office-docusign-net[.]tammy-e82[.]workers[.]dev
“Suspected Phishing | Cloudflare”
证据摘要
Analysis indicates that the domain office-docusign-net.tammy-e82.workers.dev is actively flagged as a phishing threat targeting DocuSign users. Registered through Cloudflare Workers on February 8, 2019, this domain resolves to the IP address 188.114.96.3, which is associated with Cloudflare's infrastructure. As of July 29, 2026, the domain appears on at least one security blocklist and is explicitly blocked by PhishDestroy. VirusTotal reports that 16 out of 91 security vendors have detected this domain as malicious, providing concrete evidence of its elevated risk status.
The use of Cloudflare Workers for registration is notable, as this platform is frequently leveraged by threat actors to rapidly deploy and rotate phishing domains while maintaining operational anonymity. The domain's structure, incorporating 'office-docusign-net', suggests an intent to deceive users into believing it is affiliated with DocuSign, a widely used electronic signature service. However, the exact content and mechanics of the phishing page remain unanalyzed, as no direct inspection of the site has been conducted. Defenders should treat this domain as an active threat and implement blocking measures at the DNS, proxy, or endpoint level.
Security teams are advised to monitor for connections to 188.114.96.3 and review logs for any interaction with this domain, particularly in environments where DocuSign is utilized. Given the domain's persistence since 2019, it may be part of a broader, long-running phishing campaign. No additional brand-specific indicators, such as page titles or phishing kit signatures, are currently available for further classification.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
首次记录
首次存储值:可访问
-
域名状态
可访问 → 无法访问
域名情报
技术详情DNS、TLS 名称和时间戳
技术
识别出 3 项高置信度技术
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of office-docusign-net.tammy-e82.workers.dev · checked Jul 29, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控