escehrgroup.com
Kategoria: Phishing
Aby korzystać z produktu z pełną funkcjonalnością, musisz kupić licencję na Combo Cleaner. Dostępny jest ograniczony siedmiodniowy bezpłatny okres próbny. Combo Cleaner należy do RCS LT i jest obsługiwany przez tę firmę, spółkę macierzystą PCRisk.com.
Opis escehrgroup.com
The domain escehrgroup.com appears to present a document-themed landing page styled to resemble a DocuSign workflow, with prompts to verify identity through Microsoft before viewing a file labeled "ACH_INCOMING_PAYMENT.pdf." Based on the screenshot and the domain name, the site does not appear to represent an established corporate homepage or a normal business website for an "HR group"; instead, it appears to be a single-purpose page designed to funnel visitors into an account-verification flow.
Available classification data associates this domain with phishing and fraud-related activity rather than a legitimate business service. The page branding references well-known third-party services, but the domain itself does not appear to be an official DocuSign or Microsoft property. At the time of this scan, no clear evidence was provided that the site is operated by the brands shown on the page.
Ocena bezpieczeństwa escehrgroup.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, and several web-classification providers categorized it as phishing, fraud-related, or malware-associated. The screenshot also shows a credential-style verification flow that references DocuSign and Microsoft on a newly registered, unrelated domain, which is a common pattern seen in account-harvesting campaigns.
Additional context increases concern: the domain age is 0 days, it has no established traffic ranking, and the page appears focused on getting the visitor to continue to a Microsoft-branded verification step in order to access a supposed payment document. While one malware scan did not detect malicious files on the page itself and some blacklist sources were clean, those signals do not outweigh the broader phishing indicators and the strong multi-engine consensus.
Based on these findings, this website may pose potential risks to visitors.
Opis techniczny
The site was using a valid Let's Encrypt SSL certificate at the time of the scan, hosted on an Apache web server at IP address 130.49.188.78. Hosting appears to be provided by LLC Vpsville, with infrastructure geolocated to Moscow, Russia. The domain is extremely new, registered on 2026-06-03, and uses nameservers from 1domainregistry.com.
DNSSEC appears to be unsigned, which means DNS responses may not benefit from that additional integrity layer. Although HTTPS was present, a valid certificate only confirms encrypted transport and does not by itself indicate legitimacy. In this case, the combination of very recent registration, phishing-related detections, and brand-referencing page content would generally be considered concerning at the time of the scan.
Podziel się swoimi doświadczeniami z tą witryną. Czy była bezpieczna? Czy wystąpiły jakieś problemy?