Analysis indicates that the domain forven.pro was registered on 26 May 2026 through Global Domain Group LLC and is served by the DNSPod nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com. The domain resolves to the IPv4 address 193.187.110.3, which is currently listed on one public security blocklist and has been actively blocked by the PhishDestroy mitigation service. A VirusTotal scan submitted the host to 91 antivirus and URL‑reputation engines; none of the engines raised a detection at the time of analysis, a result that does not imply the absence of malicious behavior.
The domain is classified as a generic phishing site, but no detailed page content, page title, or targeted brand information has been extracted, leaving the exact phishing vector uncertain. No SSL/TLS certificate data has been observed for the host, indicating that either the service operates without HTTPS or that certificate information has not been captured; this omission further complicates automated reputation scoring. The short operational lifespan—creation less than three months before the report date—suggests a rapidly deployed campaign, possibly leveraging disposable registration services.
Defenders should consider adding forven.pro to internal URL filtering and DNS blocklists, monitor traffic to the associated IP address, and implement heuristic detection for credential‑harvesting patterns. Ongoing observation of the IP reputation and any future VirusTotal or sandbox submissions is recommended to detect potential evolution of the payload or hosting changes. Given the active status and existing blocklist entry, immediate preventative controls are advised while additional threat intelligence is gathered.