MALICIOUS — CRITICAL
fortrx[.]cc
PhishDestroy identifies fortrx.cc as an active crypto drainer phishing domain designed to steal cryptocurrency assets from unsuspecting users.
- VirusTotal
- 21 detections
- Blocklists
- No stored match
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
fortrx.cc — Контент недоступний (HTTP 502). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 21 detections (engine total unavailable) (ADMINUSLabs, Criminal IP, alphaMountain.ai, Chong Lua Dao, Cluster25); URLQuery 5 alerts; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies fortrx.cc as an active crypto drainer phishing domain designed to steal cryptocurrency assets from unsuspecting users. This domain employs deceptive tactics, including spoofed SSL certificates from Let's Encrypt, to appear legitimate while harvesting private keys and wallet credentials. The threat actor leverages social engineering to trick victims into connecting wallets or entering seed phrases, enabling direct fund extraction. No known brand impersonation or specific drainer kit has been publicly documented, but the domain's infrastructure suggests a high degree of sophistication in targeting crypto users.
This domain was flagged by PhishDestroy with an elevated risk level, confirmed by a 21/95 detection score on VirusTotal. It was registered through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to IP 188.114.97.3. The domain was created on May 01, 2026, which is an anomaly given the current date, raising suspicions about its legitimacy. Additionally, the domain has been flagged by Google Safe Browsing (GSB) and is present on multiple blocklists, indicating widespread recognition as a malicious entity.
Fortrx.cc remains an active threat with no confirmed takedown as of the latest assessment. Users are strongly advised to avoid interacting with this domain and to report any suspicious activity immediately. The remaining risk is elevated due to the domain's recent creation, active infrastructure, and partial detection by security vendors. Proactive monitoring and blocking of this domain are critical to prevent financial losses.
Обсяг даних13 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | fortrx.cc |
malicious | Sinkholed |
| OpenDNS | fortrx.cc |
phishing | Phishing Block |
| DNS4EU | fortrx.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | fortrx.cc |
malicious | Sinkholed |
| DigiCert UltraDNS | fortrx.cc |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260514-7A8635 Recipient: abuse-contact@publicdomainregistry.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.