Analysis of fortishot.com shows the domain is currently active and has been identified as a generic phishing operation. The domain was registered on May 05, 2026 through Web Commerce Communications Limited dba WebNic.cc and uses the DNS service provider dnspod.com with three authoritative name servers: a.dnspod.com, b.dnspod.com, and c.dnspod.com. DNS resolution points to the IPv4 address 158.94.211.169.
VirusTotal records indicate the domain was scanned by 91 security vendors, none of which raised a detection; however, the lack of detections does not constitute assurance of safety. The domain is listed on at least one security blocklist and is actively blocked by PhishDestroy. No additional public intelligence such as Safe Browsing, OTX, SSL certificate details, HTTP response codes, trust scores, or page title information is presently available, leaving the full scope of the malicious content unknown.
Defenders should proactively block the domain at network perimeter and endpoint controls, monitor DNS queries for the associated name servers, and consider adding the IP address 158.94.211.169 to deny lists. Continuous re‑evaluation is advised as further indicators may emerge from future scans or threat‑intel feeds.