The domain fortdrop.shop is presently active and resolves to the IPv4 address 193.187.110.3. Infrastructure analysis shows it is delegated to three DNSpod nameservers—a.dnspod.com, b.dnspod.com, and c.dnspod.com—indicating use of a popular DNS hosting provider. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy service, confirming that at least one reputable anti‑phishing vendor has catalogued it as malicious.
VirusTotal records indicate that the domain was scanned by 91 separate detection engines and none reported a detection at the time of analysis; this observation is noted without implying that the domain is safe. No additional public intelligence such as ASN, country attribution, SSL certificate details, HTTP response codes, or page‑title information is available, leaving the broader hosting context and site content unverified. The lack of broader detection or reputation data creates uncertainty regarding the full scope of the phishing campaign, but the presence on a blocklist and the active resolution to a dedicated IP address suggest a deliberately maintained malicious infrastructure.
Defenders are advised to add fortdrop.shop to outbound filtering rules, ensure that internal DNS resolvers block or sinkhole the domain, and monitor for any future appearance on additional blocklists or detection platforms. Continuous re‑evaluation of the domain’s status is recommended, as changes in hosting, content, or detection outcomes may alter the risk profile.