Fort26.top is a newly registered domain (creation date 11 February 2026) that has been observed serving a generic phishing campaign. The domain is delegated to the DNSPod nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com and resolves to the IPv4 address 193.187.110.3. Registration was performed via Global Domain Group LLC, a registrar frequently used by malicious operators. The domain appears on at least one public blocklist and is currently listed by the PhishDestroy sink‑hole service, indicating that defensive feeds are already flagging it.
VirusTotal has processed the domain with 91 scanning engines, none of which returned a detection; this lack of a positive match does not constitute evidence of benign intent and should be treated as inconclusive. No public information is available regarding the site’s SSL certificate, HTTP response codes, page title, or any associated malware kit, leaving those vectors unverified. Consequently, the confidence in the full threat profile is limited to the network‑level indicators described above. Defenders should ingest the domain and its IP address into DNS and proxy filters, add the IP to network‑level blocklists, and monitor outbound traffic for connections to 193.187.110.3.
Because the domain is actively listed by PhishDestroy, existing sink‑hole configurations can be leveraged to capture any future payloads or credential submissions. Continuous re‑analysis is recommended, especially if the site begins serving content that can be harvested for page titles or SSL fingerprints, which would enable more precise detection rules. Until additional artifacts appear, the domain should be considered high‑risk for credential‑stealing activity and treated accordingly.