docusign-8pt[.]shawn-knowler-smcalgarys-com-s-account[.]workers[.]dev
“Worker threw exception | docusign-8pt.shawn-knowler-smcalgarys-com-s-account.workers.dev | Cloudfla…”
docusign-8pt.shawn-knowler-smcalgarys-com-s-account.workers.dev — Doğrulanmamış. Marka kimliğine bürünme: Cloudflare; Dolandırıcılık türü: Credential Phishing. Kanıt özeti: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 95/100. Kayıt kuruluşu: Cloudflare Workers.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain is identified as a high-risk credential phishing threat associated with a fake login workflow designed to capture user authentication data. Analysis indicates that visitors may be presented with content intended to imitate a legitimate account access process and persuade users to submit usernames, passwords, or other sensitive credentials. The infrastructure remains active and resolves to IP address 172.67.205.175. The observed page title currently returns an error message, but this does not reduce the risk because phishing operators frequently modify or temporarily disable content while retaining the underlying infrastructure.
Technical assessment reveals multiple indicators supporting the classification. The domain docusign-8pt.shawn-knowler-smcalgarys-com-s-account.workers.dev was created on May 05, 2026 and is registered through Cloudflare Workers. Security telemetry shows that 13 out of 95 security vendors on VirusTotal flag the domain as malicious. The domain appears on 1 security blocklist and is currently blocked by PhishDestroy. Infrastructure analysis further shows hosting behind Cloudflare network services with IP geolocation reported as CA and an active Let's Encrypt / E7 SSL certificate. The current status is active.
If a user visited this domain, any credentials entered should be considered exposed. Affected individuals should immediately change passwords associated with the targeted account and any other accounts reusing the same credentials. Multi-factor authentication should be enabled where available, and account activity should be reviewed for unauthorized access. Security teams should block the domain, monitor authentication logs for suspicious sign-in attempts, and investigate systems that interacted with the site. Continued monitoring is recommended because active phishing infrastructure can be repurposed or updated without warning.
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin