The domain fortnitebuyer.online was registered on July 23, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and is currently resolved to the IPv4 address 158.94.211.169. DNS resolution is provided by the authoritative name servers a.dnspod.com, b.dnspod.com and c.dnspod.com. The domain appears on a single security blocklist and has been actively blocked by the PhishDestroy service, indicating that at least one defensive infrastructure has identified it as malicious.
VirusTotal reports that the domain has been scanned by 91 security vendors; none of the vendors have raised a detection at the time of analysis, but the absence of detections does not confirm benign intent. No further public reputation scores, Safe Browsing status, or Open Threat Exchange (OTX) indicators are available in the current dataset. The limited observable data points to a newly created infrastructure that is consistent with a generic phishing campaign, yet the specific target brand or phishing kit cannot be confirmed from the available evidence.
Defenders should consider adding the domain and its associated IP address to local block lists, monitor DNS queries for the listed name servers, and continue to watch for any emerging detections from additional threat intel sources. Ongoing observation is recommended to determine whether the site begins serving phishing content, changes hosting, or becomes associated with broader malicious activity.