docusign-signature[.]github[.]io
Перевірка домену docusign-signature.github.io на фішинг і безпеку
“Site not found · GitHub Pages”
docusign-signature.github.io — Контент недоступний (HTTP 404). Уособлення бренду: Generic; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Certego); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 100/100. Реєстратор: GitHub.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies the domain docusign-signature.github.io as an active generic phishing infrastructure leveraging the DocuSign brand to deceive users into disclosing sensitive information. This domain impersonates DocuSign's signature verification portal, a common tactic in credential harvesting campaigns. The infrastructure relies on a drainer kit designed to mimic legitimate DocuSign workflows, tricking victims into inputting their login credentials or payment details. Technical analysis confirms the presence of obfuscated JavaScript within the landing page to capture user input and exfiltrate data to attacker-controlled servers.
This domain was flagged by 18 out of 95 VirusTotal security vendors, indicating widespread detection but insufficient blocking by default configurations. Registered through GitHub, Inc., the domain resolves to the IP address 185.199.108.153 and utilizes a Let's Encrypt SSL certificate for authenticity. The domain has been active long enough to be included on 2 security blocklists, including OpenPhish and OISD blocklists, underscoring its malicious reputation. While the exact creation date is not provided, the presence on multiple blocklists suggests a prolonged operational period.
Current status of docusign-signature.github.io remains active, posing an elevated risk to unsuspecting users. Immediate response actions include blocking the domain at the network perimeter and updating endpoint detection rules to quarantine associated IP traffic. Despite these measures, the domain continues to evade complete takedown, likely due to GitHub's hosting policies for Pages services. Remaining risk is elevated, particularly for organizations with lax email filtering or users unfamiliar with DocuSign's official domains. PhishDestroy recommends heightened scrutiny for emails referencing DocuSign signatures and immediate reporting of any suspicious activity to security teams. Users should verify sender domains and avoid clicking on embedded links in unsolicited messages.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | docusign-signature.github.io |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of docusign-signature.github.io · checked May 2, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога