MALICIOUS — CRITICAL
Verifica phishing e sicurezza per idpsupport.org
idpsupport[.]
Analysis of the domain idpsupport.org indicates it is actively serving as a generic phishing infrastructure with high-risk classification.
- VirusTotal
- 11/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ultimo attivo conosciuto · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
idpsupport.org — Ultimo attivo conosciuto (HTTP 302). Tipo di truffa: Impersonation. Riepilogo delle prove: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Registrar: Hosting Concepts.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
Analysis of the domain idpsupport.org indicates it is actively serving as a generic phishing infrastructure with high-risk classification. Registered on May 4, 2026, through Hosting Concepts B.V. d/b/a Registrar.eu, the domain resolves to IP 176.123.0.199, hosted by Alexhost SRL in Moldova. Nameservers ns7.alexhost.com and ns8.alexhost.com further link it to this provider. The domain currently returns an HTTP 302 redirect status, suggesting it may be funneling traffic to another malicious endpoint, though the destination remains unconfirmed. Security vendors PhishDestroy, MetaMask, and SEAL have blocked this domain, and it appears on three security blocklists. AlienVault OTX lists it in one threat intelligence pulse, while Gridinsoft assigns a trust score of 0/100. The SSL certificate is misconfigured, presenting as idpsupport.org.terkepmasolatletoltes.com, a discrepancy that may indicate an attempt to evade detection or impersonate a legitimate service. The page title 'Index of /' suggests an exposed directory listing, a common misconfiguration in hastily deployed phishing sites. No specific brand impersonation is confirmed from the available data, though the domain name implies a support-themed deception. Defenders should treat this domain as active and malicious, blocking resolution at the DNS level and monitoring for connections to 176.123.0.199. Further investigation is required to determine the exact phishing kit or payload in use, as current intelligence does not provide these details.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Copertura dei dati13 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Riscontro delle informazioni sulle minacce · source references
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.