VirusTotal
13 / 91
“Sign In.”
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | mail-jdhlilinlink.appwrite.network/ |
malware | Detects file containing Telegram Bot API |
| YARAhub by abuse.ch | mail-jdhlilinlink.appwrite.network/favicon.ico |
malware | Detects file containing Telegram Bot API |
| Cloudflare DNS | mail-jdhlilinlink.appwrite.network |
malicious | Sinkholed |
| OpenDNS | mail-jdhlilinlink.appwrite.network |
phishing | Phishing Block |
| DNS4EU | mail-jdhlilinlink.appwrite.network |
malicious | Sinkholed |
| Hagezi Threat Feed | mail-jdhlilinlink.appwrite.network |
malicious | Sinkholed |
This domain, mail-jdhlilinlink.appwrite.network, poses a credential harvesting threat by impersonating DHL, a global logistics provider. Visitors to the site encounter a fraudulent login page titled 'Sign In,' designed to deceive users into submitting sensitive account details such as usernames, passwords, or shipment tracking credentials. The site exploits trust in the DHL brand to facilitate unauthorized access to personal or corporate data, potentially leading to financial fraud or identity theft. Analysis indicates the domain was registered on March 12, 2026, through the Appwrite registrar and resolves to the IP address 151.101.131.52, hosted on infrastructure belonging to AS54113 (Fastly, Inc.) in the United States. The SSL certificate is issued by Certainly, a provider commonly used for both legitimate and malicious domains. Detection engines on VirusTotal flagged the domain as malicious, with 20 out of 95 security vendors identifying it as a phishing site. Additionally, the domain appears on one security blocklist, further confirming its malicious intent. If you or someone in your organization visited mail-jdhlilinlink.appwrite.network and entered credentials, immediate action is required. First, reset the password for any accounts accessed through the site, using a strong, unique password not reused elsewhere. Enable multi-factor authentication where available to add an extra layer of security. Monitor accounts for unauthorized activity, such as unexpected shipments, password changes, or financial transactions. If payment details were submitted, contact your financial institution to report potential fraud and request a card replacement. Finally, report the incident to your organization’s IT or security team for further investigation and mitigation.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
swoole-http-serverScanner note: alive_content: raw=short_403; http=403; via=https_proxy; server=swoole-http-server
For the registrable domain appwrite.network behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
fastly.appwrite.systemsLocation describes the IP network.
ab4fe143debe5caf2b0aa57ac75528529aeb3af669856693135c7cb3a266e788appwrite.networkimagine.diySaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of mail-jdhlilinlink.appwrite.network · checked Apr 23, 2026
7 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Reported by 1 community member, first seen Mar 12, 2026
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive