Analysis of fortpop.top indicates a high-risk credential-theft phishing domain active as of July 31, 2026. The domain was registered on May 25, 2026, through PDR Ltd and currently resolves to the IP address 193.187.110.3. Infrastructure analysis reveals the use of nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration commonly observed in phishing campaigns leveraging low-cost or bulletproof hosting providers. The domain appears on one security blocklist, and PhishDestroy has explicitly blocked it, suggesting prior detection of malicious activity. VirusTotal reports that 13 out of 91 security vendors flag fortpop.top as malicious, though the specific nature of the threat—such as the targeted brand or phishing kit—remains unconfirmed due to the absence of detailed page content analysis.
The registration details and hosting infrastructure provide additional context for defenders. PDR Ltd, the registrar, has been associated with domains involved in phishing and fraud in prior campaigns, though this does not inherently confirm malicious intent for fortpop.top. The IP address 193.187.110.3 has not been linked to additional domains in the available data, limiting attribution to broader campaigns. No SSL certificate details or HTTP response codes are provided, so the domain's current operational status—whether it is actively serving phishing pages or is in a dormant state—cannot be definitively determined.
Defenders should treat this domain as actively malicious based on the available evidence. Immediate actions include blocking the domain at the DNS or network level, monitoring for connections to the associated IP address, and reviewing logs for prior interactions. If internal users or systems have accessed fortpop.top, incident response procedures should be initiated to assess potential credential exposure or malware delivery.