# m.fortuneprimeglobalxins.pro — SUSPICIOUS > PhishDestroy warns: m.fortuneprimeglobalxins.pro is a live crypto-drainer impersonating Fortune Prime Global. ## Summary PhishDestroy has identified m.fortuneprimeglobalxins.pro as a recently activated crypto-drainer posing as Fortune Prime Global. This malicious domain is designed to trick cryptocurrency users into connecting their wallets, which can result in the unauthorized transfer of digital assets to attacker-controlled addresses. The site leverages social engineering tactics, such as mimicking the branding and user interface of legitimate financial platforms, to deceive visitors into authorizing fraudulent transactions. Users who visit this domain risk losing funds stored in connected wallets, as the crypto-drainer silently exfiltrates private keys and transaction approvals without explicit consent. This domain was flagged by PhishDestroy’s automated pipeline after analysis revealed a 0/95 detection rate on VirusTotal as of the latest scan. The domain resolves to IP address 172.67.141.143 and is protected by a Let’s Encrypt SSL certificate, which may give it an air of legitimacy while concealing its malicious intent. The domain uses a mobile-first subdomain (m.) to target users accessing the site from smartphones, where security warnings may be overlooked or dismissed. Additionally, the domain is registered under a privacy-protected registrar, further obscuring the true ownership and location of the threat actor. If you have visited m.fortuneprimeglobalxins.pro or interacted with it in any way, immediately disconnect your wallet from the site and revoke any unauthorized permissions through your wallet’s interface. Do not authorize any further transactions or enter sensitive information. Scan your device for malware using a reputable antivirus tool, as crypto-drainers often bundle additional payloads like keyloggers or trojans. Report the domain to PhishDestroy and your wallet provider to help prevent further attacks. Always verify the authenticity of financial websites by checking the domain spelling, SSL certificate details, and using trusted bookmarks or official app links. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registrar: REGISTRAR_NOT_FOUND - IP: 172.67.141.143 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/60d2fa38-bfdb-4b9b-92e7-47f1f9603380 - PhishDestroy: https://phishdestroy.io/domain/m.fortuneprimeglobalxins.pro/ - LLM endpoint: https://phishdestroy.io/domain/m.fortuneprimeglobalxins.pro/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/m.fortuneprimeglobalxins.pro/ Last updated: 2026-03-23