docusign-29i[.]gordon-gljacobs-com-s-account[.]workers[.]dev
“Worker threw exception | docusign-29i.gordon-gljacobs-com-s-account.workers.dev | Cloudflare”
docusign-29i.gordon-gljacobs-com-s-account.workers.dev — لم يتم التحقق منها. انتحال العلامة التجارية: Cloudflare; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 95/100. مسجّل النطاق: Cloudflare Workers.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain docusign-29i.gordon-gljacobs-com-s-account.workers.dev is identified as a high-risk credential phishing threat. The domain mimics the legitimate DocuSign brand to trick users into divulging sensitive information. Analysis has not revealed the use of any specific drainer kit, but the domain's structure and registrar suggest a sophisticated, targeted attack.
Technical indicators for the domain include a VirusTotal detection score of 11/95, indicating that 11 out of 95 security vendors have flagged this domain as malicious. The domain is registered through Cloudflare Workers, and it resolves to the IP address 188.114.97.3, which is located in California, USA, and is owned by CloudFlare, Inc. The domain was created on May 01, 2026, and currently appears on 1 security blocklist. The page title observed is 'Worker threw exception | docusign-29i.gordon-gljacobs-com-s-account.workers.dev | Cloudflare', which may be a technical error or a deliberate attempt to obfuscate the true nature of the page.
The domain remains active, posing a significant risk to users who may be tricked into entering their credentials. Immediate response actions include blocking the domain at the network level and educating users about the threat. Despite the domain being flagged by multiple vendors, it is still accessible, and further monitoring and potential takedown efforts are recommended to mitigate the remaining risk.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب