# PhishDestroy threat dossier — dpd.lqtygfo.cyou ================================================================ Fetched: 2026-07-29 14:14:47 UTC Canonical: https://phishdestroy.io/domain/dpd.lqtygfo.cyou/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 72/100 (PhishDestroy scoring — see methodology below) Targeted brand: dpd (and: youtube) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.170.112 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Dominet (HK) Limited Nameservers: alaric.ns.cloudflare.com, ingrid.ns.cloudflare.com Registered: 2026-07-18 Expires: 2027-07-18 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-10-18 Status: INVALID chain Fingerprint: 7a7566a92c5b336dfea76a550d875c7c4ea798226c84cbe7d3ae1f2b11a8c617 Subject Alternative Names (related infrastructure — often same operator): - lqtygfo.cyou ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-07-18 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-21 02:12:25 UTC (by PhishDestroy tracker) First reported: 2026-07-21 00:18:39 UTC (abuse notice filed) Last verified: 2026-07-29 12:20:37 UTC Neutralised: 2026-07-21 04:19:44 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f8202-d4ce-748d-9df0-383892beb65e/ URLQuery: https://urlquery.net/report/75319a84-10a4-459a-88fd-742b22961d1e Wayback Machine: https://web.archive.org/web/*/dpd.lqtygfo.cyou crt.sh CT logs: https://crt.sh/?q=%25.dpd.lqtygfo.cyou Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=dpd.lqtygfo.cyou AlienVault OTX: https://otx.alienvault.com/indicator/domain/dpd.lqtygfo.cyou URLhaus: https://urlhaus.abuse.ch/host/dpd.lqtygfo.cyou/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-21 02:15:38 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] dpd.lqtygfo.cyou Safety Check — Parcel Phishing Detected This domain, dpd.lqtygfo.cyou, was registered on July 18, 2026, through Dominet (HK) Limited and remains active as of July 21, 2026. Infrastructure analysis reveals it is hosted on Cloudflare nameservers (alaric.ns.cloudflare.com and ingrid.ns.cloudflare.com) and resolves to the IP address 172.67.170.112. The domain is currently flagged by PhishDestroy and appears on one security blocklist. Google Safe Browsing categorizes it as engaging in social engineering, a classification consistent with phishing activity. No detections were recorded by the 95 vendors that scanned the domain on VirusTotal, though the absence of detections does not confirm safety. The domain's content has not been fully analyzed, and no specific brand or scam kit has been identified in the available data. However, the combination of a newly registered domain, Cloudflare hosting, and social engineering classification suggests it is likely part of a phishing campaign targeting parcel delivery or logistics-related credentials. Defenders should treat this domain as high-risk and consider blocking it at the network level, particularly in environments where users may be exposed to parcel delivery scams. Further investigation is recommended to determine the exact nature of the phishing content and any associated payloads or credential harvesting mechanisms. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260721-E7744E TLS cert SHA-256: 7a7566a92c5b336dfea76a550d875c7c4ea798226c84cbe7d3ae1f2b11a8c617 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/dpd.lqtygfo.cyou/ JSON API: https://api.destroy.tools/v1/check?domain=dpd.lqtygfo.cyou Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,478 domains (83,245 alive under monitoring, 109,716 confirmed takedowns/dead). Site: https://phishdestroy.io