# PhishDestroy threat dossier — dpd.xtrqplm.cfd ================================================================ Fetched: 2026-06-25 01:43:13 UTC Canonical: https://phishdestroy.io/domain/dpd.xtrqplm.cfd/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 67/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 6/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Cluster25, CRDF, Fortinet, Gridinsoft, SOCRadar Public blocklists: listed on 1 independent blocklist Google Safe Browsing: FLAGGED ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.208.105 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: Cloudflare, Inc. Registrar: Aceville Pte. Ltd. Nameservers: ["gail.ns.cloudflare.com", "ram.ns.cloudflare.com"] Registered: 2026-05-22 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-08-19 Status: INVALID chain Fingerprint: b745bc477136d40efa00fd14c911ac4ac4f43aca7bf782ec36cc545c8e00c331 Subject Alternative Names (related infrastructure — often same operator): - xtrqplm.cfd ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-05-22 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-22 11:30:23 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-06-25 00:20:44 UTC Neutralised: 2026-05-23 18:13:59 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-13 13:27:26 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] The domain dpd.xtrqplm.cfd has been assessed at an elevated risk level due to its classification as a generic phishing threat. This domain was designed to impersonate DPD (a parcel delivery service) to harvest login credentials and personal information from unsuspecting victims. The phishing campaign likely targeted users expecting package delivery notifications, exploiting trust in well-known logistics brands. Technical indicators confirm the malicious nature of this domain. VirusTotal reports 6 out of 95 security vendors flagging the domain as malicious. It resolves to IP address 172.67.208.105, which is associated with Cloudflare infrastructure. The domain was registered through Aceville Pte. Ltd., a registrar known for hosting questionable domains. Google Safe Browsing explicitly flags it for phishing. The SSL certificate was issued by Let's Encrypt (serial E7), providing a veneer of legitimacy. The domain is currently offline, suggesting it was taken down after detection. No creation date was provided, but the registration and observed activity indicate a short lifespan. To mitigate risks from generic phishing domains like this, users should avoid clicking links in unsolicited emails or messages, especially those requesting login credentials or personal data. Organizations should implement email filtering solutions that block known malicious domains and use web security gateways to prevent access. Users are advised to verify the legitimacy of package delivery notifications by visiting the official DPD website directly rather than following embedded links. Regular security awareness training can help users recognize phishing attempts, and reporting suspicious domains to threat intelligence platforms aids in broader takedown efforts. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 5c25dc4385fe5963f245c0f0dc98b4ca TLS cert SHA-256: b745bc477136d40efa00fd14c911ac4ac4f43aca7bf782ec36cc545c8e00c331 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/dpd.xtrqplm.cfd/ JSON API: https://api.destroy.tools/v1/check?domain=dpd.xtrqplm.cfd Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 169,696 domains (15,827 alive under monitoring, 153,516 confirmed takedowns/dead). Site: https://phishdestroy.io