Analysis indicates that fortloots.com is an active malicious infrastructure used for credential harvesting. The domain was registered on April 01, 2026 through Global Domain Group LLC and is hosted on Cloudflare, as evidenced by the authoritative nameservers lila.ns.cloudflare.com and neil.ns.cloudflare.com. DNS resolution points to the IPv4 address 172.67.137.87, a Cloudflare edge node commonly leveraged by threat actors to obscure origin servers.
The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service, confirming that defensive feeds consider it malicious. VirusTotal scans have recorded 17 detections out of 91 participating security vendors, indicating a moderate to high level of consensus among anti‑malware engines that the site is associated with phishing or credential‑stealing activity. No additional intelligence such as Safe Browsing verdicts, OTX tags, or SSL certificate details were provided, and the page title or targeted brand has not been disclosed, leaving the exact impersonated entity unidentified.
Given the high‑risk rating, defenders should add fortloots.com to network deny lists, enforce DNS sinkholing, and monitor outbound connections to the resolving IP address. Continuous re‑evaluation is advised, as the infrastructure may evolve or additional indicators could emerge from deeper content analysis.