MALICIOUS — HIGH
Phishing- und Sicherheitsprüfung für dhlvips.us.cc
dhlvips[.]
This domain, dhlvips.us.cc, is actively engaged in a delivery scam operation impersonating DHL, a global logistics provider.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- Verfügbarkeit
- Inhalt nicht verfügbar · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
dhlvips.us.cc — Inhalt nicht verfügbar (HTTP 502). Markenidentität: DHL; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 5/91 (alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar, Webroot); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Registrar: Gname.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain, dhlvips.us.cc, is actively engaged in a delivery scam operation impersonating DHL, a global logistics provider. The site presents itself as a legitimate parcel tracking or delivery notification portal, likely targeting users with fraudulent shipping alerts to harvest personal and financial information. As of the latest verification, the domain remains active and operational, continuing to pose a high risk to unsuspecting recipients of phishing messages. Analysis indicates the domain was registered on June 12, 2026, through Gname.com Pte. Ltd., a registrar frequently associated with malicious domains. It resolves to the IP address 43.159.142.248, which has been linked to other suspicious activities in recent threat intelligence reports. The domain is flagged by 5 of 95 security vendors on VirusTotal, a relatively low detection rate that may indicate evasion techniques or recent deployment. Additionally, it appears on one security blocklist and is blocked by at least one threat intelligence feed. Notably, the domain lacks an SSL certificate, a red flag for any site handling user data, particularly one impersonating a trusted brand. Infrastructure analysis reveals that dhlvips.us.cc leverages a subdomain under the .us.cc country-code second-level domain (ccSLD), a structure commonly abused for short-lived phishing campaigns. The absence of SSL encryption, combined with the recent registration date and low vendor detection, suggests the site may be part of a larger, rapidly rotating scam infrastructure. Organizations and individuals are advised to block the domain and its associated IP at the network level. End users should be trained to verify the authenticity of delivery notifications by cross-referencing tracking numbers directly with the official DHL website. Security teams are encouraged to monitor for related domains registered under the same registrar or resolving to the same IP range, as these may indicate further campaign expansion.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
VirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.