# PhishDestroy threat dossier — dhl-towcester.consultationonline.co.uk ================================================================ Fetched: 2026-07-21 08:17:36 UTC Canonical: https://phishdestroy.io/domain/dhl-towcester.consultationonline.co.uk/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: DHL ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 16/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Chong Lua Dao, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Kaspersky, Lionic, Netcraft, OpenPhish, SOCRadar, Sophos, VIPRE, Webroot URLQuery: 2 detections Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 64.227.37.136 (GB, Slough) ASN: AS14061 DigitalOcean, LLC Hosting org: DigitalOcean, LLC Registrar: 123-Reg Limited t/a 123-reg [Tag = 123-REG] Nameservers: ns15.domaincontrol.com, ns16.domaincontrol.com Registered: 2005-12-31 Expires: 2026-12-31 HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YR2 Expires: 2026-09-11 Status: INVALID chain Fingerprint: d81d9dafa092f3f445d00d7dcdbc19d7f8445c69d59a775ff227f3c6fe6733cb Subject Alternative Names (related infrastructure — often same operator): - consultationonline.co.uk ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2005-12-31 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-19 17:05:31 UTC (by PhishDestroy tracker) First reported: 2026-07-19 15:08:39 UTC (abuse notice filed) Last verified: 2026-07-21 08:20:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019f7ae7-5e07-750a-8418-f3ddae662340/ URLQuery: https://urlquery.net/report/fa496e15-8cf3-4803-9514-85addecd17ca Wayback Machine: https://web.archive.org/web/*/dhl-towcester.consultationonline.co.uk crt.sh CT logs: https://crt.sh/?q=%25.dhl-towcester.consultationonline.co.uk Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=dhl-towcester.consultationonline.co.uk AlienVault OTX: https://otx.alienvault.com/indicator/domain/dhl-towcester.consultationonline.co.uk URLhaus: https://urlhaus.abuse.ch/host/dhl-towcester.consultationonline.co.uk/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-19 17:07:19 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] Is dhl-towcester.consultationonline.co.uk a Delivery Scam? Analysis indicates that the domain dhl-towcester.consultationonline.co.uk is currently active and associated with a high‑risk delivery‑scam campaign. The domain was registered on 31 December 2005 through 123‑Reg Limited and resolves to the IPv4 address 64.227.37.136. Its authoritative name servers are ns15.domaincontrol.com and ns16.domaincontrol.com. Independent threat intelligence sources have flagged the domain: PhishDestroy has placed it on its blocklist and it appears on one additional security blocklist. VirusTotal scans show that 15 of 95 scanning engines flagged the domain as malicious, reinforcing the suspicion of abusive use. The available data do not include a content analysis of the hosted site, so the exact delivery‑scam tactics, malicious payloads, or credential‑harvesting mechanisms remain unconfirmed. Consequently, defenders cannot describe the specific user‑interaction flow, but the presence of multiple detections and the high‑risk rating suggest active exploitation. Defensive actions should include adding the domain and its resolving IP address to network‑level denylists, configuring email gateways to quarantine messages containing URLs that resolve to 64.227.37.136, and enabling DNS sink‑holing for the associated name servers. Continuous monitoring of DNS query logs for lookups to ns15.domaincontrol.com or ns16.domaincontrol.com can help detect compromised hosts. Given the high risk, organizations should treat any communication referencing DHL or other courier services that directs users to this domain as malicious until proven otherwise. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260719-953476 Favicon MD5: d8106bf3a1d00ab43b01e6e3c92500eb TLS cert SHA-256: d81d9dafa092f3f445d00d7dcdbc19d7f8445c69d59a775ff227f3c6fe6733cb ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/dhl-towcester.consultationonline.co.uk/ JSON API: https://api.destroy.tools/v1/check?domain=dhl-towcester.consultationonline.co.uk Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 187,503 domains (57,608 alive under monitoring, 128,244 confirmed takedowns/dead). Site: https://phishdestroy.io