office-document-sign[.]tammy-e82[.]workers[.]dev
“Suspected Phishing | Cloudflare”
Kanıt özeti
Analysis of the domain office-document-sign.tammy-e82.workers.dev shows that it is an active generic phishing infrastructure flagged as elevated risk. The domain was registered on February 08, 2019 and is hosted behind Cloudflare Workers, a serverless platform that masks the true origin of the payload. DNS resolution points to the IP address 188.114.97.3, which is a Cloudflare edge node rather than a dedicated host, making attribution to a specific attacker difficult.
VirusTotal scans have recorded 13 detections out of 91 security vendors, indicating that a minority of AV engines have identified malicious behavior associated with the domain. The domain is currently listed on one public blocklist and has been explicitly blocked by the PhishDestroy sinkhole, confirming that at least one defensive organization has observed malicious traffic targeting it. No public Safe Browsing, OTX, or additional blocklist entries were found in the supplied intelligence, and no page title or SSL certificate details are available for further verification.
The limited detection coverage suggests that the phishing campaign may be targeting a niche audience or employing evasion techniques to avoid broader detection. Defenders should add the domain and its resolving IP to outbound deny lists, monitor DNS queries for the domain pattern, and enforce strict email filtering for messages that reference Office document signing workflows. Continuous re‑scanning with multi‑vendor services is advised to detect any changes in the detection profile, and any observed traffic should be forwarded to threat‑intelligence sharing platforms to improve collective visibility.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Tespit zaman çizelgesi
-
VirusTotal
17 → 16
-
İlk kayıt
İlk kayıtlı değer: Erişilebilir
-
Alan adı durumu
Erişilebilir → Erişilemiyor
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of office-document-sign.tammy-e82.workers.dev · checked Jul 29, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin