MALICIOUS — CRITICAL
fortlocker[.]one
13 of 91 security engines flagged the domain; the latest stored check returned HTTP 502.
- VirusTotal
- 13/91
- Blocklists
- No stored match
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fortlocker.one — Konten tidak tersedia (HTTP 502). Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100. Registrar: Gname.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Digest
fortlocker.one is classified critical with an evidence score of 89/100. 13 of 91 security engines flagged the domain. Registered 21 May 2026 via Gname.com Pte. Ltd., hosted on 91.227.114.14 (Shereverov Marat Ahmedovich, DE). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)mistral · 25/06/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, fortlocker.one, is flagged as a high-risk generic phishing threat targeting users of secure file storage or cloud locker services. Analysis indicates the infrastructure is designed to deceive victims into entering credentials or downloading malicious payloads under the guise of legitimate file-sharing or encryption platforms. The lack of SSL encryption and the use of a non-standard page title ('Loading') suggest an attempt to evade detection while maintaining operational simplicity. Infrastructure analysis reveals the domain was registered on May 21, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk registrations. It resolves to the IP address 91.227.114.14, which has been linked to other phishing campaigns in recent threat intelligence reports. As of the latest scan, 13 out of 95 security vendors on VirusTotal have flagged the domain as malicious, and it appears on at least one security blocklist. The absence of an SSL certificate further increases the risk of credential interception or man-in-the-middle attacks. The domain remains active, indicating ongoing malicious operations. Mitigation steps should include immediate blocking of the domain and its associated IP (91.227.114.14) at the network perimeter. Organizations should deploy endpoint protection rules to detect and prevent access to unencrypted phishing sites, particularly those impersonating secure storage services. User awareness training should emphasize the risks of entering credentials on sites lacking SSL certificates, especially those with generic or placeholder page titles. Security teams are advised to monitor for related domains registered through Gname.com Pte. Ltd. or resolving to the same IP range, as these may indicate additional phishing infrastructure linked to the same threat actor.
Cakupan data12 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 1 identified
HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of fortlocker.one · checked Jun 3, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.