EN ES PT
Back to Stats

Visual Capture

Screenshot of dhl-presentation.com

Detection Info

https://dhl-presentation.com/setup/
Detected Brand
DHL
Country
International
Confidence
100%
HTTP Status
200
Report ID
17e31285-9ed…
Analyzed
2026-01-26 00:11

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T19B22953023441E3E5A2BC698F6A4B31E619BE388D62F915CE2AF027557C7D82DC375D8
CONTENT ssdeep
192:HSB6lsI1nqPDSMsP2F+7eezgXRwXCCY/1Y2hCYOSsNu:HSUls5L+gXRwXCCYtYXYr

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9b4d34326d98c667
VISUAL aHash
000c3c3c203c1c00
VISUAL dHash
0448405042793902
VISUAL wHash
103c3c3c3c3c3c30
VISUAL colorHash
38006000018
VISUAL cropResistant
0448405042793902

Code Analysis

Risk Score 76/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: DHL phishing targeting account access.
• Target: DHL users.
• Method: Fake license and access path request.
• Exfil: Likely credentials and potentially other data to unknown endpoint.
• Indicators: Non official website URL, recent domain, obfuscation detected and javascript form submission detected.
• Risk: HIGH - Credentials theft.

🔒 Obfuscation Detected

  • fromCharCode
  • unicode_escape

🎯 Kit Endpoints

  • /login

📡 API Calls Detected

  • https://t.me/zephyrscamasupportbot

📊 Risk Score Breakdown

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester, OTP Stealer, and Personal Info harvesting kits targeting DHL users.
High Obfuscation
17 obfuscation techniques detected in JavaScript files, indicating evasion of static analysis.
Brand Impersonation
Domain and content impersonate DHL, a high-value logistics brand, increasing trust exploitation.
Suspicious Form Fields
Form fields labeled 'Votre licence' and 'Chemin d'accès' suggest credential harvesting for unauthorized access.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
DHL users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
HIGH - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 17 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
DHL
Official Website
https://www.dhl.com
Fake Service
Account verification or license validation

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The phishing kit captures user credentials through fake form fields ('Votre licence', 'Chemin d accès'). Data is likely exfiltrated via HTTP POST requests to a command-and-control server.

Secondary Method: OTP Stealer

The kit includes functionality to intercept one-time passwords (OTPs), enabling attackers to bypass multi-factor authentication on compromised accounts.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
dhl-presentation.com
Registered
2026-01-23 14:26:06+00:00
Registrar
Hosting Concepts B.V. d/b/a Registrar.eu
Status
Recently registered (2 days old)

🦠 Malicious Files

Main File
File Size

Obfuscated JavaScript files containing credential harvesting and OTP interception logic.

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
836.1 KB

🔗 API Endpoints Detected

Other
30

🔐 Obfuscation Detected

  • : Moderate
  • : Light
  • : Moderate
  • : Light
  • : None
  • : Light
  • : Light
  • : Light
  • : None
  • : Light
  • : Light
  • : Light
  • : Moderate
  • : Light
  • : None

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.