
DocuSign phishing & impersonation
Tech & Clouddocusign.com
37
Impersonation sightings
21
Distinct hosts
2026-08-15
Last detected
2
Official domains
ScanMalware watches every scanned site for signs it is impersonating DocuSign — the brand name in the page title or screenshot text, the brand's logo/favicon on a non-official host, and lookalike domains. A match on a host outside DocuSign's official domains is recorded below.
Official domains
docusign.comdocusign.net
Also known as
—
Detected impersonation sites
| Host | Title | Detected by | Verdict | Date | |
|---|---|---|---|---|---|
| dr.flipme.info | Welcome | Page text | {"verdict": "Low Risk", "confidence": 72, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 28, "recommendations": ["📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (dr.flipme.info)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 2, "total risk": 0, "valid count": 2, "invalid count": 0, "not found count": 0}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (dr.flipme.info)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-15 | View scan → |
| sf-demo-d0b.pages.dev | Grant Operations | Salesforce | Page text | {"verdict": "Low Risk", "confidence": 67, "risk level": "low", "risk factors": ["Mixed Content", "Brand Impersonation (Docusign)"], "overall score": 33, "recommendations": ["🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (sf-demo-d0b.pages.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 3, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (sf-demo-d0b.pages.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-14 | View scan → |
| sf-demo-d0b.pages.dev | Grant Operations | Salesforce | Page text | {"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (sf-demo-d0b.pages.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 2, "total risk": 0, "valid count": 2, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 3, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (sf-demo-d0b.pages.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-14 | View scan → |
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 34, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 4, "valid count": 11, "invalid count": 0, "not found count": 2}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 21, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 40, "issues": [], "total redirects": 7, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 2, "distinct redirect patterns": 2, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1450, "category": "ESTABLISHED", "registrar": null, "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-13 | View scan → |
| maindoc-app-md8gw.ondigitalocean.app | Document - OFeHpE | Page text | {"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-08 | View scan → |
| njj.standard.us-east-1.oortstorages.com | Docusign | #1 in Electronic Signature and Intelligent Agreement Managemen | Page text | {"verdict": "High Risk", "confidence": 60, "risk level": "high", "risk factors": ["Brand Impersonation (Docusign)", "Threat-intel IoC on scanned domain (known attacker): njj.standard.us-east-1.oortstorages.com", "Favicon matches DocuSign but domain 'njj.standard.us-east-1.oortstorages.com' is not a legitimate DocuSign domain (credential form present)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (njj.standard.us-east-1.oortstorages.com)"], "password fields": 5, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ioc matches": {"primary": [{"indicator": "njj.standard.us-east-1.oortstorages.com", "threat type": "known attacker"}], "infra ip": [], "score floor": 60}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 14, "total risk": 2, "valid count": 13, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 18, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 55, "issues": ["Favicon matches DocuSign but domain 'njj.standard.us-east-1.oortstorages.com' is not a legitimate DocuSign domain (credential form present)"], "details": {"favicon brand": {"brand": "DocuSign", "source": "curated", "penalty": 45, "embed risk": "low", "corroborated": true}, "matched brand": "DocuSign", "signals detected": ["favicon brand mismatch"], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Matched 1 threat-intel indicator(s) on site infrastructure: njj.standard.us-east-1.oortstorages.com", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (njj.standard.us-east-1.oortstorages.com)", "Favicon matches DocuSign but domain 'njj.standard.us-east-1.oortstorages.com' is not a legitimate DocuSign domain (credential form present)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-08 | View scan → |
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Medium Risk", "confidence": 35, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 35, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date", "📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 10, "total risk": 4, "valid count": 8, "invalid count": 0, "not found count": 2}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 45, "issues": [], "total redirects": 4, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1443, "category": "ESTABLISHED", "registrar": null, "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-05 | View scan → |
| www.alwafacarreg.com | Docusign | #1 in Electronic Signature and Intelligent Agreement Management | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)", "Favicon matches DocuSign but domain 'www.alwafacarreg.com' is not a legitimate DocuSign domain (credential form present)"], "overall score": 34, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (www.alwafacarreg.com)"], "password fields": 5, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 15, "total risk": 0, "valid count": 15, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 20, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 55, "issues": ["Favicon matches DocuSign but domain 'www.alwafacarreg.com' is not a legitimate DocuSign domain (credential form present)"], "details": {"favicon brand": {"brand": "DocuSign", "source": "curated", "penalty": 45, "embed risk": "low", "corroborated": true}, "matched brand": "DocuSign", "signals detected": ["favicon brand mismatch"], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 2, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (www.alwafacarreg.com)", "Favicon matches DocuSign but domain 'www.alwafacarreg.com' is not a legitimate DocuSign domain (credential form present)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-05 | View scan → |
| corpsolnaciente.com | Document - lBw | Page text | {"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (corpsolnaciente.com)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (corpsolnaciente.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-04 | View scan → |
