Security Scan Report: dhofareng.com

Submitted: Sep 17, 2026, 12:45:13 PMCompleted: Sep 17, 2026, 12:46:05 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Fake DocuSign 'e-sign' page on dhofareng.com luring users to download a Windows executable disguised as a document attachment; CRITICAL IDS PE/EXE download alerts confirm malware delivery. Avoid; report.

Risk Factors
DocuSign brand impersonation on non-official domain dhofareng.com
Serves a Windows executable download disguised as a document attachment (utility.php)
CRITICAL IDS alert for PE EXE/DLL Windows file download
Packed executable download indicating an intentionally obfuscated payload
Unranked domain with no legitimate reputation or business presence
Domain age information unavailable

Details

Page Title

e-sign

Scan Type

public

Domain Name Analysis

You're looking at domain 'dhofareng.com' on the commercial generic top-level domain (.com) and has no subdomain. The registrable portion 'dhofareng' spans 9 characters containing 3 vowels alongside 6 consonants. Breaking it apart gives 4 words: dh, of, are, ng. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://dhofareng.com/docusign/Windows/utility.php

Page Load Overview

0.43s
Total Load Time
167 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:100 chars
Detector Agreement:100%

Website Classification

Primary Category

download file sharing43% confidence
Type: static
Method: ml+structural

All Detected Categories

download file sharing
43%
documentation technical
38%
healthcare medical
33%
e-commerce shopping
30%
government public service
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
291.204.209.18United Kingdom
AS52148Enix Ltd
21--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T14854123157813DBB583CCA8C71D13E842ED8DECFC6B8524535F5A0E282EE752ADB1259

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:6Edo2Cp6Edo2Cp9UNuO+L6qFnxw7Ap27rpZioq:6Edo2Cp6Edo2Cp9UNuODqFnqkp27rpZS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:302759:hxJAEYAkggSKEIoGiEA5ggEHGAEBACBKpoIiRQMdAMQ8h9BMptsAfmCQOopEBbeOGnAIqDsACChMkCAACQYNFBEkDRBBagQD

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffcfc383c7ffff
Perceptual Hash:b8c7c7386cc73838
Difference Hash:80009d1eb79d002c
Wavelet Hash:00cf87838387ff07
Color Hash:#d22da1

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data