Analysis of the domain fortpro.live indicates active phishing infrastructure targeting business users. Registered on May 23, 2026, through Global Domain Group LLC, the domain currently resolves to the IP address 193.187.110.3. Infrastructure analysis reveals the use of DNSPod nameservers (a.dnspod.com, b.dnspod.com, c.dnspod.com), a pattern observed in other high-risk phishing campaigns. As of July 31, 2026, the domain remains operational and is flagged by one security blocklist, with PhishDestroy marking it as malicious.
VirusTotal telemetry shows that 8 of 91 security vendors classify this domain as malicious, though the specific nature of the threat—such as credential harvesting, malware distribution, or fraudulent transaction pages—has not been confirmed through content analysis. The absence of additional context, such as a known phishing kit or targeted brand, limits attribution beyond its classification as a generic phishing domain. The IP address 193.187.110.3 has not been linked to prior campaigns in available threat feeds, though its association with a recently registered domain warrants caution.
Defenders should treat fortpro.live as high-risk and consider implementing DNS-level blocking or network-level mitigations. Organizations are advised to monitor for connections to 193.187.110.3 and review logs for interactions with the domain, particularly from users accessing business-related portals. Further investigation into the site’s content and potential ties to broader phishing operations is recommended, though no additional evidence of compromise or lateral movement has been identified at this time.