doc-sign-online--microsoftlogs[.]replit[.]app
“Login Screen”
Stored observation
Observed title contrast
Evidence Summary
Analysis indicates that the domain doc-sign-online--microsoftlogs.replit.app is currently active and resolves to the IPv4 address 34.117.33.233. Registration information shows the domain was created through Replit Inc., a reputable development platform that also provides the hosting environment. The domain lacks publicly resolvable nameserver records, as the nameserver lookup returned NS_NOT_FOUND, which may hinder typical DNS‑based reputation checks. VirusTotal has recorded 16 of 91 security vendors flagging the domain, indicating a moderate level of consensus among scanning engines that the site is malicious.
Independent blocklist monitoring confirms that the domain appears on a single security blocklist and is actively blocked by the PhishDestroy mitigation service. No additional public reputation services such as Safe Browsing or OTX are referenced in the supplied intelligence. The limited detection footprint, combined with the presence on a known phishing blocklist, suggests that the infrastructure is being used for a generic phishing campaign targeting users who may be enticed to submit credentials.
Defenders should add the domain and its resolved IP address to outbound and inbound deny lists, enforce DNS filtering that drops queries for the domain, and monitor network traffic for connections to 34.117.33.233. Continuous re‑evaluation is advised, as the threat actor may modify hosting or rename the domain in future iterations. Until further forensic analysis of the hosted content is performed, the domain should be treated as high‑risk.
Data Coverage
Network Security Intelligence
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
First recorded
First stored value: Reachable
-
Domain status
Reachable → Unreachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Registration: replit.app
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For the registrable domain replit.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
7 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of doc-sign-online--microsoftlogs.replit.app · checked Aug 6, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive