lockercheck[.]fit
“Inventory Check | Fortnite”
Сводка доказательств
Analysis of the domain lockercheck.fit confirms its classification as an active credential-theft phishing site. Registered on May 15, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, the domain currently resolves to the IP address 104.21.10.31, which is associated with Cloudflare infrastructure, as indicated by its nameservers aldo.ns.cloudflare.com and nova.ns.cloudflare.com. This configuration is frequently observed in phishing campaigns due to Cloudflare’s provision of anonymity and protection against takedowns. Threat intelligence platforms provide corroborating evidence of malicious activity. As of July 17, 2026, 13 of 91 security vendors on VirusTotal have flagged the domain as malicious, indicating a consensus among detection engines regarding its harmful nature. Additionally, the domain appears in at least one threat intelligence pulse on AlienVault OTX, further supporting its association with phishing operations. The domain’s registration age—just over two months at the time of this report—aligns with typical phishing lifecycle patterns, where domains are often short-lived to evade detection and mitigation efforts. While the specific brand or service being impersonated is not yet confirmed through available metadata, the domain name suggests an attempt to deceive users into believing it is related to secure storage, file verification, or authentication processes, which are common themes in credential-theft schemes. Defenders are advised to treat this domain as high-risk and implement blocking measures at the DNS or network level. Given its active status and association with known phishing infrastructure, organizations should monitor for any connections to 104.21.10.31 or related Cloudflare-hosted endpoints. Further analysis of the site’s content, if accessible, may provide additional context regarding the targeted brand or specific phishing kit in use. However, as of this report, no such details are available.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260717-D8AE2E- Заголовок сохранённой страницы
- Inventory Check | Fortnite
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (FR):
French Penal Code Article 323-1
French Penal Code Article 313-1 (Fraud)
Law for a Digital Republic
French law prohibits fraudulent access to automated data processing systems.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | lockercheck.fit |
malicious | Sinkholed |
| DigiCert UltraDNS | lockercheck.fit |
malicious | Sinkholed |
| OpenDNS | lockercheck.fit |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | lockercheck.fit |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание