Security Scan Report: dhofareng.com

Redirected to:
https://dhofareng.com/cgi-sys/suspendedpage.cgi
Site favicon
Submitted: Sep 17, 2026, 1:45:07 PMCompleted: Sep 17, 2026, 1:45:32 PMpubliccompleted

This website contacted 3 IPs in 2 countries across 2 domains to perform 6 HTTP transactions. The main domain is dhofareng.com and was registered 13 years ago.

Submitted URL: https://dhofareng.com/docusign/

Effective URL:

https://dhofareng.com/cgi-sys/suspendedpage.cgi
Redirected

AI Security Verdict

Moderate Risk

Confidence: 55%

4
Risk Score

Suspended cPanel page on a low-reputation domain; the /docusign/ path hints at prior phishing staging, but the live page has no forms, scripts, or threat-intel hits. Treat as untrusted and avoid re-use.

Risk Factors
Brand-adjacent directory name (/docusign/) on a domain unrelated to DocuSign suggests prior abuse or phishing staging
Domain has no reputation in Cisco Umbrella top 1M and very low business legitimacy signals
Safety Factors
Currently serving a hosting-provider suspension page with no forms, scripts, or credential collection
No Indicators of Compromise, YARA malware, Safe Browsing, or IDS phishing/malware alerts
No cross-origin form submissions or credential exfiltration detected
Domain is roughly 6 months old rather than freshly registered
Domain age information unavailable

Details

Page Title

Account Suspended

Scan Type

public

Domain Name Analysis

The domain name 'dhofareng.com' uses the commercial generic top-level domain (.com) while skipping any subdomain. Count 9 characters in 'dhofareng' split between 3 vowels and 6 consonants. Splitting it apart reveals four words: dh, of, are, ng. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dhofareng.com/docusign/

Page Load Overview

1.20s
Total Load Time
54 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:58%
Script:Latin
Direction:ltr

Detection Details

Text Length:120 chars
Detector Agreement:100%

Website Classification

Primary Category

adult content40% confidence
Type: static
Method: ml+structural

All Detected Categories

adult content
40%
finance banking
36%
news media journalism
33%
cryptocurrency blockchain
27%
government public service
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
291.204.209.18United Kingdom
AS52148Enix Ltd
2172.67.142.245Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.21.27.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
63--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D4F1F9AB2AF3000B740712E87ABE3216AB59A543911ACD617F4DF6E9CF97980CC4375D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:ylVZHCkA26xd3Q4JRveuTtMy47R/Ga0kVhFuPwf8Pn9wHHyJPB:mJvVGaRF8I8R

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7619:kGACPCIhIJIwpDUGcmEjCAMiAmCEEICESIgIII4CJoAqNFAAeA0gMYF5BFCgAi0KMqGQUECMIzDBgGhEEEAE4UhrCEQCZlIG

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0000ffffffffff
Perceptual Hash:e767878e989c3c18
Difference Hash:7848003000000000
Wavelet Hash:070000cf0f0f0f0f
Color Hash:#53ac80

Scan History

Scan history not available

Unable to load historical scan data