HTTP 200
Report / Add Evidence Appeal this listing
2026-06-15 04:37 UTCОстанній відомий активний · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 4. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Jump to section
Огляд звіту

darkfail.io — Останній відомий активний (HTTP 200). Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Реєстратор: Eranet International.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Evidence Analysis

Ref 8364386C

This domain, darkfail.io, is flagged as a generic phishing site designed to impersonate legitimate darknet market tracking services. Analysis indicates the site mimics the branding and functionality of DarkFail, a known resource for verifying the operational status of darknet markets. The phishing infrastructure appears tailored to harvest user credentials, payment details, or other sensitive information under the guise of providing market status updates. No evidence of a drainer kit was observed, but the site’s deceptive design and targeted impersonation elevate its risk profile. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 104.21.45.108 and was registered on May 15, 2026, suggesting a recently deployed phishing campaign. VirusTotal detection rates show 3 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is associated with a Google Trust Services SSL certificate, which may lend a false sense of legitimacy. The page title, 'DarkFail: What darknet markets are online? ✅,' directly mirrors the branding of the legitimate service, increasing the likelihood of successful deception. Currently, darkfail.io is offline, having been taken down following detection by threat intelligence systems. Despite its inactive status, residual risk remains due to the potential for re-deployment under a similar domain or infrastructure. Users who interacted with the site prior to takedown may still be at risk of credential compromise or financial fraud. Actionable guidance includes monitoring for unauthorized account access, revoking any credentials entered on the site, and verifying the authenticity of darknet market resources through trusted, verified channels. The domain’s creation date and rapid inclusion in threat intelligence pulses suggest a coordinated phishing operation, warranting continued vigilance.

VirusTotal
VirusTotal
4 det.
OTX references
Сертифікат TLS
Google Trust Services
Вік
3 mo New
Зафіксований статус
Останній відомий активний 200
PhishDestroy
DestroyList
У списку
Обсяг даних12 recorded checks
VirusTotal 4 / 91 URLQuery не перевірено PhishStats не перевірено OTX 1 community reference CF Radar scan completed URLScan capture not submitted URLScan verdict висновок недоступний Блокування DNS не перевірено TLS valid certificate, 71d WHOIS 3 mo old Знімок екрана зовнішній знімок Ланцюжок перенаправлень не досліджено

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
10/12

Статус у публічних блоклистах

Збережений знімок

Аналітика доменів

Домен
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутація Edge-IP не пов’язана з цим доменом.
Реєстратор Eranet International
IP-адреса 104.21.45.108 CDN
ГеолокаціяCA Toronto, CA
МережаAS13335 · Cloudflare, Inc.
Зворотний пошук IPviewdns.info → rapiddns.io →
Початкова IP-адреса прихована за проксі CDN. Результати зворотного IP для крайової адреси містять непов’язаних орендарів; для пошуку джерела потрібен пасивний DNS або дані прозорості сертифіката.
РеєстраціяСтворено 15.05.2026 (85d · New)
Статус HTTP200
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено15.06.2026
Сервери іменnovalee.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 09.04.2026scanned 17.05.2026
Favicon Hash
Заголовок сторінки
DarkFail: What darknet markets are online? ✅
Сертифікат TLS
Valid transport encryption · Виданий Google Trust Services · valid for 71 days
Технології · 3 identified
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com 100% впевненості
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% впевненості
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

4 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed First positive detection Previous stored snapshot: 3 detections
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar
Аналіз продуктивності сайту

Google PageSpeed Insights — mobile performance audit of darkfail.io · checked Jun 26, 2026

100
Good
Performance
FCP
1.51s
First Contentful Paint
LCP
1.51s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
16ms
Total Blocking Time
SI
1.51s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно
Вбудувати цей звітRead-only HTML widget
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/darkfail.io"
  title="PhishDestroy threat report for darkfail.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>