This report analyzes the domain fortbuf.com, flagged as a generic phishing threat on July 30, 2026, with the investigation ongoing. The domain is currently active and resolves to IP address 158.94.211.169. It was registered on July 26, 2026, through the registrar Fewmoretaps OU d/b/a Trustname.com, a relatively recent creation date that may indicate a short-lived malicious campaign. The domain uses nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, which are commonly associated with free or low-cost DNS services and are sometimes leveraged by threat actors for quick deployment. Security checks show that fortbuf.com appears on one security blocklist, specifically PhishDestroy, indicating at least one independent source has identified it as suspicious.
VirusTotal scanned the domain with 91 vendors, but none currently flag it as malicious; however, the absence of detections does not confirm the domain is safe, as many phishing domains evade detection initially. Safe Browsing, OTX, SSL certificate details, HTTP status, and trust scores have not been provided in the available intelligence, so these cannot be assessed. The page title and exact content of the website have not been analyzed, so it is unknown what brand or service the phishing attempt targets. Defenders should treat fortbuf.com with caution. The domain remains active and may be used to host phishing pages targeting unsuspecting users.
Recommended actions include monitoring for any future detections, blocking the domain at network or email gateways, and avoiding interaction with the site. Further investigation into the IP address and associated infrastructure may reveal additional indicators of compromise. Users who have encountered this domain should report it to their security team and avoid entering any personal or financial information. The risk level remains under investigation, and updates should be tracked as more data becomes available.