Analysis of fortpon.com indicates a high-risk phishing domain registered on July 22, 2026, through Realtime Register B.V. As of July 31, 2026, the domain remains active and resolves to IP address 193.187.110.3. VirusTotal reports that 3 out of 91 security vendors flag this domain, suggesting detection by a minority of engines but not widespread consensus. The domain appears on one security blocklist, specifically PhishDestroy, which classifies it as malicious. Nameserver infrastructure is provided by DNSPod (a.dnspod.com, b.dnspod.com, c.dnspod.com), a provider frequently associated with both legitimate and malicious domains, requiring further scrutiny of associated records.
No specific brand target, phishing kit, or page title has been confirmed in available intelligence, limiting classification to generic credential-theft phishing. The domain's recent registration and low detection rate may indicate an early-stage campaign or evasion techniques. Defenders should treat this domain as untrusted and implement blocking at the DNS or proxy level.
Network logs should be reviewed for connections to 193.187.110.3 or fortpon.com, particularly from endpoints exhibiting anomalous authentication behavior. Additional context, such as SSL certificate details or HTTP response headers, is not currently available but would aid in further assessment. Given the active status and minimal detection coverage, this domain warrants continued monitoring for changes in infrastructure or detection volume.