# PhishDestroy threat dossier — fortressfinancialgp.com ================================================================ Fetched: 2026-07-24 20:18:53 UTC Canonical: https://phishdestroy.io/domain/fortressfinancialgp.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 93/100 (PhishDestroy scoring — see methodology below) Scam classification: Generic Phishing ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: Netcraft, SOCRadar Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 194.36.191.196 (NL, Naaldwijk) ASN: ASAS60117 HS Host Sailor Ltd, AE Hosting org: AS60117 Host Sailor Ltd Registrar: TuringSign Inc. d/b/a Cosmotown Nameservers: ns5.nl.hostsailor.com, ns6.nl.hostsailor.com Registered: 2026-02-16 Expires: 2027-02-16 Page title: Home - Fortress Financial Group HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR1 Expires: 2026-09-16 Status: INVALID chain Fingerprint: 81f743a418ed6b7a074790146d663bb3d68a964d3f7910ed5152ea37840c8a52 Subject Alternative Names (related infrastructure — often same operator): - www.acct.fortressfinancialgp.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-02-16 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-19 02:20:55 UTC (by PhishDestroy tracker) First reported: 2026-06-19 00:28:47 UTC (abuse notice filed) Last verified: 2026-07-24 20:20:30 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019edd40-124d-761f-ab91-faeb7244f332/ URLQuery: https://urlquery.net/report/13838745-3bf4-4c34-94dc-c72c1bbb9a52 Wayback Machine: https://web.archive.org/web/*/fortressfinancialgp.com crt.sh CT logs: https://crt.sh/?q=%25.fortressfinancialgp.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=fortressfinancialgp.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/fortressfinancialgp.com URLhaus: https://urlhaus.abuse.ch/host/fortressfinancialgp.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-12 17:48:24 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] fortressfinancialgp.com: Confirmed Credential Harvesting This domain, fortressfinancialgp.com, is actively flagged as a high-risk credential harvesting phishing site targeting financial services. Analysis indicates the domain was registered on February 16, 2026, through a registrar known for low oversight, TuringSign Inc. d/b/a Cosmotown. The site resolves to IP address 194.36.191.196, hosted on AS60117 by Host Sailor Ltd in the Netherlands, an infrastructure provider frequently associated with malicious activity. Nameservers ns5.nl.hostsailor.com and ns6.nl.hostsailor.com further link the domain to this hosting environment, which has been previously observed in phishing campaigns. The domain presents a page titled 'Home - Fortress Financial Group,' mimicking a legitimate financial institution to deceive users into submitting sensitive credentials. While the site uses a Let's Encrypt SSL certificate (YR1), this is a common tactic among threat actors to create a false sense of security. The domain appears on one security blocklist and is flagged by two out of ninety-five vendors on VirusTotal, indicating early but growing detection. The Gridinsoft trust score of 0/100 reinforces the assessment of malicious intent. Defenders should treat this domain as an active threat. The infrastructure, including the IP and nameservers, has been previously linked to phishing operations, and the recent registration date aligns with common phishing lifecycle patterns. The site remains accessible with an HTTP 200 status, confirming its operational status. Organizations are advised to block the domain and its associated IP at the network level, monitor for internal connections to this infrastructure, and alert users to the fraudulent nature of the site. Given the domain's use of a financial brand impersonation, priority should be given to protecting users with access to financial systems or sensitive data. [Updates since narrative was generated:] - VirusTotal detections: now 2/91 (narrative was written when count was lower) ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260619-A38EE5 Favicon MD5: edb90bbd247bd051897bafe986b37e2a TLS cert SHA-256: 81f743a418ed6b7a074790146d663bb3d68a964d3f7910ed5152ea37840c8a52 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/fortressfinancialgp.com/ JSON API: https://api.destroy.tools/v1/check?domain=fortressfinancialgp.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 189,348 domains (58,574 alive under monitoring, 129,192 confirmed takedowns/dead). Site: https://phishdestroy.io