1ido[.]org
“www.www.1ido.org”
证据摘要
PhishDestroy identifies the domain 1ido.org as an active threat engaged in generic phishing, targeting users with no specific brand impersonation detected. This domain does not currently appear to leverage a known drainer kit but functions as a credential harvesting platform, attempting to deceive victims with a generic phishing page titled "www.www.1ido.org".
The domain 1ido.org yields a VirusTotal detection ratio of 1 out of 95 security vendors, indicating low but non-negligible recognition as malicious. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain resolves to the IP address 172.67.154.139 and is secured by an SSL certificate issued by Google Trust Services. This domain was created recently on November 09, 2025, and despite its fresh registration, it lacks a Google Safe Browsing block (GSB status not flagged) and has a limited blocklist presence, which suggests it may evade some automated defenses.
Currently, 1ido.org remains active with an elevated risk level due to its ongoing phishing activity targeting generic credentials. Security teams are advised to monitor and block this domain proactively given its potential for user credential compromise despite a low VirusTotal detection count. Users should avoid interacting with this domain and report any suspicious communications linked to it. Continued vigilance and updates to endpoint protections will help mitigate exposure as threat intelligence evolves.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
已存储的结果证据
处置结果与下线归因
- 结果
held- 可用性
unreachable- 原因
registrar_client_hold- 执行方
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- 机制
client_hold- 置信度
- 95%
- 首次观测
- 最新观测
预计不可用时间
直至不可用的时间: 0 h证据 SHA-256 db7ae43b0fe2
检测时间线
-
可用性
首次存储值:DNS 非活动
f93a11f87e4d -
可用性
DNS 非活动 → 未知
25c711c458e5 -
可用性
未知 → DNS 非活动
f69af090fd4e -
可用性
DNS 非活动 → 已保留
7ae302f89ede -
可用性
已保留 → DNS 非活动
f52d526b76a1 -
可用性
DNS 非活动 → 未知
09c219cb984a -
可用性
未知 → 已保留
15d98a3d41c3 -
可用性
已保留 → 未知
5bbf4bed9ecd -
可用性
未知 → DNS 非活动
6dfe9145995c -
可用性
DNS 非活动 → 已保留
51c7e99bab90
显示全部(9)
-
可用性
已保留 → DNS 非活动
641ed81dc4d5 -
可用性
DNS 非活动 → 未知
4cde599c3e22 -
可用性
未知 → 已保留
d860533c9cd2 -
可用性
已保留 → 未知
37870f833b21 -
可用性
未知 → DNS 非活动
d0b7046e8c2f -
可用性
DNS 非活动 → 已保留
bff0469999d3 -
可用性
已保留 → DNS 非活动
ca9ed662b468 -
可用性
DNS 非活动 → 未知
f4fa2f7cf5c3 -
可用性
未知 → 已保留
db7ae43b0fe2
社区报告
由 1 名社区成员报告;首次发现于 2026年3月25日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
社区情报
1 条社区报告
类别PHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against Lido Finance. Threat detected at 2026-03-26T00:42:09.056Z.
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控