This domain, fortowow.com, is actively flagged as a high-risk phishing site targeting Blizzard account credentials. Infrastructure analysis reveals the domain was registered on July 23, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with phishing campaigns. It currently resolves to the IP address 158.94.211.169, which has not yet been widely profiled in threat intelligence feeds but is already blocked by PhishDestroy. As of July 31, 2026, two out of 91 security vendors on VirusTotal have detected the domain as malicious, indicating early but confirmed detection.
The domain appears on at least one security blocklist, reinforcing its classification as an active threat. The nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com) are consistent with infrastructure used by threat actors to evade takedowns, as DNSPod services are known for lenient abuse handling. No SSL certificate details or HTTP response data are currently available in the provided intelligence, leaving the exact page content unconfirmed. However, the domain name itself, combined with the phishing classification, strongly suggests an attempt to impersonate Blizzard's World of Warcraft login portal to harvest user credentials.
Defenders should treat this domain as an active credential theft operation. Immediate actions include blocking the domain and its resolving IP at the network perimeter, updating endpoint protection signatures, and monitoring for connections to 158.94.211.169. If internal logs show any user interaction with fortowow.com, reset affected credentials and initiate incident response procedures. Given the domain's recent registration and limited detection footprint, further analysis of the hosting provider and IP range may reveal additional related infrastructure.