escehrgroup.com
Categoria: Phishing
Per usare il prodotto con tutte le funzionalità, devi acquistare una licenza di Combo Cleaner. È disponibile una prova gratuita limitata di sette giorni. Combo Cleaner è di proprietà e gestito da RCS LT, la società madre di PCRisk.com.
Descrizione di escehrgroup.com
The domain escehrgroup.com appears to present a document-themed landing page styled to resemble a DocuSign workflow, with prompts to verify identity through Microsoft before viewing a file labeled "ACH_INCOMING_PAYMENT.pdf." Based on the screenshot and the domain name, the site does not appear to represent an established corporate homepage or a normal business website for an "HR group"; instead, it appears to be a single-purpose page designed to funnel visitors into an account-verification flow.
Available classification data associates this domain with phishing and fraud-related activity rather than a legitimate business service. The page branding references well-known third-party services, but the domain itself does not appear to be an official DocuSign or Microsoft property. At the time of this scan, no clear evidence was provided that the site is operated by the brands shown on the page.
Valutazione sicurezza di escehrgroup.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, and several web-classification providers categorized it as phishing, fraud-related, or malware-associated. The screenshot also shows a credential-style verification flow that references DocuSign and Microsoft on a newly registered, unrelated domain, which is a common pattern seen in account-harvesting campaigns.
Additional context increases concern: the domain age is 0 days, it has no established traffic ranking, and the page appears focused on getting the visitor to continue to a Microsoft-branded verification step in order to access a supposed payment document. While one malware scan did not detect malicious files on the page itself and some blacklist sources were clean, those signals do not outweigh the broader phishing indicators and the strong multi-engine consensus.
Based on these findings, this website may pose potential risks to visitors.
Descrizione tecnica
The site was using a valid Let's Encrypt SSL certificate at the time of the scan, hosted on an Apache web server at IP address 130.49.188.78. Hosting appears to be provided by LLC Vpsville, with infrastructure geolocated to Moscow, Russia. The domain is extremely new, registered on 2026-06-03, and uses nameservers from 1domainregistry.com.
DNSSEC appears to be unsigned, which means DNS responses may not benefit from that additional integrity layer. Although HTTPS was present, a valid certificate only confirms encrypted transport and does not by itself indicate legitimacy. In this case, the combination of very recent registration, phishing-related detections, and brand-referencing page content would generally be considered concerning at the time of the scan.
Condividi la tua esperienza con questo sito web. Era sicuro? Hai riscontrato problemi?