# PhishDestroy threat dossier — fortnestwealth.com ================================================================ Fetched: 2026-07-29 14:02:53 UTC Canonical: https://phishdestroy.io/domain/fortnestwealth.com/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 72/100 (PhishDestroy scoring — see methodology below) Scam classification: Credential Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Chong Lua Dao, CRDF, Gridinsoft, Netcraft, SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: Dynadot Inc Nameservers: dahlia.ns.cloudflare.com, jerome.ns.cloudflare.com Registered: 2026-01-09 Expires: 2027-01-09 Page title: fortnestwealth.com HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE1 Expires: 2026-10-12 Status: INVALID chain Fingerprint: 87e54ea21cd4575fb7d901d9043405985a1b08910a628f6ce64e84cc760dfee0 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-01-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:54:36 UTC (by PhishDestroy tracker) First reported: 2026-07-27 06:34:15 UTC (abuse notice filed) Last verified: 2026-07-29 12:20:31 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa1fb-ee95-7149-a891-9ca59ab7acf6/ URLQuery: https://urlquery.net/report/e59888cd-1448-42b1-9f85-7cbf272ae687 Wayback Machine: https://web.archive.org/web/*/fortnestwealth.com crt.sh CT logs: https://crt.sh/?q=%25.fortnestwealth.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=fortnestwealth.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/fortnestwealth.com URLhaus: https://urlhaus.abuse.ch/host/fortnestwealth.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:56:29 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] FortnestWealth.com Credential Harvesting Campaign Analysis indicates that the domain fortnestwealth.com was registered on January 09 2026 through Dynadot Inc. The domain is currently delegated to the Cloudflare nameservers dahlia.ns.cloudflare.com and jerome.ns.cloudflare.com and resolves to the IP address 188.114.97.3, which is part of Cloudflare’s edge network. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy service, confirming that threat‑intel feeds have identified it as malicious. VirusTotal records show the domain was scanned by 91 AV vendors; none reported a detection at the time of scanning, but the absence of detections does not constitute a safety indication. The infrastructure analysis reveals no additional hosting or ASN information beyond the Cloudflare edge IP, and no SSL certificate details, page title, or HTTP response codes have been published in the current intelligence set. Consequently, the precise content served by the site remains unknown, but the classification as a generic phishing operation suggests that the domain is being used to harvest login credentials or personal data. Defenders should consider adding the domain to DNS‑based blocklists, monitoring outbound connections to the IP 188.114.97.3, and applying URL filtering rules that flag any traffic to the domain. Ongoing observation is recommended to capture any changes in hosting, page content, or detection status, and to update defensive controls accordingly. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-274BF8 Favicon MD5: 90b3e00625ef0a249a256a90b1ec2ead TLS cert SHA-256: 87e54ea21cd4575fb7d901d9043405985a1b08910a628f6ce64e84cc760dfee0 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/fortnestwealth.com/ JSON API: https://api.destroy.tools/v1/check?domain=fortnestwealth.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,478 domains (83,245 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io