Security Scan Report: dpd-ptrest.cfd

Site favicon
Submitted: Dec 11, 2025, 12:42:08 AMCompleted: Dec 11, 2025, 12:43:28 AMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 2 countries across 2 domains to perform 52 HTTP transactions. The main domain is dpd-ptrest.cfd and was registered NaN years ago.

Submitted URL: https://dpd-ptrest.cfd/ptr

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed phishing scam impersonating DPD; report and do not use the site.

Risk Factors
Malicious Indicators of Compromise match
Google Safe Browsing social engineering detection
Brand impersonation of a well‑known courier (DPD)
Domain age less than 7 days (critical)
Unranked domain in Cisco Umbrella
Domain age information unavailable

Details

Page Title

DPD - Envio de encomendas para clientes empresariais e particulares » DPD

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate business

(36%)

Domain Information

Domain 'dpd-ptrest.cfd' uses the .cfd top-level domain without a subdomain. The second-level label 'dpd-ptrest' is 10 characters long split between one vowel and eight consonants, plus 1 hyphen. Word splitting yields 4 words: d, pd, pt, rest. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dpd-ptrest.cfd/ptr

Page Load Overview

10.99s
Total Load Time
52
HTTP Requests
2
Domains
2.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:80 chars
Detector Agreement:67%

Website Classification

Primary Category

corporate business36% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

corporate business
36%
phishing/scam
20%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12104.18.180.27United States
AS13335CLOUDFLARENET
1043.165.197.107Jakarta, Jakarta, Indonesia
AS132203Tencent Building, Kejizhongyi Avenue
10104.18.181.27United States
AS13335CLOUDFLARENET
102606:4700::6812:b41bUnited States
AS13335CLOUDFLARENET
102606:4700::6812:b51bUnited States
AS13335CLOUDFLARENET
525--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T132E3437174A1111B0A7BD0CB62AD750B1613FA0FD626CDCE715CA2284FDEAAF34E2749

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:N6H0RhAsTFwOjf1duCifuRfhcwj2YRtQkor/xBbp5FGYCyqZJBiO4j:NY0RhAsTFwOjf1dlifuRfhcwj2YRtQkM

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:151986:JIAEiIYocEPQEgVgiEEU1cMAgaTBKiBFQCQIABhmiAVyhgUIKAYBwBzyGA4hXCEPCFnhDBh7AgEIABgUUeAAoCCK0BCDLbrG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:efc7efffe7e70000
Perceptual Hash:b3b109a6ccccce4e
Difference Hash:1c9e1e1a0e0c331b
Wavelet Hash:c7c3c7efe7c70000
Color Hash:#9d53ac

Scan History

Scan history not available

Unable to load historical scan data