office-document-sign[.]tammy-e82[.]workers[.]dev
“Suspected Phishing | Cloudflare”
ملخص الأدلة
Analysis of the domain office-document-sign.tammy-e82.workers.dev shows that it is an active generic phishing infrastructure flagged as elevated risk. The domain was registered on February 08, 2019 and is hosted behind Cloudflare Workers, a serverless platform that masks the true origin of the payload. DNS resolution points to the IP address 188.114.97.3, which is a Cloudflare edge node rather than a dedicated host, making attribution to a specific attacker difficult.
VirusTotal scans have recorded 13 detections out of 91 security vendors, indicating that a minority of AV engines have identified malicious behavior associated with the domain. The domain is currently listed on one public blocklist and has been explicitly blocked by the PhishDestroy sinkhole, confirming that at least one defensive organization has observed malicious traffic targeting it. No public Safe Browsing, OTX, or additional blocklist entries were found in the supplied intelligence, and no page title or SSL certificate details are available for further verification.
The limited detection coverage suggests that the phishing campaign may be targeting a niche audience or employing evasion techniques to avoid broader detection. Defenders should add the domain and its resolving IP to outbound deny lists, monitor DNS queries for the domain pattern, and enforce strict email filtering for messages that reference Office document signing workflows. Continuous re‑scanning with multi‑vendor services is advised to detect any changes in the detection profile, and any observed traffic should be forwarded to threat‑intelligence sharing platforms to improve collective visibility.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
17 ← 16
-
أول تسجيل
أول قيمة محفوظة: يمكن الوصول إليه
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
التقنيات
حُدّدت ٣ تقنيات عالية الثقة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of office-document-sign.tammy-e82.workers.dev · checked Jul 29, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب