docusign-dj2[.]gihida6940-ostahie-com-s-account[.]workers[.]dev
“Worker threw exception | docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev | Cloudflare”
docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev — Непроверенный. Олицетворение бренда: Cloudflare; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 95/100. Регистратор: Cloudflare Workers.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev, is identified as a high-risk credential phishing threat targeting users through DocuSign brand impersonation. Analysis indicates the domain is designed to harvest login credentials by mimicking legitimate DocuSign authentication portals, a common tactic in credential theft campaigns. No evidence of a crypto drainer kit or secondary payload delivery was observed, but the infrastructure aligns with known credential harvesting frameworks. Infrastructure analysis reveals the domain resolves to IP address 172.67.188.178, hosted on Cloudflare Workers, a platform frequently abused for rapid deployment of phishing pages. The domain was registered on May 05, 2026, though this date may reflect a misconfiguration or spoofed record, as it predates the current year. VirusTotal detection rates show 10 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is actively blocked by PhishDestroy. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility. No Google Safe Browsing (GSB) listing was observed at the time of analysis. Current status indicates the domain remains active, though the page title 'Worker threw exception' suggests a potential misconfiguration or failed deployment. Despite this, the domain retains a high risk level due to its association with DocuSign impersonation and credential theft. Response actions should include immediate blocking of the domain and IP at the network level, as well as monitoring for related infrastructure. Users are advised to verify the legitimacy of DocuSign communications by accessing the platform directly through official channels. Organizations should implement multi-factor authentication (MFA) to mitigate the impact of credential theft and educate users on recognizing brand impersonation tactics.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание