Analysis indicates that tenzdrop.com was registered on August 23, 2025 through REG.RU LLC and is currently hosted at IP address 158.94.211.169. The domain uses the DNSPod nameservers a.dnspod.com, b.dnspod.com and c.dnspod.com. VirusTotal reports that the domain has been scanned by 91 security vendors; none of the vendors flagged the domain as malicious at the time of the scan, but the absence of detections does not constitute a safety guarantee.
The domain is listed on a single external blocklist and is actively blocked by the PhishDestroy feed, confirming that it has been observed in phishing campaigns. No public SSL certificate information, HTTP response codes, page title, or content analysis have been published, so the exact appearance of the site and the brand it may be impersonating remain unknown. The lack of additional telemetry limits confidence in attributing a specific phishing kit or target brand.
Defenders should treat tenzdrop.com as a potentially malicious resource. Recommended actions include adding the domain to internal deny lists, monitoring DNS queries for resolutions to 158.94.211.169, and correlating any authentication attempts or credential submissions to the domain with user activity logs. Continuous re‑evaluation is advised, as future scans or intelligence feeds may provide further indicators of compromise.