escehrgroup.com
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of escehrgroup.com
The domain escehrgroup.com appears to present a document-themed landing page styled to resemble a DocuSign workflow, with prompts to verify identity through Microsoft before viewing a file labeled "ACH_INCOMING_PAYMENT.pdf." Based on the screenshot and the domain name, the site does not appear to represent an established corporate homepage or a normal business website for an "HR group"; instead, it appears to be a single-purpose page designed to funnel visitors into an account-verification flow.
Available classification data associates this domain with phishing and fraud-related activity rather than a legitimate business service. The page branding references well-known third-party services, but the domain itself does not appear to be an official DocuSign or Microsoft property. At the time of this scan, no clear evidence was provided that the site is operated by the brands shown on the page.
Safety Assessment for escehrgroup.com
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 18 out of 91 security engines, and several web-classification providers categorized it as phishing, fraud-related, or malware-associated. The screenshot also shows a credential-style verification flow that references DocuSign and Microsoft on a newly registered, unrelated domain, which is a common pattern seen in account-harvesting campaigns.
Additional context increases concern: the domain age is 0 days, it has no established traffic ranking, and the page appears focused on getting the visitor to continue to a Microsoft-branded verification step in order to access a supposed payment document. While one malware scan did not detect malicious files on the page itself and some blacklist sources were clean, those signals do not outweigh the broader phishing indicators and the strong multi-engine consensus.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was using a valid Let's Encrypt SSL certificate at the time of the scan, hosted on an Apache web server at IP address 130.49.188.78. Hosting appears to be provided by LLC Vpsville, with infrastructure geolocated to Moscow, Russia. The domain is extremely new, registered on 2026-06-03, and uses nameservers from 1domainregistry.com.
DNSSEC appears to be unsigned, which means DNS responses may not benefit from that additional integrity layer. Although HTTPS was present, a valid certificate only confirms encrypted transport and does not by itself indicate legitimacy. In this case, the combination of very recent registration, phishing-related detections, and brand-referencing page content would generally be considered concerning at the time of the scan.
Share your experience with this website. Was it safe? Did you encounter any issues?