MALICIOUS — CRITICAL
fortbox[.]fun
PhishDestroy identifies fortbox.fun as an active, elevated-risk phishing domain posing as a legitimate service to harvest user credentials.
- VirusTotal
- 1 detections
- Blocklists
- No stored match
- Disponibilità
- Ammantato · raggiungibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fortbox.fun — Ammantato · raggiungibile (HTTP 502). Simulazione del marchio: Fortnite; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 1 detections (engine total unavailable) (ESET); URLScan malicious verdict; cloaking observed; PhishDestroy score 71/100. Registrar: Global Domain Group.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
fortbox.fun – Fake Login Phishing Alert: Immediate Caution
fortbox.fun is a deceptive login phishing site that steals credentials. Flagged by 1 of 95 VirusTotal vendors, users should avoid entering any details.
PhishDestroy identifies fortbox.fun as an active, elevated-risk phishing domain posing as a legitimate service to harvest user credentials. This domain represents a clear credential theft threat, with adversaries leveraging social engineering to trick victims into submitting sensitive login information. The site’s immediate availability and the presence of a valid SSL certificate issued by Let’s Encrypt may further lend it an air of legitimacy at first glance—heightening the risk of successful deception. This domain was flagged by 1 out of 95 VirusTotal security vendors. It resolves to IP address 104.21.80.226 and was registered through Global Domain Group LLC on April 28, 2026. While the domain currently sits at low detection coverage, its active status and hosting configuration suggest ongoing operations. The use of Let’s Encrypt for SSL suggests the threat actors are prioritizing perceived trust, likely to bypass browser warnings and increase engagement. Given the recency of domain registration and the lack of broad blocklisting, this phishing campaign may be in an early or targeted phase. To mitigate risk, users must avoid interacting with fortbox.fun entirely. Organizations should block the domain at DNS and firewall levels, and inspect outbound traffic for connections to 104.21.80.226. Security teams are advised to monitor for related TLS certificate issuance patterns using Let’s Encrypt logs and to warn users about spoofed login prompts. Proactive user awareness training on identifying phishing lures is strongly recommended to reduce the likelihood of credential compromise through this or similar campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 4 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
PD-20260512-813DC2 Recipient: registry@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.