Analysis as of July 31, 2026 indicates that fortcalc.club is actively being used in a generic phishing campaign. The domain resolves to the IPv4 address 158.94.211.169 and is served from infrastructure that uses the DNSPod name servers a.dnspod.com, b.dnspod.com, and c.dnspod.com. The domain has been observed by the PhishDestroy blocklist and appears on one additional security blocklist, confirming that at least one external threat‑intelligence source has flagged it as malicious.
VirusTotal records show that the domain was scanned by 91 antivirus and URL‑reputation vendors; none of the vendors returned a detection at the time of the scan. While the lack of detections does not constitute evidence of safety, it does indicate that the payload or landing page may be employing techniques that evade static signatures. No public Safe Browsing, Open Threat Exchange, registrar, SSL certificate, HTTP status code, trust‑score, or page‑title information is currently available for this domain, leaving gaps in the observable surface.
Consequently, defenders should treat fortcalc.club as a high‑confidence phishing indicator. Recommended actions include adding the domain to internal blocklists, monitoring DNS queries for the IP 158.94.211.169, and enabling real‑time URL filtering that references the known blocklist entries. Continuous re‑assessment is advised, as additional telemetry such as page content or SSL details may emerge and refine the risk posture.