The domain fortone.top was registered on November 26, 2025 through Web Commerce Communications Ltd and remains active as of the report date, July 31, 2026. DNS resolution points to the IPv4 address 158.94.211.169, and the domain is served by the DNS providers a.dnspod.com, b.dnspod.com, and c.dnspod.com. Infrastructure analysis shows the domain is listed on a single public blocklist and is actively blocked by the PhishDestroy feed, indicating that at least one security vendor has deemed it malicious. VirusTotal reports that the domain has been examined by 91 scanning engines; none of the engines have produced a detection at the time of analysis.
While the absence of detections does not constitute a safety guarantee, it suggests that the malicious payload, if any, may be obfuscated or not yet identified by existing signatures. The limited visibility—no public SSL certificate details, HTTP status codes, or page title information—prevents a deeper content assessment. Consequently, the exact phishing theme, targeted brand, or credential‑harvesting mechanism cannot be confirmed from the available data.
Defenders should treat fortone.top as a high‑confidence phishing indicator based on its registration age, blocklist presence, and active blocking by PhishDestroy. Recommended mitigation steps include adding the domain to local deny lists, monitoring DNS queries for lookups to 158.94.211.169, and employing URL filtering solutions that reference the PhishDestroy feed. Continuous re‑evaluation is advised, as future scans may reveal additional detections or content changes that could refine the threat profile.