This report analyzes the domain fortcheaks.com, which is currently flagged as a high-risk generic phishing domain. The domain was created on June 21, 2026, and remains active as of the report date of July 31, 2026. Infrastructure analysis reveals that fortcheaks.com is registered through MAT BAO CORPORATION, a registrar commonly associated with low-cost, high-volume domain registrations that are frequently abused for malicious purposes. The domain utilizes nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, which are part of a DNS hosting service often observed in phishing campaigns due to its free tier and rapid propagation capabilities. The domain resolves to the IP address 158.94.211.169, though the associated hosting provider and country of origin are not specified in the available intelligence.
Security vendor detection is notable: VirusTotal reports that 3 out of 91 security vendors flag this domain as malicious, indicating a moderate level of community recognition of its threat nature. Additionally, fortcheaks.com appears on one security blocklist, and it has been actively blocked by the PhishDestroy service, confirming its identification as a phishing threat. The exact content hosted on the domain has not yet been analyzed, as no page title, brand target, or specific scam kit information is available. Therefore, the precise impersonation target or scam methodology remains uncertain.
Defenders should treat fortcheaks.com as a confirmed malicious infrastructure element and implement blocks at the DNS and network levels. Organizations should monitor logs for any connections to this domain or its associated IP address, as such traffic may indicate compromised credentials or ongoing phishing interactions. Given the domain's recent creation and active status, it is likely part of a broader campaign, and related infrastructure sharing similar nameservers or registrar details should be investigated.