सुरक्षा रिपोर्ट पर जाएँ
Checked 09/08/2026 Ref F8799BCB

MALICIOUS — CRITICAL

fortso[.]com

PhishDestroy identifies fortso.com as an active crypto drainer phishing domain under investigation, flagged for attempting to siphon cryptocurrency from unsuspecting victims.

100/100 evidence score · Critical
VirusTotal
18/91
Blocklists
No stored match
उपलब्धता
सामग्री अनुपलब्ध · HTTP 502
Report / Add Evidence Appeal this listing
2026-04-27 16:38 UTCसामग्री अनुपलब्ध · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 18। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
Jump to section
रिपोर्ट सारांश

fortso.com — सामग्री अनुपलब्ध (HTTP 502). घोटाले का प्रकार: Crypto Drainer. साक्ष्य सारांश: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 100/100. रजिस्ट्रार: MAT BAO.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

Evidence Analysis

Ref F8799BCB

PhishDestroy identifies fortso.com as an active crypto drainer phishing domain under investigation, flagged for attempting to siphon cryptocurrency from unsuspecting victims. The site employs deceptive social engineering tactics to trick users into connecting their wallets or entering private keys, then initiates unauthorized transactions to drain funds. Like many crypto drainers, fortso.com leverages urgency and fake rewards to bypass user skepticism. Technical indicators reveal this domain was only recently registered on December 08, 2025, making it a fresh threat with minimal historical trust. Its SSL certificate issued by Let’s Encrypt provides a false sense of security, while the domain resolves to IP address 186.2.171.13 in Vietnam, hosted by a registrar (MAT BAO CORPORATION) with limited oversight. Notably, fortso.com currently evades detection by all 95 VirusTotal engines, underscoring its stealth and rapid operational deployment.

This domain’s timeline is a critical red flag: zero detections on VirusTotal despite active hosting, a creation date just days ago, and no established reputation. Such metrics are typical of opportunistic crypto drainers that emerge, operate briefly, and disappear before blocklists update. Users interacting with fortso.com risk immediate asset loss if they connect wallets or input seed phrases, as crypto drainers automatically execute unauthorized transfers upon gaining access. The absence of prior reports also suggests this campaign may be part of a broader wave targeting early adopters or specific blockchain communities. Defenders should treat fortso.com as hostile infrastructure until proven otherwise, especially given its reliance on newly minted domains and Let’s Encrypt certs.

If you visited fortso.com or entered any information, act immediately to secure your assets and identity. Disconnect any connected wallets using blockchain explorers or wallet settings, revoke any suspicious approvals via tools like revoke.cash, and transfer remaining funds to a new wallet if compromise is suspected. Report the domain to your antivirus vendor and platforms like PhishTank or URLVoid. Use network-level blocking (e.g., Pi-hole, local hosts file, or firewall rules) to prevent further access. Monitor blockchain transaction logs for unauthorized activity and consider using real-time alerting services for your wallet addresses. Given the crypto drainer threat, assume compromise and act with urgency—crypto losses are often irreversible.

VirusTotal
VirusTotal
18 det.
URLQuery
यूआरएलक्वेरी
4 threat alerts
सीएफ रडार
दुर्भावनापूर्ण
URLScan
यूआरएलस्कैन
Gridinsoft
1/100
ScamAdviser
Scamadviser
1/100
TLS प्रमाणपत्र
Let's Encrypt
आयु
3 mo
देखी गई स्थिति
सामग्री अनुपलब्ध 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज14 recorded checks
VirusTotal 18 / 91 यूआरएलक्वेरी 4 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार provider verdict: malicious URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 12 जाँच पूरी — कोई ब्लॉक नहीं TLS valid certificate, 56d कौन है 3 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई Gridinsoft 1/100 Scamadviser 1/100
सुरक्षा संकेत
GS Gridinsoft Analysis 1 / 100
4 0 2 17 140
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS fortso.com malicious Sinkholed
OpenDNS fortso.com phishing Phishing Block
DNS4EU fortso.com malicious Sinkholed
DNS4EU fortnb.com malicious Sinkholed
CF Cloudflare Radar Verdict दुर्भावनापूर्ण
Security threats Phishing Phishing

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
13/13
Sent Report Recorded
Stored sent-report record for registrar MAT BAO CORPORATION, hosting provider, 2 abuse contacts
abuse@matbao.comabuse@iqweb.io
27/04/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Check the value of your inventory - Fortnite
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 56 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN ddos-guard · AS59692 IQWeb FZ-LLC
IP प्रतिष्ठा abuse score 0/100 0 reports checked 13/07/2026
रजिस्ट्रार MAT BAO VN(VN)
दुरुपयोग संपर्कabuse@matbao.com, abuse@iqweb.io
IP पता 186.2.171.13 BZ
भौगोलिक स्थानBZ Belmopan, BZ
नेटवर्कAS59692 · Iqweb LLC
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 27/04/2026 (103d)
HTTP स्थिति502 Error
पहली अनुपलब्धता तक का समय 17 days
हम क्या मापते हैं पहली संग्रहीत दुरुपयोग रिपोर्ट से लेकर पहली बार अवलोकन तक कि सामग्री अनुपलब्ध थी, बीता हुआ समय। इससे कारण स्थापित नहीं होता.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला27/04/2026
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://fortso.com/
नेमसर्वरns74.cloudns.uk
TLS Fingerprint
TLS Observationvalid from 25/03/2026scanned 27/04/2026
Case ID
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
तकनीकें · 4 identified
Node.js
Programming languages

Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.

nodejs.org 100% विश्वास
Express
Web frameworks Web servers

Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.

expressjs.com 100% विश्वास
HSTS
सुरक्षा

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% विश्वास
DDoS-Guard
सुरक्षा

DDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.

ddos-guard.net 100% विश्वास
Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

18 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
साइरेडार
ईएसईटी
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
नेटक्राफ्ट
Seclookup
सोफोस
VIPRE
वेबरूट
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of fortso.com · checked Apr 27, 2026

52
Needs Work
Performance
FCP
2.86s
First Contentful Paint
LCP
8.15s
Largest Contentful Paint
CLS
0.323
Cumulative Layout Shift
TBT
68ms
Total Blocking Time
SI
4.2s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें
इस रिपोर्ट को एम्बेड करेंRead-only HTML widget
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/fortso.com"
  title="PhishDestroy threat report for fortso.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।