mta[.]sspl[.]com[.]au
“Index of /”
Résumé des preuves
On July 23, 2026, analysis of the domain mta.sspl.com.au revealed a high‑risk brand‑impersonation campaign that masquerades as Google. The domain is registered through Web Address Registration Pty Ltd and uses the authoritative nameservers ns1.vodien.com, ns2.vodien.com and ns3.vodien.com. DNS resolution points to the IPv4 address 185.184.154.169, which belongs to AS38719 Dreamscape Networks Limited based in Australia. An HTTPS service is presented using a Let’s Encrypt R12 certificate, and an HTTP GET request returns a 200 status code with the page title “Index of /”, indicating an open directory listing rather than a crafted login page.
VirusTotal reports that 13 of 95 security vendors have flagged the domain, and it appears on one public blocklist. Google Safe Browsing classifies the site as a social‑engineering threat, and the PhishDestroy service has already blocked it. Gridinsoft assigns a trust score of 0 out of 100, underscoring the malicious nature of the infrastructure. The site’s current status is offline, but the observed indicators suggest that the operators can reactivate the domain or duplicate the setup on similar infrastructure.
Defenders should continue to block the domain and its associated IP address at perimeter filters, ensure that any internal DNS resolvers deny queries for this name, and monitor for re‑registration or similar sub‑domains using the same nameserver set. Additional scrutiny of outbound connections to Dreamscape Networks’ address space is advisable. Because only the directory index has been observed, the exact phishing payload remains unknown; analysts should treat any future content served from the domain as potentially malicious and apply standard credential‑theft mitigations. Continuous threat‑intel sharing with platforms such as PhishDestroy and Google Safe Browsing will help maintain up‑to‑date defenses.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
13 → 14
-
VirusTotal
14 → 12
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of mta.sspl.com.au · checked Mar 2, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif