Security Scan Report: excel-wckzlrncpezehnnlwwfywfdw.pages.dev

Redirected to:
https://www.dhl.com/de-de/home.html?locale=true
Submitted: Apr 18, 2026, 9:11:07 AMCompleted: Apr 18, 2026, 9:12:23 AMpubliccompleted
Loading additional data...

Summary

This website contacted 3 IPs in 2 countries across 3 domains to perform 3 HTTP transactions. The main domain is dhl.com and was registered NaN years ago.

Submitted URL: https://excel-wckzlrncpezehnnlwwfywfdw.pages.dev/

Effective URL: https://www.dhl.com/de-de/home.html?locale=trueRedirected

AI Security Verdict

Moderate Risk

Confidence: 88%

5
Risk Score

The pages.dev subdomain pretends to be DHL, uses heavily obfuscated JavaScript and triggers high‑severity IDS alerts; it is high‑risk brand impersonation.

Risk Factors
Brand impersonation via meta tags
Unranked / low‑reputation domain
Unknown subdomain age on hosting platform
High‑severity IDS alerts for script obfuscation
Critical JavaScript obfuscation
Safety Factors
Established domain (13477 days old) with no strong malicious indicators — risk clamped from 7 to 5
Domain age information unavailable

Details

Page Title

www.dhl.com

Scan Type

public

Language

🇩🇪

German

(80% confidence)

Category

corporate business

(99%)

Domain Information

You're looking at domain 'excel-wckzlrncpezehnnlwwfywfdw.pages.dev' on the developer-focused generic top-level domain (.dev); it also runs on subdomain 'excel-wckzlrncpezehnnlwwfywfdw'. The second-level label 'pages' is 5 characters long holding 2 vowels versus 3 consonants. It segments into 1 word: pages. Median word length comes out to five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://excel-wckzlrncpezehnnlwwfywfdw.pages.dev/

Page Load Overview

3.38s
Total Load Time
78
HTTP Requests
6
Domains
4.5 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:de
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:de-DE
Text Length:12,089 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business99% confidence
Type: spa
Method: ml+structural

All Detected Categories

corporate business
99%
finance banking
93%
government public service
78%
documentation technical
51%
blog personal website
51%

Detected Features

Search
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
26172.66.45.30United States
AS13335Cloudflare, Inc.
2623.67.136.227Frankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
26142.251.127.95Germany
783--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B1048F77329A063986558498F05B43099F20B143F506C9BCB9BCBAD9BFDED06107BB78

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:pfQho9PKBb9Js3q9Jzbs6tlg3SBKwdQWgceIszH2bMy8Oldv:ehoC9JSqzzbs6o3Sj3gcrsz2eA1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:184438:rwAEjHBIALwhE4AEhsiAgkBGaSYAsuUBC73iACGUDMJANoAIl0FhKDJEGwBsoR8MQMlgIYwUYxoGABzhkAF4QyZAowxZIQWE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcfc3cfffffffff
Perceptual Hash:b3318ccccc673333
Difference Hash:00180c1000000000
Wavelet Hash:fcdcc0cc00000000
Color Hash:#5b862d

Other Hashes

Crop Resistant:00180c1000000000

Scan History

Scan history not available

Unable to load historical scan data