Analysis conducted on July 31, 2026 identifies forniteskins.com as an active generic phishing infrastructure. The domain was registered only six days earlier, on July 25, 2026, through Realtime Register B.V., indicating a rapid deployment typical of opportunistic campaigns. DNS resolution points to the single IPv4 address 158.94.211.169, and the authoritative name servers are a.dnspod.com, b.dnspod.com, and c.dnspod.com, all hosted by the DNSPod service, suggesting the operator leveraged a widely available DNS provider to obtain quick domain activation. Reputation data shows the domain appears on one external security blocklist and is actively blocked by the PhishDestroy service, reinforcing the assessment of malicious intent.
VirusTotal scanning reports that two of ninety‑one submitted security vendors flagged the domain, providing independent confirmation of its suspicious nature despite the relatively low detection count. No additional public intelligence such as SSL certificate details, HTTP response codes, or page title information has been published, leaving those aspects of the payload and hosting environment unverified. Given the recent creation date, the association with a known blocklist, and the detection by multiple security vendors, defenders should treat forniteskins.com as high‑risk.
Recommended mitigations include immediate network‑level blocking of the domain and its resolved IP address, adding the domain to local and third‑party URL filtering lists, and continuous monitoring for any changes in DNS records or additional detections. Analysts should also consider proactive harvesting of any future samples or URLs associated with the domain to enrich detection signatures. Until further forensic evidence becomes available, the domain remains classified as an active phishing threat.