Analysis of fncate.com shows a newly registered domain (creation date July 25, 2026) that is currently active and associated with a generic phishing threat. The domain is registered through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to the IPv4 address 158.94.211.169. DNS resolution is serviced by three DNSpod nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com), a configuration commonly observed in fast‑flux or disposable‑hosting setups.
The domain has been flagged by the PhishDestroy blocklist and appears on one additional security blocklist, indicating that at least one external feed has identified it as malicious. A VirusTotal scan involving 91 antivirus and URL‑analysis engines returned no detections; however, the absence of detections does not constitute a safety guarantee and should be interpreted as a lack of current signatures rather than evidence of benign behavior. No publicly available information on SSL/TLS certificates, HTTP status codes, page titles, or brand targeting has been released, leaving the exact phishing payload and victim lure uncertain.
Defenders should treat fncate.com as hostile: block the domain and its resolving IP at network perimeters, add the domain to internal deny lists, and continue to monitor for any new indicators such as changes in hosting, additional blocklist listings, or the emergence of URL‑based detections. Ongoing re‑scanning with multi‑engine services is recommended to capture any future malicious payloads that may be associated with this infrastructure.