Analysis of fpmarket.group, first observed on July 28, 2026, indicates that the domain is actively being used in a generic phishing campaign. The domain was registered through Ultahost, Inc, and employs Cloudflare name servers (clint.ns.cloudflare.com and val.ns.cloudflare.com). DNS resolution points to the IP address 104.21.35.157, which is currently listed on a single security blocklist and has been blocked by the PhishDestroy service.
VirusTotal records show that the domain has been examined by 91 scanning vendors, none of which have flagged it as malicious at the time of the scan; however, the absence of detections does not constitute a safety assurance. The domain remains active as of the report date, July 30, 2026, and continues to resolve to the same IP address. Defenders should monitor network traffic for connections to 104.21.35.157 and consider adding fpmarket.group to local block lists, especially given its presence on external blocklists.
Additional investigation of HTTP responses, SSL certificate details, and page content is recommended to confirm the phishing payload and to identify any associated infrastructure. Operators are advised to update intrusion detection signatures to include the observed registrar and name server patterns, and to engage with threat intelligence sharing platforms to track any new detections related to this domain.