MALICIOUS — CRITICAL
fortbox[.]fun
PhishDestroy identifies fortbox.fun as an active, elevated-risk phishing domain posing as a legitimate service to harvest user credentials.
- VirusTotal
- 1 detections
- Blocklists
- No stored match
- Доступність
- Прикритий · доступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fortbox.fun — Прикритий · доступний (HTTP 502). Уособлення бренду: Fortnite; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 1 detections (engine total unavailable) (ESET); URLScan malicious verdict; cloaking observed; PhishDestroy score 71/100. Реєстратор: Global Domain Group.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies fortbox.fun as an active, elevated-risk phishing domain posing as a legitimate service to harvest user credentials. This domain represents a clear credential theft threat, with adversaries leveraging social engineering to trick victims into submitting sensitive login information. The site’s immediate availability and the presence of a valid SSL certificate issued by Let’s Encrypt may further lend it an air of legitimacy at first glance—heightening the risk of successful deception. This domain was flagged by 1 out of 95 VirusTotal security vendors. It resolves to IP address 104.21.80.226 and was registered through Global Domain Group LLC on April 28, 2026. While the domain currently sits at low detection coverage, its active status and hosting configuration suggest ongoing operations. The use of Let’s Encrypt for SSL suggests the threat actors are prioritizing perceived trust, likely to bypass browser warnings and increase engagement. Given the recency of domain registration and the lack of broad blocklisting, this phishing campaign may be in an early or targeted phase. To mitigate risk, users must avoid interacting with fortbox.fun entirely. Organizations should block the domain at DNS and firewall levels, and inspect outbound traffic for connections to 104.21.80.226. Security teams are advised to monitor for related TLS certificate issuance patterns using Let’s Encrypt logs and to warn users about spoofed login prompts. Proactive user awareness training on identifying phishing lures is strongly recommended to reduce the likelihood of credential compromise through this or similar campaigns.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 4 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260512-813DC2 Recipient: registry@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.