EN ES PT
Back to Stats

Visual Capture

Screenshot of dhlsiprod.eu23.smartcommunications.cloud

Detection Info

https://dhlsiprod.eu23.smartcommunications.cloud/produce/home
Detected Brand
DHL
Country
International
Confidence
100%
HTTP Status
200
Report ID
06e13123-b1a…
Analyzed
2025-12-31 18:40
Final URL (after redirects)
https://dhlsiprod.eu23.smartcommunications.cloud/produce/Account/Login?ReturnUrl=%2Fproduce%2Fhome

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1B141B7B0E0384C63019296F4B3C4570A64C5D21FC7821D00A2FC9BE893FFC52ED79858
CONTENT ssdeep
24:nl8CiQ4tKonEnobcoEDcomCh7BK6jHWAPnpV3BsYEiK3r+hHc7VD8q04Dr+k1OWW:nb4UFnKc3cJC1PnJsBiKbTJgyii2H5j5

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
d884a64d7e94b569
VISUAL aHash
7f7d7d5c484868e0
VISUAL dHash
c1d1919199909199
VISUAL wHash
7f7d7d5c484848e0
VISUAL colorHash
0ee00010000
VISUAL cropResistant
c1d1919199909199,36396cc8c8989a6c,d3e1c1c5013379dd,27222381899923e3,1a1a1b1f0f8f8703,c3c38f4fe7b57575

Code Analysis

Risk Score 73/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing
• Target: DHL customers
• Method: Fake DHL login page stealing usernames and passwords.
• Exfil: Unknown, likely a custom API or a compromised server.
• Indicators: Domain name doesn't match the official DHL domain, presence of a login form, use of 'fromCharCode' obfuscation.
• Risk: HIGH - Credentials theft.

🔒 Obfuscation Detected

  • fromCharCode
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.