Analysis of the domain fortlive.live, created on July 24 2026 and currently active, shows multiple indicators of malicious use consistent with a generic phishing campaign. The domain is registered through Global Domain Group LLC and is serviced by the DNSPod nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com, a configuration frequently observed in malicious infrastructure due to the ease of rapid provisioning. DNS resolution points to the IPv4 address 158.94.211.169; the host does not appear to be shared with known legitimate services, and no public SSL certificate details are available in the current dataset.
The domain appears on one security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming that at least one operational anti‑phishing platform has identified it as abusive. VirusTotal has processed the domain with 91 scanning engines; at the time of the scan none of the engines reported a detection, but the absence of detections does not constitute a safety guarantee and should be interpreted as an inconclusive result pending further analysis. No additional evidence such as page titles, brand targeting, or malicious payload hashes is presently available, leaving the exact phishing lure undefined.
Defenders should treat fortlive.live as a high‑confidence phishing indicator: block the domain at perimeter firewalls and proxy solutions, add the associated IP address to network‑level deny lists, and monitor DNS queries for the listed nameservers. Continuous re‑scanning with VirusTotal and inclusion in threat‑intel sharing platforms are recommended to capture any emerging detections. Because the domain is newly created, the infrastructure may evolve rapidly; ongoing observation is required to assess whether the IP address is reused for further campaigns.