Security Scan Report: parcelcourierline.com

Submitted: Oct 1, 2026, 1:04:09 PMCompleted: Oct 1, 2026, 1:04:48 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 85%

9
Risk Score

Compromised courier site serving a ClearFake/EtherHiding malware kit: critical IDS alerts for EtherHiding exfiltration, blockchain RPC C2 calls, and a fake Cloudflare 'verification' that tells users to run a command. Do not interact.

Risk Factors (6)
Critical network IDS alerts for EtherHiding malware exfiltration (x4)
Fake Cloudflare verification prompting Windows-key + clipboard command execution
Loaded blockchain RPC resources flagged as ClearFake malware by multiple threat feeds
Content copied from unrelated courier/moving businesses
Domain unranked in Cisco Umbrella with no genuine reputation
Human-verification text framed as anti-bot check that actually pushes a terminal command
Domain age information unavailable

Details

Page Title

PARCEL COURIER LINE | Ultimate Shipping Logistic Cargo express

Scan Type

public

Domain Name Analysis

You're looking at domain 'parcelcourierline.com' on the commercial generic top-level domain (.com) without a subdomain. Count 17 characters in 'parcelcourierline' split between eight vowels and 9 consonants. Tokenizing the label suggests three words: parcel, courier, line. Median word length comes out to 6 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://parcelcourierline.com/

Page Load Overview

1.43s
Total Load Time
648 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,949 chars
Detector Agreement:75%

Website Classification

Primary Category

government public service37% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

government public service
37%

Detected Features

Search
Articles

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
11144.76.97.27Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
4152.236.9.75Frankfurt am Main, Hesse, Germany
AS396356Latitude.sh
4104.26.1.115Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4172.67.73.221Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.26.0.115Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.20.38.203Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4132.145.155.63Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
4178.16.52.101Frankfurt am Main, Hesse, Germany
AS202412Omegatech LTD
439--

Detected Technologies11

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T195241A8F5BB5327472138799F9D5771887BCC123ED1218EA79B2814ECBC2B92117262F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:4ZNVAR9WQDr4kQ7wgrdczE7o7eAp1a4pLXP7uEZIVopRo1yiHEPPCG:RR9Hr4kQS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:212501:CgzAJgTBGIYwaAkJCGKAUIDQsMwBDIIg0QBh0kwohtE3QE6giwYEUgxhJCAFEoCEDiBYQQ89dlARgd9IgnEFJ9ASABDFgIUC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fff8e0f1ddfd9881
Perceptual Hash:dac0358a3d2d7336
Difference Hash:22e1092129c9797f
Wavelet Hash:fff0e0e0ddfc8080
Color Hash:#e06c79

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data