Security Scan Report: dhl-express-ehbspqjtxsxuinvlneecpfzo.pages.dev

Site favicon
Submitted: May 16, 2026, 2:00:43 PMCompleted: May 16, 2026, 2:02:36 PMpubliccompleted

Summary

This website contacted 4 IPs in 2 countries across 3 domains to perform 17 HTTP transactions. The main domain is dhl-express-ehbspqjtxsxuinvlneecpfzo.pages.dev and was registered 6 years ago.

Submitted URL: http://dhl-express-ehbspqjtxsxuinvlneecpfzo.pages.dev/

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Page impersonates DHL, collects credentials, and triggers multiple high‑severity phishing IDS alerts – confirmed scam.

Risk Factors
Brand impersonation of DHL
Credential harvesting form
High‑severity phishing IDS alerts
Unranked domain on shared‑hosting subdomain
Obfuscated HTML/JavaScript patterns
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

other

(90%)

Domain Information

Domain 'dhl-express-ehbspqjtxsxuinvlneecpfzo.pages.dev' uses the developer-focused generic top-level domain (.dev), featuring subdomain 'dhl-express-ehbspqjtxsxuinvlneecpfzo'. Its registrable label 'pages' stretches across 5 characters split between two vowels and three consonants. It segments into one word: pages. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://dhl-express-ehbspqjtxsxuinvlneecpfzo.pages.dev/

Page Load Overview

N/A
Total Load Time
17
HTTP Requests
3
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:652 chars
Detector Agreement:100%

Website Classification

Primary Category

other90% confidence
Type: webapp
Method: ml+structural

All Detected Categories

other
90%
legitimate website
42%
e-commerce
38%
malicious
33%
suspicious phishing
33%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5157.180.198.140Germany
AS41961Siemens Digital Logistics GmbH
4194.153.114.214Germany
AS41961Siemens Digital Logistics GmbH
423.67.136.227Frankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
4172.66.47.24Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
04--

Page Statistics

0
Requests
0
Unique Domains
0.0 KB
Total Size

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D482652480F90936510384D47AF1AA0A2F51DA0FCA4B691977FC4BE49FDBEC6CC4736A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:18GQe0uvbY0bE9dbuDBmNVZm08OVBMXZsKsfs/sMZufhGU4ANIzurK:0YEVAU4gI7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:18655:GhjkgqCSBllqrGBLQGxBwBAISgKRuaFLAqyCuYPFAAAhCREA0/TUE2CoDNdCMgMgbnQBMUMkArQzyAlARQ0y1EyBhgAQiqAw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000000000000000
Perceptual Hash:a288882222888822
Difference Hash:0000000000000000
Wavelet Hash:3c3c3c24e4fcf0f0
Color Hash:#2d3dd2

Other Hashes

Crop Resistant:0000000000000000

Scan History

Scan history not available

Unable to load historical scan data