dpd[.]mqtrplxzvn[.]cloud
“dpd.mqtrplxzvn.cloud”
Kanıt özeti
PhishDestroy has identified dpd.mqtrplxzvn.cloud as a malicious phishing domain targeting users of the parcel delivery service DPD. This domain is part of a broader campaign that uses deceptive landing pages to harvest sensitive personal and financial information. No specific drainer kit was identified, but the site's design and behavior are consistent with credential theft.
The domain has a VirusTotal detection rate of 10 out of 95 security vendors, indicating significant malicious consensus. It was registered through Dominet (HK) Limited and resolves to the IP address 188.114.97.3, hosted on Cloudflare infrastructure. The domain was created on May 27, 2026, a remarkably recent date that underscores its transient nature. Google Safe Browsing flags the site as phishing, and it appears on at least one security blocklist. Notably, the domain lacks an SSL certificate, which is a common red flag for phishing sites.
As of the latest check, dpd.mqtrplxzvn.cloud is offline. This takedown may be the result of a hosting provider suspension, registrar intervention, or law enforcement action. However, given the short lifespan and rapid registration, the threat actors likely have multiple similar domains ready for deployment. Users who may have visited the site are advised to change passwords and monitor accounts for suspicious activity. PhishDestroy recommends avoiding interaction with unsolicited delivery notifications and verifying tracking URLs through official DPD channels.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260529-2A0B0A- Yakalanan sayfa başlığı
- dpd.mqtrplxzvn.cloud/com/
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
AUP Section 3: The domain dpd.mqtrplxzvn.cloud is engaged in phishing activities, which directly contravenes your Acceptable Use Policy prohibiting illegal activities and fraud.
TOS Section 5: The use of this domain for deceptive practices violates your Terms of Service, which reserves the right to suspend or terminate services for such violations.
AUP Section 4: The distribution of malware through this domain constitutes a breach of your policy against harmful content, further justifying immediate action.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): Prohibits unauthorized access and fraud in connection with computers and networks.
Wire Fraud Statute (18 U.S.C. § 1343): Criminalizes schemes to defraud individuals or entities via electronic communications.
CAN-SPAM Act (15 U.S.C. § 7701): Regulates commercial email and prohibits deceptive practices in electronic communications.
Regulatory Note: Failure to take appropriate action against this domain may expose your organization to legal liability and regulatory scrutiny. Immediate compliance with your AUP and TOS is strongly advised.
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | dpd.mqtrplxzvn.cloud |
phishing | Phishing Block |
| Hagezi Threat Feed | dpd.mqtrplxzvn.cloud |
malicious | Sinkholed |
| Quad9 DNS | dpd.mqtrplxzvn.cloud |
malicious | Sinkholed |
| DNS4EU | dpd.mqtrplxzvn.cloud |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: mqtrplxzvn.cloud
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain mqtrplxzvn.cloud behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
2 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin