checkfort[.]info
“MrBeast x Fortnite - Exclusive Event”
Сводка доказательств
Analysis indicates that the domain checkfort.info was registered on March 13, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently delegated to the Cloudflare authoritative nameservers harlan.ns.cloudflare.com and yolanda.ns.cloudflare.com. DNS resolution points to the IP address 172.67.219.206, which belongs to Cloudflare’s edge network and therefore masks the underlying hosting infrastructure. The domain is listed on one external security blocklist and is actively blocked by the PhishDestroy service, confirming that it is being treated as malicious by at least one reputable anti‑phishing repository. A VirusTotal scan shows that 15 out of 95 participating security vendors have flagged the domain as malicious, providing independent corroboration of its threat status.
The risk rating assigned by internal monitoring is high, and the operational status remains active as of the report date, July 22, 2026. No public page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts are available in the current intelligence set, leaving the exact content of the hosted page unverified. Likewise, no indicators from Open Threat Exchange or additional blocklists have been observed.
Given the combination of recent registration, Cloudflare‑based hosting, multiple vendor detections, and inclusion on a phishing‑specific blocklist, defenders should treat checkfort.info as a confirmed phishing infrastructure. Recommended actions include immediate DNS‑level blocking, updating intrusion‑prevention signatures to flag any outbound connections to the IP 172.67.219.206 when associated with the domain, and monitoring for newly created domains that share the same registrar or nameserver pair. Continuous re‑evaluation is advised in case further evidence, such as page content or SSL fingerprints, becomes available.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260722-C26B1C
Полный текст доказательств
Policy Violations: Explicit policy to immediately suspend domains used for phishing, 419 scams, identity fraud, malware distribution without prior notice
Applicable Laws: IT Act 2000 §§66C–66D (identity theft, cheating by personation), Indian Penal Code §420 / Bharatiya Nyaya Sanhita §318 (fraud)
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 4 технологии с высокой уверенностью
Анализ VirusTotal
Архивные доказательства
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание