Fortroad.cc is a newly registered domain that has been observed in active phishing campaigns. The domain was created on July 23, 2026 and is registered through Global Domain Group LLC. DNS resolution points to the IPv4 address 158.94.211.169, and the authoritative name servers are a.dnspod.com, b.dnspod.com and c.dnspod.com, indicating use of the DNSPod hosting platform. VirusTotal analysis shows that five of ninety‑one scanning engines have flagged the domain as malicious, providing an early indication of suspicious activity. The domain is currently listed on one external security blocklist and has been added to the PhishDestroy blocklist, confirming that at least one commercial mitigation service is actively denying traffic to it.
The risk rating assigned by the reporting system is high, reflecting the combination of recent creation, active status, and multi‑vendor detection. No additional public intelligence such as page titles, SSL certificates, or HTTP response codes has been released, so the exact phishing lure and targeted brand remain unknown. At this time, no evidence of SSL/TLS configuration or specific phishing page content has been published, limiting attribution of the exact attack vector. The limited visibility suggests that the infrastructure is being used in a short‑lived campaign, but the presence of multiple DNSPod name servers may facilitate rapid re‑deployment.
Defenders should add 158.94.211.169 and fortroad.cc to network‑level deny lists, monitor DNS queries for the listed name servers, and enforce URL filtering based on the blocklist entries. Continuous re‑scanning with multi‑engine services is recommended to capture any changes in detection status. Organizations that rely on email or web gateways should ensure that phishing‑prevention rules are updated to include this domain, and incident response teams should treat any credential submissions to the domain as compromised.