The domain fortlop.top was registered on June 30, 2026 through Global Domain Group LLC and is currently resolving to the IPv4 address 158.94.211.169. Its authoritative name servers are a.dnspod.com, b.dnspod.com, and c.dnspod.com, indicating use of the DNSPod service. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy sink‑hole, confirming that it is being used in a phishing campaign.
VirusTotal analysis shows that three of ninety‑one scanned security vendors flagged the domain as malicious, providing independent corroboration of its hostile intent. No additional public intelligence such as Safe Browsing status, SSL certificate details, or page‑title metadata is available at this time, leaving the exact payload and targeted brand unspecified beyond the generic phishing classification. The infrastructure is minimal but active, and the IP address 158.94.211.169 remains reachable, suggesting that the hosting environment is still operational.
Defenders should immediately add fortlop.top to DNS and web‑filter blocklists, monitor outbound connections to the associated IP, and consider sinkholing the domain to disrupt further credential collection. Continuous re‑scanning of the domain on multi‑vendor platforms is advised to capture any changes in detection status. Organizations should also review email gateway logs for any recent communications containing fortlop.top links and enforce MFA where possible to mitigate credential compromise risk.