Analysis of the domain fortic.cc shows that it was registered on April 10 2026 through Gname.com Pte. Ltd. The authoritative nameservers are a.dnspod.com, b.dnspod.com and c.dnspod.com, indicating use of the DNSPod service. DNS resolution points to the IPv4 address 158.94.211.169, which is the sole hosting endpoint observed for this site. The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy mitigation service, confirming that it is recognized by at least one anti‑phishing consortium.
VirusTotal reports that four out of ninety‑one scanning engines have flagged the domain, demonstrating that a minority of reputation services have identified malicious characteristics. No additional public threat‑intel sources such as OTX, Google Safe Browsing, or SSL/TLS certificate data are currently associated with fortic.cc, and the HTTP response details and page title have not been disclosed in the available intelligence. The limited detection footprint suggests that the campaign may be in an early deployment phase or that the operators are employing evasion techniques to stay under the radar of bulk scanners.
Defenders should add fortic.cc to internal deny‑list controls, monitor DNS queries for outbound resolution to 158.94.211.169, and enforce outbound traffic filtering for any HTTP(S) connections to this host. Continuous re‑evaluation of the domain on VirusTotal and other reputation platforms is recommended, as additional detections could emerge as the phishing infrastructure matures. Organizations employing email security gateways should ensure that any messages containing links to fortic.cc are quarantined or rejected, and users should be educated to avoid clicking unknown URLs, especially those that appear in unsolicited communications.