docusign-dj2[.]gihida6940-ostahie-com-s-account[.]workers[.]dev
“Worker threw exception | docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev | Cloudflare”
docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev — لم يتم التحقق منها. انتحال العلامة التجارية: Cloudflare; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 95/100. مسجّل النطاق: Cloudflare Workers.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev, is identified as a high-risk credential phishing threat targeting users through DocuSign brand impersonation. Analysis indicates the domain is designed to harvest login credentials by mimicking legitimate DocuSign authentication portals, a common tactic in credential theft campaigns. No evidence of a crypto drainer kit or secondary payload delivery was observed, but the infrastructure aligns with known credential harvesting frameworks. Infrastructure analysis reveals the domain resolves to IP address 172.67.188.178, hosted on Cloudflare Workers, a platform frequently abused for rapid deployment of phishing pages. The domain was registered on May 05, 2026, though this date may reflect a misconfiguration or spoofed record, as it predates the current year. VirusTotal detection rates show 10 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is actively blocked by PhishDestroy. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility. No Google Safe Browsing (GSB) listing was observed at the time of analysis. Current status indicates the domain remains active, though the page title 'Worker threw exception' suggests a potential misconfiguration or failed deployment. Despite this, the domain retains a high risk level due to its association with DocuSign impersonation and credential theft. Response actions should include immediate blocking of the domain and IP at the network level, as well as monitoring for related infrastructure. Users are advised to verify the legitimacy of DocuSign communications by accessing the platform directly through official channels. Organizations should implement multi-factor authentication (MFA) to mitigate the impact of credential theft and educate users on recognizing brand impersonation tactics.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب