fortskin[.]club
“Fortnite Wealth Leaderboard | Epic Games”
fortskin.club — Conteúdo indisponível. Representação da marca: Epic Games; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Registrador: Global Domain Group.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, fortskin.club, is a phishing site designed to steal user credentials by impersonating the official Fortnite Wealth Leaderboard. The site presents a fraudulent login interface under the guise of Epic Games, tricking users into entering their account details. Once submitted, these credentials are harvested by threat actors for unauthorized access, account takeovers, or further malicious activities such as financial fraud or identity theft. The site specifically targets Fortnite players, leveraging the popularity of the game to increase the likelihood of successful phishing attempts. Analysis indicates that fortskin.club was registered on June 07, 2026, through Global Domain Group LLC, a registrar often associated with domains used in phishing campaigns. The domain is flagged by 18 out of 95 security vendors on VirusTotal, a clear indicator of its malicious nature. It resolves to the IP address 104.21.41.95, which has been linked to other suspicious domains. Additionally, the site appears on one security blocklist and was previously blocked by PhishDestroy, further confirming its classification as a phishing threat. The page title, 'Fortnite Wealth Leaderboard | Epic Games,' is crafted to mimic legitimate Epic Games content, enhancing its deceptive appearance. If you or someone else visited fortskin.club and entered login credentials, immediate action is required to mitigate potential damage. First, change the password for the affected Fortnite or Epic Games account, as well as any other accounts where the same credentials may have been reused. Enable multi-factor authentication (MFA) on all accounts to add an extra layer of security. Monitor the account for any unauthorized transactions, in-game purchases, or changes to account settings. If financial information was entered, contact the relevant financial institution to report potential fraud and request a review of recent transactions. Finally, scan the device used to access the site with up-to-date antivirus software to detect and remove any malware that may have been installed during the visit.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 5 identified
Mautic is a free and open-source marketing automation tool for Content Management, Social Media, Email Marketing, and can be used for the integration of social networks, campaign management, forms, questionnaires, reports, etc.
www.mautic.org 100% de confiançaCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-20260607-73BFDA Recipient: abuse@globaldomaingroup.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo