test[.]dhl-express-ppd[.]infanion[.]com
“Login | DHL Express RPA portal”
test.dhl-express-ppd.infanion.com — Неперевірений. Уособлення бренду: DHL; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLScan malicious verdict; PhishDestroy score 95/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of test.dhl-express-ppd.infanion.com indicates the domain is currently offline and was created on 21 February 2026. The domain resolves to the IP address 52.19.172.57, which is assigned to AS16509 operated by Amazon.com, Inc. and geolocated to Ireland. Registration was performed through GoDaddy.com, LLC and the authoritative name servers are ns67.domaincontrol.com and ns68.domaincontrol.com. An active TLS certificate issued by Let’s Encrypt (E6) is present, confirming that HTTPS connections were available before the offline status.
The web server returned HTTP 502, and the page title captured was "Login | DHL Express RPA portal", matching the declared brand target DHL. Technology fingerprinting identified Drupal, PHP, Ubuntu, Bootstrap, Nginx, Slick, reCAPTCHA and jQuery, suggesting a typical content‑management stack. VirusTotal reports 16 of 93 scanners flagging the domain, demonstrating moderate detection across security vendors. The domain is listed on one public blocklist and has been actively blocked by PhishDestroy.
Taken together, the evidence supports a brand‑impersonation campaign aimed at harvesting DHL credentials. Uncertainty remains regarding the specific phishing payload, command‑and‑control infrastructure, or any exfiltration activity, as no additional intelligence such as OTX tags or Safe Browsing entries are available. Defenders should add the domain and its associated IP address to blocklists, enforce DNS sink‑hole rules, monitor for traffic to the IP range owned by Amazon in Ireland, and inspect any outbound connections from internal users that attempt TLS handshakes with the Let’s Encrypt certificate fingerprint. Continuous re‑scanning of the domain is recommended in case it becomes active again.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: infanion.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain infanion.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 8 identified
Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com 100% впевненостіBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% впевненостіNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіreCAPTCHA is a free service from Google that helps protect websites from spam and abuse.
www.google.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога