Analysis of fntop.live, a domain registered through PDR Ltd. d/b/a PublicDomainRegistry.com on March 13 2026, shows it is currently active and resolves to the IPv4 address 193.187.110.3. The domain is delegated to the DNSPod name servers a.dnspod.com, b.dnspod.com and c.dnspod.com. Infrastructure profiling indicates the hosting provider operates from the same IP range that hosts other recent phishing infrastructure, although no additional attribution is available. The domain has been submitted to VirusTotal and scanned by 91 antivirus and sandbox engines; none of the engines reported a detection at the time of analysis, but the absence of detections does not constitute a safety assurance. fntop.live is listed on a single security blocklist and is actively blocked by the PhishDestroy filtering service, confirming that at least one downstream security product has identified it as malicious.
No public SSL certificate information, HTTP response codes, or page‑title metadata have been published, so the web content has not yet been fingerprinted. Consequently, the exact phishing campaign details, target brand, and lure tactics remain unknown. Defenders should treat fntop.live as a potentially malicious host pending further investigation. Network‑level controls should block outbound connections to 193.187.110.3 and to the three DNSPod name servers when possible.
Email gateways and web proxies should incorporate the domain into blocklists, leveraging the existing PhishDestroy entry. Continuous monitoring of VirusTotal re‑scans and additional threat‑intel feeds is recommended to capture any future detections. Analysts should also query the IP for any associated malicious activity and watch for new entries on blocklists that reference fntop.live. Until more concrete evidence emerges, the precautionary stance is to deny or quarantine traffic to the domain.