fnview.cc
“Inventory Check | Fortnite”
Evidence Summary
This domain, fnview.cc, is identified as a high-risk credential theft operation impersonating the Fortnite gaming platform. The page title, 'Inventory Check | Fortnite,' suggests an attempt to deceive users into submitting account credentials under the guise of verifying in-game inventory or rewards. No direct evidence of a crypto drainer kit was observed, but the infrastructure aligns with credential harvesting tactics commonly deployed in gaming-related phishing campaigns. The domain’s design and branding mimic legitimate Fortnite interfaces to lower user suspicion and increase the likelihood of successful credential capture. Analysis of technical indicators reveals the following: the domain was registered on May 18, 2026, through NameSilo, LLC, and currently resolves to the IP address 85.239.149.81. Security vendors on VirusTotal flagged the domain as malicious, with 19 out of 95 detections. The domain appears on three security blocklists, including PhishDestroy, PhishingArmy, and CERT-PL. Detected technologies include Tailwind CSS, Nginx, and OpenResty, which are often leveraged in phishing infrastructure for rapid deployment and scalability. Gridinsoft assigned a trust score of 0/100, further corroborating the domain’s malicious classification. As of the latest assessment, fnview.cc has been taken offline, likely due to takedown efforts or abandonment by the threat actor. However, the infrastructure may resurface under a different domain or IP address, given the transient nature of phishing campaigns. Users who interacted with this domain are advised to reset their Fortnite account credentials immediately and enable multi-factor authentication. Organizations should monitor for similar domains registered through NameSilo or resolving to 85.239.149.81, as these may indicate related threat actor activity. The remaining risk persists due to the potential for credential reuse across platforms and the likelihood of future campaigns targeting the same user base.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 26, 2026 · 05:17 UTCVirusTotal scanner detections updated from 16 to 19. Added scanner alerts: ADMINUSLabs, BitDefender, CRDF, Chong Lua Dao, Cluster25, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, PREBYTES, SOCRadar, Seclookup, Sophos, VIPRE, Webroot, alphaMountain.ai.
Threat Response Pipeline
Public Blocklist Status
Technologies · 3 identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of fnview.cc · checked Jun 26, 2026
Community reports
Reported by 1 community member, first seen May 19, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
PD-20260519-F37000 Recipient: abuse@dedik.io Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive