Security Scan Report: www.geotehnica.com

Submitted: Sep 18, 2026, 12:45:13 PMCompleted: Sep 18, 2026, 12:45:35 PMpubliccompleted

This website contacted 3 IPs in 3 countries across 3 domains to perform 7 HTTP transactions. The main domain is geotehnica.com and was registered 16 years ago.

Submitted URL: https://www.geotehnica.com/docusignreader/e-sign.php

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Compromised geotehnica.com hosts a fake DocuSign e-signature page pushing a malicious 'attachment' download; corroborated phishing IoC. Avoid and report.

Risk Factors (4)
Brand impersonation of DocuSign on an unrelated third-party domain
Multi-source corroborated phishing threat-intelligence match against the primary domain
Social-engineering download lure delivering an 'attachment' rather than any real signature flow
Legitimate but unrelated established domain apparently repurposed/compromised for phishing
Domain age information unavailable

Details

Page Title

e-sign

Scan Type

public

Domain Name Analysis

Domain 'www.geotehnica.com' uses the commercial generic top-level domain (.com) and includes subdomain 'www'. The second-level label 'geotehnica' is 10 characters long holding 5 vowels versus 5 consonants. Segmentation suggests three words: geo, teh, nica. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.geotehnica.com/docusignreader/e-sign.php

Page Load Overview

0.65s
Total Load Time
231 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:100 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing50% confidence
Type: static
Method: ml+structural

All Detected Categories

download file sharing
50%
documentation technical
42%
government public service
38%
healthcare medical
37%
news media journalism
32%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
394.26.91.102Bulgaria
AS48452Telco power Ltd
2142.251.14.94Google · CDNUnited States
AS15169Google LLC
245.43.142.5United Kingdom
AS16276OVH SAS
73--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T103D1944387A343795C0A816C5BF12504306AC817E078E9F43FDF1595EF4E9E068AA7DE

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:N9S2fsVcOgyExA9vzp9wRp6kU+RvVa2HMpl:N5U4vVa2c

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6622:DCKCCowAIECEEAiARAEMIDSgggAmAwgACUweCACAkGsDKgBYFTBAEg6ABCgCAAMQAPkBrwDAAwjEFBVYgUAgACGwJIkBGEFg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffcfc383c7ffff
Perceptual Hash:b8c7c7386cc73838
Difference Hash:80009d1eb79d002c
Wavelet Hash:00cf87838387ffc3
Color Hash:#a179d2

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data