dpd.mztrqplxvn.cfd
“dpd.mztrqplxvn.cfd”
Evidence Summary
The domain dpd.mztrqplxvn.cfd has been confirmed as a social engineering scam. This site poses a significant risk to users by attempting to deceive them into providing sensitive information, such as login credentials or financial details. The domain does not appear to be associated with a specific brand and no drainer kit has been identified.
Analysis indicates that the domain dpd.mztrqplxvn.cfd has been flagged by 20 out of 95 security vendors on VirusTotal, suggesting a high level of suspicion. The domain is registered through Aceville Pte. Ltd. and resolves to the IP address 188.114.97.3. Created on May 26, 2026, the domain has a very low Gridinsoft trust score of 0/100. Google Safe Browsing has flagged the domain for social engineering, and it appears on 1 security blocklist. The domain is currently offline, as of the latest assessment.
Despite the domain being taken offline, the infrastructure and technical indicators suggest a deliberate and sophisticated phishing operation. Organizations and users should remain vigilant and ensure that their security systems are updated to block this domain. The risk of exposure remains, particularly for users who may have interacted with the site before it was taken down. It is recommended to monitor for any related malicious activity and to educate users about the signs of social engineering scams.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | dpd.mztrqplxvn.cfd |
malicious | Sinkholed |
Detection timeline
-
VirusTotal
11 → 20 (+9) (Added: BitDefender, Chong Lua Dao, Cluster25, Criminal IP, CyRadar, Forcepoint ThreatSeeker, G-Data, Google Safebrowsing, Gridinsoft, LevelBlue, Lionic, SOCRadar, Sophos, VIPRE) (Removed: Emsisoft, Netcraft)
Threat Response Pipeline
Public Blocklist Status
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260601-BDBC9A- Captured page title
- dpd.mztrqplxvn.cfd/com/
Blocklist coverage
11 monitored external feeds · stored snapshot Sep 10, 2026
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
SHORTDOT ZONE · PUBLIC EVIDENCE
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: mztrqplxvn.cfd
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain mztrqplxvn.cfd behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Technologies
2 high-confidence technologies identified
Evidence & External Reports
PD-20260601-BDBC9A Recipient: dnsabuse_complaint@tencent.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive