docusign-dj2[.]gihida6940-ostahie-com-s-account[.]workers[.]dev
“Worker threw exception | docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev | Cloudflare”
docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev — Неперевірений. Уособлення бренду: Cloudflare; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 15/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); PhishDestroy score 95/100. Реєстратор: Cloudflare Workers.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, docusign-dj2.gihida6940-ostahie-com-s-account.workers.dev, is identified as a high-risk credential phishing threat targeting users through DocuSign brand impersonation. Analysis indicates the domain is designed to harvest login credentials by mimicking legitimate DocuSign authentication portals, a common tactic in credential theft campaigns. No evidence of a crypto drainer kit or secondary payload delivery was observed, but the infrastructure aligns with known credential harvesting frameworks. Infrastructure analysis reveals the domain resolves to IP address 172.67.188.178, hosted on Cloudflare Workers, a platform frequently abused for rapid deployment of phishing pages. The domain was registered on May 05, 2026, though this date may reflect a misconfiguration or spoofed record, as it predates the current year. VirusTotal detection rates show 10 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is actively blocked by PhishDestroy. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility. No Google Safe Browsing (GSB) listing was observed at the time of analysis. Current status indicates the domain remains active, though the page title 'Worker threw exception' suggests a potential misconfiguration or failed deployment. Despite this, the domain retains a high risk level due to its association with DocuSign impersonation and credential theft. Response actions should include immediate blocking of the domain and IP at the network level, as well as monitoring for related infrastructure. Users are advised to verify the legitimacy of DocuSign communications by accessing the platform directly through official channels. Organizations should implement multi-factor authentication (MFA) to mitigate the impact of credential theft and educate users on recognizing brand impersonation tactics.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога