Security Scan Report: objectstorage.ap-sydney-1.oraclecloud.com

Redirected to:
https://docu-sign.creativaplanning.com/
Submitted: Sep 15, 2026, 2:51:16 PMCompleted: Sep 15, 2026, 2:51:41 PMpubliccompleted

This website contacted 2 IPs in 2 countries across 2 domains to perform 3 HTTP transactions. The main domain is docu-sign.creativaplanning.com and was registered 17 years ago.

Submitted URL: https://objectstorage.ap-sydney-1.oraclecloud.com/n/sdl2lsmh7igo/b/Wire/o/paybonus.htm

Effective URL:

https://docu-sign.creativaplanning.com/
Redirected

The Cisco Umbrella rank of the primary domain is #4,295 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 72%

7
Risk Score

Redirects to docu-sign.creativaplanning.com, a non-DocuSign/non-Microsoft domain whose page claims 'Microsoft Outlook' — clear brand impersonation with a 74% phishing classifier hit and anti-analysis scripts.

Risk Factors (4)
Brand impersonation of DocuSign (subdomain) and Microsoft Outlook (page title) on a domain neither owns
ML content classifier: phishing scam 74%
Anti-analysis techniques and encoding/decoding inline script functions
Phishing-style lure page hosted in an object-storage bucket before redirect
Domain age information unavailable

Details

Page Title

502 Bad Gateway

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'objectstorage.ap-sydney-1.oraclecloud.com' is registered with subdomain 'objectstorage.ap-sydney-1'. The second-level label 'oraclecloud' is 11 characters long split between 5 vowels and 6 consonants. Word splitting yields two words: oracle, cloud. Average segment length settles at 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://objectstorage.ap-sydney-1.oraclecloud.com/n/sdl2lsmh7igo/b/Wire/o/paybonus.htm

Page Load Overview

2.07s
Total Load Time
7 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:17 chars
Detector Agreement:0%

Website Classification

Primary Category

phishing scam74% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

phishing scam
74%
documentation technical
68%
technology software
66%
adult content
43%
news media journalism
35%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2172.232.140.122Stockholm, Stockholm County, Sweden
AS63949Akamai Connected Cloud
1134.70.92.3Oracle · CLOUDBungarribee, New South Wales, Australia
AS31898Oracle Corporation
32--

Detected Technologies1

40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EFC142482181219415FB6338A79BA100FFBF512BAB05C4847E8D97492F71C75A973FDB

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:t2p87Pi0QSYXLFwK8snU1rmsH/TYJCCmO3MFv8N3:C87P3KYrV0JvmOcO3

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5614:ABARGAASEVcQxzQgUAABZIVABEYgCkQFJEQGgQgBOAACAgQiQIiiABiIBACAUKFIFIQAiQ44OUEgIHAAJCCgIIYpQKAggpgI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3fffffffffffffff
Perceptual Hash:87070f0f0f0f0f1f
Difference Hash:c000000000000000
Wavelet Hash:30f0f0f000000000
Color Hash:#e0ad6c

Other Hashes

Crop Resistant:c000000000000000

Scan History

Scan history not available

Unable to load historical scan data