idpsupport[.]org
Análisis de phishing y seguridad de idpsupport.org
“Index of /”
idpsupport.org — Último activo conocido (HTTP 302). Tipo de estafa: Impersonation. Resumen de las pruebas: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Registrador: Hosting Concepts.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain idpsupport.org indicates it is actively serving as a generic phishing infrastructure with high-risk classification. Registered on May 4, 2026, through Hosting Concepts B.V. d/b/a Registrar.eu, the domain resolves to IP 176.123.0.199, hosted by Alexhost SRL in Moldova. Nameservers ns7.alexhost.com and ns8.alexhost.com further link it to this provider. The domain currently returns an HTTP 302 redirect status, suggesting it may be funneling traffic to another malicious endpoint, though the destination remains unconfirmed. Security vendors PhishDestroy, MetaMask, and SEAL have blocked this domain, and it appears on three security blocklists. AlienVault OTX lists it in one threat intelligence pulse, while Gridinsoft assigns a trust score of 0/100. The SSL certificate is misconfigured, presenting as idpsupport.org.terkepmasolatletoltes.com, a discrepancy that may indicate an attempt to evade detection or impersonate a legitimate service. The page title 'Index of /' suggests an exposed directory listing, a common misconfiguration in hastily deployed phishing sites. No specific brand impersonation is confirmed from the available data, though the domain name implies a support-themed deception. Defenders should treat this domain as active and malicious, blocking resolution at the DNS level and monitoring for connections to 176.123.0.199. Further investigation is required to determine the exact phishing kit or payload in use, as current intelligence does not provide these details.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Cruce de inteligencia de amenazas · source references
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.