1ido[.]org
“www.www.1ido.org”
PhishDestroy identifies the domain 1ido.org as an active threat engaged in generic phishing, targeting users with no specific brand impersonation detected. This domain does not currently appear to leverage a known drainer kit but functions as a credential harvesting platform, attempting to deceive victims with a generic phishing page titled "www.www.1ido.org".
The domain 1ido.org yields a VirusTotal detection ratio of 1 out of 95 security vendors, indicating low but non-negligible recognition as malicious. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain resolves to the IP address 172.67.154.139 and is secured by an SSL certificate issued by Google Trust Services. This domain was created recently on November 09, 2025, and despite its fresh registration, it lacks a Google Safe Browsing block (GSB status not flagged) and has a limited blocklist presence, which suggests it may evade some automated defenses.
Currently, 1ido.org remains active with an elevated risk level due to its ongoing phishing activity targeting generic credentials. Security teams are advised to monitor and block this domain proactively given its potential for user credential compromise despite a low VirusTotal detection count. Users should avoid interacting with this domain and report any suspicious communications linked to it. Continued vigilance and updates to endpoint protections will help mitigate exposure as threat intelligence evolves.
네트워크 보안 인텔리전스 Registrar context
위협 대응 Pipeline
차단 목록 범위
출처 10개 · 2026년 8월 9일 동기화
저장된 결과 증거
결과 및 차단 귀속
- 결과
held- 원인
registrar_client_hold- 조치 주체
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- 메커니즘
client_hold- 신뢰도
- 95%
등록기관 조치
NICENIC INTERNATIONAL GROUP CO., LIMITED IANA 3765
귀속 증거:
예상 비가용 시점
불확실성 범위: ±2515.09 h 시간 정밀도:very_low 탐지 타임라인
저장된 관찰 결과를 시간순으로 표시합니다.
-
가용성
가용성: 최초 관찰 상태 dns_inactive
f93a11f87e4d -
가용성
가용성: dns_inactive → unknown
25c711c458e5 -
가용성
가용성: unknown → dns_inactive
f69af090fd4e -
가용성
가용성: dns_inactive → held
7ae302f89ede -
가용성
가용성: held → dns_inactive
f52d526b76a1 -
가용성
가용성: dns_inactive → unknown
09c219cb984a -
가용성
가용성: unknown → held
15d98a3d41c3 -
가용성
가용성: held → unknown
5bbf4bed9ecd -
가용성
가용성: unknown → dns_inactive
6dfe9145995c -
가용성
가용성: dns_inactive → held
51c7e99bab90
모두 보기 (6)
-
가용성
가용성: held → dns_inactive
641ed81dc4d5 -
가용성
가용성: dns_inactive → unknown
4cde599c3e22 -
가용성
가용성: unknown → held
d860533c9cd2 -
가용성
가용성: held → unknown
37870f833b21 -
가용성
가용성: unknown → dns_inactive
d0b7046e8c2f -
가용성
가용성: dns_inactive → held
bff0469999d3
커뮤니티 인텔리전스
커뮤니티 신고 1건
범주PHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against Lido Finance. Threat detected at 2026-03-26T00:42:09.056Z.
저장된 캡처
도메인 인텔리전스
기술 세부 정보DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
포렌식 인텔리전스
VirusTotal 분석
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.
모든 도메인 확인
저장된 차단 목록, WHOIS, DNS 및 공개 스캔 증거를 사용한 위협 분석
지금 스캔하기피싱 신고
의심스러운 도메인을 당사의 위협 데이터베이스에 신고해 주세요 — 커뮤니티를 보호해 주세요
보고서실시간 위협 정보
최근 피싱 보고서 및 관찰된 가용성 변경 사항
모니터링