Security Scan Report: dhofareng.com

Redirected to:
https://dhofareng.com/docusign/Mac/utility.php
Submitted: Sep 17, 2026, 12:45:03 AMCompleted: Sep 17, 2026, 12:45:27 AMpubliccompleted

This website contacted 1 IP in 1 country across 1 domain to perform 3 HTTP transactions. The main domain is dhofareng.com and was registered 6 months ago.

Submitted URL: https://dhofareng.com/docusign/Mac/visit.php

Effective URL:

https://dhofareng.com/docusign/Mac/utility.php
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Fake DocuSign e-sign page on dhofareng.com using DocuSign branding and a download-attachment lure to push a malicious file. Brand impersonation confirmed; avoid and report.

Risk Factors
Impersonation of DocuSign brand on a non-official domain
Downloadable-attachment lure consistent with malware/phishing delivery
Unranked domain with negligible legitimacy signals
Fake e-signature/document-completion workflow
Domain age information unavailable

Details

Page Title

e-sign

Scan Type

public

Domain Name Analysis

Domain 'dhofareng.com' uses the commercial generic top-level domain (.com) and has no subdomain. The registrable portion 'dhofareng' spans 9 characters containing three vowels alongside six consonants. It segments into four words: dh, of, are, ng. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dhofareng.com/docusign/Mac/visit.php

Page Load Overview

0.59s
Total Load Time
167 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:100 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing43% confidence
Type: static
Method: ml+structural

All Detected Categories

download file sharing
43%
documentation technical
38%
healthcare medical
33%
e-commerce shopping
30%
government public service
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
391.204.209.18United Kingdom
AS52148Enix Ltd
31--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14854123157813DBB583CCA8C71D13E842ED8DECFC6B8524535F5A0E282EE752ADB1259

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:6Edo2Cp6Edo2Cp9UNuO+L6qFnxw7Ap27rpZioq:6Edo2Cp6Edo2Cp9UNuODqFnqkp27rpZS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:302759:hxJAEYAkggSKEIoGiEA5ggEHGAEBACBKpoIiRQMdAMQ8h9BMptsAfmCQOopEBbeOGnAIqDsACChMkCAACQYNFBEkDRBBagQD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffcfc383c7ffff
Perceptual Hash:b8c7c7386cc73838
Difference Hash:80009d1eb79d002c
Wavelet Hash:00cf87838387ff07
Color Hash:#b3e06c

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data