fncheck[.]lol
“Fortnite Inventory Checker | Epic Games”
fncheck.lol — Conteúdo indisponível. Representação da marca: Epicgames; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 95/100. Registrador: NameSilo.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies fncheck.lol as a high-risk domain actively impersonating Epic Games' Fortnite brand to deceive users into revealing personal information or cryptocurrency credentials. This threat falls under the category of brand impersonation phishing, where attackers create fraudulent websites mimicking legitimate gaming platforms to exploit players' trust. The domain displays a page title and interface designed to mimic Epic Games' official services, specifically targeting Fortnite players searching for inventory-checking tools. Research shows this deception is effective due to the popularity of Fortnite and the demand for third-party tools that offer additional gameplay insights or item tracking. Users who interact with this site may unknowingly expose their account credentials or fall victim to crypto wallet draining attacks, where attackers trick users into connecting their wallets to fraudulent smart contracts.
Evidence supporting the classification of fncheck.lol as a malicious domain includes its recent creation on April 05, 2026, which is highly indicative of a short-lived campaign designed to avoid prolonged scrutiny. The domain is registered through NameSilo, LLC, a registrar commonly associated with both legitimate and malicious domain registrations. The IP address 104.21.81.59, associated with this domain, hosts multiple suspicious endpoints and has been linked to other flagged phishing campaigns. VirusTotal analysis reveals that 9 out of 95 security vendors have flagged this domain as malicious, emphasizing its high-risk status. The presence of a Let's Encrypt SSL certificate does not validate the site's legitimacy, as threat actors frequently exploit free certificates to enhance the appearance of authenticity while hosting malicious content. Additionally, the domain continues to resolve and remain active in the threat landscape, indicating ongoing operations.
Users who have visited fncheck.lol should immediately cease all interactions with the site and avoid entering any personal information, account credentials, or cryptocurrency wallet details. If credentials were entered, change passwords immediately and enable two-factor authentication on all associated accounts. For those who connected cryptocurrency wallets, revoke any unauthorized permissions through the wallet provider's settings and transfer remaining funds to a secure wallet if suspicious transactions are detected. Report this domain to your antivirus provider and consider using a dedicated tool like PhishDestroy to check other suspected domains. Avoid downloading any files or software from this site, as it may contain malware or additional payloads. Stay vigilant by cross-referencing URLs with official Epic Games communication channels to verify legitimacy before interacting with any gaming-related tools or services.
Inteligência de segurança de rede Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | fncheck.lol |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 4 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-20260421-AEFB09 Recipient: abuse@namesilo.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo