MALICIOUS — CRITICAL
fortso[.]com
PhishDestroy identifies fortso.com as an active crypto drainer phishing domain under investigation, flagged for attempting to siphon cryptocurrency from unsuspecting victims.
- VirusTotal
- 18/91
- Blocklists
- No stored match
- उपलब्धता
- सामग्री अनुपलब्ध · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fortso.com — सामग्री अनुपलब्ध (HTTP 502). घोटाले का प्रकार: Crypto Drainer. साक्ष्य सारांश: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 100/100. रजिस्ट्रार: MAT BAO.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
PhishDestroy identifies fortso.com as an active crypto drainer phishing domain under investigation, flagged for attempting to siphon cryptocurrency from unsuspecting victims. The site employs deceptive social engineering tactics to trick users into connecting their wallets or entering private keys, then initiates unauthorized transactions to drain funds. Like many crypto drainers, fortso.com leverages urgency and fake rewards to bypass user skepticism. Technical indicators reveal this domain was only recently registered on December 08, 2025, making it a fresh threat with minimal historical trust. Its SSL certificate issued by Let’s Encrypt provides a false sense of security, while the domain resolves to IP address 186.2.171.13 in Vietnam, hosted by a registrar (MAT BAO CORPORATION) with limited oversight. Notably, fortso.com currently evades detection by all 95 VirusTotal engines, underscoring its stealth and rapid operational deployment.
This domain’s timeline is a critical red flag: zero detections on VirusTotal despite active hosting, a creation date just days ago, and no established reputation. Such metrics are typical of opportunistic crypto drainers that emerge, operate briefly, and disappear before blocklists update. Users interacting with fortso.com risk immediate asset loss if they connect wallets or input seed phrases, as crypto drainers automatically execute unauthorized transfers upon gaining access. The absence of prior reports also suggests this campaign may be part of a broader wave targeting early adopters or specific blockchain communities. Defenders should treat fortso.com as hostile infrastructure until proven otherwise, especially given its reliance on newly minted domains and Let’s Encrypt certs.
If you visited fortso.com or entered any information, act immediately to secure your assets and identity. Disconnect any connected wallets using blockchain explorers or wallet settings, revoke any suspicious approvals via tools like revoke.cash, and transfer remaining funds to a new wallet if compromise is suspected. Report the domain to your antivirus vendor and platforms like PhishTank or URLVoid. Use network-level blocking (e.g., Pi-hole, local hosts file, or firewall rules) to prevent further access. Monitor blockchain transaction logs for unauthorized activity and consider using real-time alerting services for your wallet addresses. Given the crypto drainer threat, assume compromise and act with urgency—crypto losses are often irreversible.
डेटा कवरेज14 recorded checks
सुरक्षा संकेत
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | fortso.com |
malicious | Sinkholed |
| OpenDNS | fortso.com |
phishing | Phishing Block |
| DNS4EU | fortso.com |
malicious | Sinkholed |
| DNS4EU | fortnb.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 4 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% विश्वासExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासDDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of fortso.com · checked Apr 27, 2026
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
PD-20260427-5FCD99 Recipient: abuse@matbao.com Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।