Analysis of frtlocker.com shows a newly registered domain created on July 24 2026 through Dominet (HK) Limited. The domain is delegated to DNSPod nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com, and resolves to the IPv4 address 158.94.211.169. VirusTotal has recorded three positive detections out of ninety‑one submitted scanners, indicating that a minority of security engines have identified malicious behavior. The domain is listed on one public blocklist and is actively blocked by the PhishDestroy service, confirming that at least one community‑run feed regards the host as abusive.
The risk rating assigned is high and the operational status is still active as of the report date, July 31 2026. The evidence points to a generic phishing infrastructure, but no additional details such as page title, SSL certificate metadata, or observed HTTP responses have been released. Consequently, the exact payload, targeted brand, or phishing kit remain unknown. The lack of further public telemetry means defenders cannot attribute the campaign to a specific attacker group or determine the full scope of compromised accounts.
Defenders should add frtlocker.com and its resolving IP 158.94.211.169 to internal block lists, enforce DNS‑level filtering for the domain, and monitor outbound traffic for connections to that address. Continuous re‑scanning on VirusTotal or similar aggregators is recommended to capture any change in detection rates. Organizations using email or web gateways should ensure that any URLs pointing to frtlocker.com are quarantined or dropped, and incident response teams should be prepared to investigate any credential submissions that may have been directed to this host.