Analysis of fortcheak.com indicates the domain is currently active and associated with a generic phishing campaign. The domain was registered on June 16, 2026 through MAT BAO CORPORATION and resolves to the IP address 193.187.110.3. DNS resolution is served by the three authoritative nameservers a.dnspod.com, b.dnspod.com, and c.dnspod.com, which are typical of the DNSPod hosting service. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one industry‑wide source has identified malicious activity tied to the domain.
A VirusTotal scan involving 91 antivirus and scanning engines returned no detections; while the lack of flags does not constitute proof of safety, it demonstrates that the payload or associated URLs have not yet been flagged by the majority of commercial scanners. No SSL certificate details, HTTP response codes, page title, or brand targeting information have been published, leaving the content of the site unverified. The absence of such telemetry means that the exact phishing vector, credential‑stealing pages, or lure techniques remain unknown. Defenders should treat the domain as hostile until further evidence is gathered.
Recommended actions include adding the domain and its resolved IP address to firewall deny lists, monitoring DNS queries for the three dnspod nameservers, and implementing proxy or web‑gateway filtering to block any outbound connections to the domain. Continuous re‑scanning with VirusTotal or equivalent sandbox services is advisable, as detection signatures may emerge as the campaign matures. Organizations that rely on email or web traffic filtering should ensure that their threat intelligence feeds ingest the PhishDestroy blocklist entry for fortcheak.com to reduce exposure.