Analysis of fortntop.cc indicates a high-risk phishing domain active as of July 31, 2026. The domain was registered on April 10, 2026, through Global Domain Group LLC and currently resolves to IP address 158.94.211.169. Infrastructure analysis reveals the use of DNSPod nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com), a common pattern observed in phishing campaigns leveraging low-cost or bulletproof hosting providers.
The domain appears on one security blocklist, specifically PhishDestroy, and is flagged by 5 of 91 security vendors on VirusTotal, confirming malicious classification by multiple detection engines. The exact content or targeted brand of the phishing site is not yet analysed, though the domain name suggests an attempt to mimic enterprise security or network infrastructure (e.g., Fortinet or similar). No specific phishing kit or brand impersonation has been confirmed in available data.
Defenders are advised to treat this domain as malicious and implement blocking at the DNS or network level. Monitoring for connections to 158.94.211.169 or domains using DNSPod nameservers may help identify related threats. Given the domain's recent registration and active status, further investigation into associated infrastructure is recommended to assess campaign scope and potential lateral movement within networks.