fco-mains[.]cc
“Benchmarkagru - Защита интересов клиентов в финансовых спорах с брокерами”
fco-mains.cc — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 20/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 6 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies fco-mains.cc as a HIGH-RISK crypto drainer phishing domain designed to deceive users into unknowingly transferring cryptocurrency to threat actor-controlled wallets. The domain impersonates legitimate financial or trading platforms, luring victims with fake login portals or fraudulent investment opportunities. Once accessed, victims are prompted to connect their cryptocurrency wallets, and embedded malicious scripts execute unauthorized transactions, draining funds without the user’s consent. Security researchers have observed similar campaigns targeting users of platforms like MetaMask, Trust Wallet, and centralized exchanges, with this domain specifically engineered to bypass basic browser security warnings through the use of a legitimate Let’s Encrypt SSL certificate. This domain was flagged by PhishDestroy with a HIGH risk assessment after being detected on 5 separate security blocklists, including PhishingArmy, StevenBlack, OISD, Hagezi, and CERT-PL. VirusTotal analysis confirms malicious activity with 20 out of 95 security vendors flagging the domain as unsafe. The domain was registered on March 23, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar often associated with high-risk or disposable domains used in phishing campaigns. The domain resolves to IP address 188.114.96.3, which has been linked to previous cryptocurrency scams and malware distribution. The use of a legitimate SSL certificate adds a false sense of security, making it more likely for unsuspecting users to interact with the site without hesitation. Given the recent creation date, rapid escalation in malicious activity, and widespread blocklist coverage, the threat posed by this domain is both immediate and severe. Users who have visited fco-mains.cc should immediately disconnect any connected cryptocurrency wallets and revoke any permissions granted to suspicious domains. Do not enter any credentials, private keys, or wallet addresses on this site. Run a full antivirus scan to detect and remove any potential malware or keyloggers installed by the site. If you have interacted with the domain, check your wallet transaction history for unauthorized transfers and report any suspicious activity to your wallet provider or exchange. For further verification, users can check the domain’s safety status on reputable threat intelligence platforms like PhishDestroy, VirusTotal, or Google Safe Browsing. Always verify the legitimacy of financial or trading platforms by cross-referencing official websites and using trusted bookmarks or direct URLs. Remain vigilant for phishing attempts, as threat actors frequently rotate domains and tactics to evade detection.
网络安全情报 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | fco-mains.cc |
malicious | Sinkholed |
| DNS4EU | fco-mains.cc |
malicious | Sinkholed |
| OpenDNS | fco-mains.cc |
phishing | Phishing Block |
| Quad9 DNS | fco-mains.cc |
malicious | Sinkholed |
| Cloudflare DNS | fco-mains.cc |
malicious | Sinkholed |
| Hagezi Threat Feed | fco-mains.cc |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
Latest Classified Outcome 2026-08-13 03:02:09 UTC
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of fco-mains.cc · checked Apr 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。