dark-matter-market-link[.]cc
“Dark Matter Market Link | Official 2026”
dark-matter-market-link.cc — Chưa được xác minh. Loại lừa đảo: Generic Phishing. Tóm tắt bằng chứng: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 83/100. Nhà đăng ký: NameSilo.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
The domain dark-matter-market-link.cc was registered on May 09, 2026 through NameSilo, LLC and remains active. It resolves to the IPv4 address 45.147.197.100, which is allocated to a hosting provider in the Netherlands (Podaon SIA). The site returns HTTP status code 200 and presents a TLS certificate issued by Let’s Encrypt (R13). Infrastructure analysis shows the domain is served by four nameservers – ns1.zomro.net, ns2.zomro.ru, ns3.zomro.com, and ns4.zomro.su – a pattern commonly observed in malicious hosting clusters. The Gridinsoft trust score of 0 out of 100 further indicates a lack of reputation. VirusTotal records two detections out of ninety‑five scanners, and the domain is listed on a single public blocklist, which has already been incorporated into the PhishDestroy feed. AlienVault OTX contains one pulse referencing this indicator. Content inspection reveals the page title “Dark Matter Market Link | Official 2026”, matching the typical branding of the legitimate Dark Matter Market platform. The classification as a cloned_site phishing campaign suggests the page is intended to mimic the official market’s login or transaction interface in order to harvest credentials or financial information. The high risk rating aligns with the use of a freshly registered domain, a low‑trust score, and active hosting of a fraudulent front‑end. Defenders should immediately add 45.147.197.100 and dark-matter-market-link.cc to web‑filter blocklists and ensure that any outbound connections to the domain are denied. Continuous monitoring of DNS queries for the four zomro nameservers can reveal additional domains that share the same hosting infrastructure. Where possible, sinkholing the IP address or redirecting traffic to a safe landing page can disrupt the phishing campaign. Incident response teams should also correlate user reports of credential‑theft attempts with this indicator and advise affected users to reset passwords and review account activity.
Tình báo an ninh mạng Registrar context
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
Phân tích của VirusTotal
Phân tích cấu hình trang
Bằng chứng và các báo cáo bên ngoài
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai