Analysis indicates that the domain fortnitestar.shop remains active as of 31 July 2026. DNS resolution points to the IPv4 address 193.187.110.3, and the authoritative name servers are a.dnspod.com, b.dnspod.com and c.dnspod.com. The domain is listed on one external security blocklist and is actively blocked by the PhishDestroy feed, confirming that it is being treated as malicious by at least one reputable anti‑phishing consortium.
VirusTotal reports that 2 of 91 scanning engines have flagged the domain, providing additional independent confirmation of its malicious nature. No further telemetry such as SSL certificate details, HTTP response codes, page title, or Safe Browsing verdicts are available in the current intelligence set, leaving the surface‑web characteristics of the site undocumented. Given the limited but consistent indicators—active status, resolvable IP, presence on a blocklist, inclusion in PhishDestroy, and multiple vendor detections—defenders should treat fortnitestar.shop as a high‑confidence phishing infrastructure.
Recommended mitigations include adding the domain and its resolved IP address to outbound and inbound deny lists, ensuring that DNS filtering solutions block queries to the listed nameservers, and monitoring for any new indicators that may emerge from deeper content analysis or sandbox execution. Continuous re‑evaluation is advised in case additional detection data becomes available, particularly regarding SSL usage, HTTP behavior, and potential credential‑stealing pages. Until such data is obtained, precautionary blocking remains the most effective control.