| 13aw2r55bh.dual3231-1.workers.dev | cd - DocuSign | Page text | {"verdict": "Medium Risk", "confidence": 39, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 39, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date", "📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (13aw2r55bh.dual3231-1.workers.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (13aw2r55bh.dual3231-1.workers.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-04 | View scan → |
| maindoc-app-md8gw.ondigitalocean.app | Document - CEL | Page text | {"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-08-01 | View scan → |
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 34, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 9, "total risk": 2, "valid count": 8, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 10, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 45, "issues": [], "total redirects": 2, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1436, "category": "ESTABLISHED", "registrar": null, "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-29 | View scan → |
| fy5w-nxh6-g2ho.joliver-powershopscentralia-com-s-account.workers.dev | DocuSign - Review Document | Page text | {"verdict": "High Risk (IDS: ET PHISHING Generic Device Code Landing Page 2026-04-07 +1 more)", "confidence": 82, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (fy5w-nxh6-g2ho.joliver-powershopscentralia-com-s-account.workers.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ids alerts": {"total": 2, "category": "Possible Social Engineering Attempted", "detected": true, "severity": "high", "signature name": "ET PHISHING Generic Device Code Landing Page 2026-04-07"}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (fy5w-nxh6-g2ho.joliver-powershopscentralia-com-s-account.workers.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-29 | View scan → |
| blob:https://landing.qlobbi.com/f87da9e8-993a-44d9-bdb2-e01345dec24d | Docusign login - enter email to continue | Page text | {"verdict": "Low Risk", "confidence": 67, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 33, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain ()"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 0, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content", "Encoded URL/query string embedded in path"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 4, "valid count": 2, "invalid count": 0, "not found count": 2}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 5, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain ()"], "positive": ["Server IPs have valid RPKI ROA coverage", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-27 | View scan → |
| maindoc-app-md8gw.ondigitalocean.app | Document - qRs | Page text | {"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-25 | View scan → |
| pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev | DocuSign - Review Document | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 34, "recommendations": ["📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 1, "total risk": 0, "valid count": 1, "invalid count": 0, "not found count": 0}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1430, "category": "ESTABLISHED", "registrar": null, "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-23 | View scan → |
| costavalley.com.br | DocuSign | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)", "Favicon matches DocuSign but domain 'costavalley.com.br' is not a legitimate DocuSign domain (credential form present)"], "overall score": 34, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (costavalley.com.br)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 1, "total risk": 0, "valid count": 1, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 5, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 55, "issues": ["Favicon matches DocuSign but domain 'costavalley.com.br' is not a legitimate DocuSign domain (credential form present)"], "details": {"favicon brand": {"brand": "DocuSign", "source": "curated", "penalty": 45, "embed risk": "low", "corroborated": true}, "matched brand": "DocuSign", "signals detected": ["favicon brand mismatch"], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (costavalley.com.br)", "Favicon matches DocuSign but domain 'costavalley.com.br' is not a legitimate DocuSign domain (credential form present)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-23 | View scan → |
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 34, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 2, "valid count": 10, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 18, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 45, "issues": [], "total redirects": 4, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1429, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-22 | View scan → |
| envisn.onrender.com | Document - sNgsS | Page text | {"verdict": "High Risk (Possible Docusign Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (envisn.onrender.com)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Docusign brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (envisn.onrender.com) — consistent with credential phishing.", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (envisn.onrender.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-22 | View scan → |
| aspeducators.onrender.com | Document - sNgsS | Page text | {"verdict": "High Risk (Possible Docusign Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (aspeducators.onrender.com)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Docusign brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (aspeducators.onrender.com) — consistent with credential phishing.", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (aspeducators.onrender.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-22 | View scan → |
| helpdeskpilot.onrender.com | Document - sNgsS | Page text | {"verdict": "Malicious", "confidence": 95, "risk level": "malicious", "risk factors": ["Brand Impersonation (Docusign)", "Google Safe Browsing Threats"], "overall score": 80, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🚫 Google Safe Browsing detected security threats - avoid interaction", "🛡️ Enable browser security warnings and avoid downloading files"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (helpdeskpilot.onrender.com)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 0, "issues": ["Google Safe Browsing detected phishing"], "threats": {"SOCIAL ENGINEERING": 1}, "threat summary": ["1 phishing/social engineering threat(s) detected"], "positive signals": []}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (helpdeskpilot.onrender.com)", "Google Safe Browsing detected phishing"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-22 | View scan → |
| helpdeskpilot.onrender.com | Document - FuiTQ | Page text | {"verdict": "High Risk (Possible Docusign Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (helpdeskpilot.onrender.com)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Docusign brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (helpdeskpilot.onrender.com) — consistent with credential phishing.", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (helpdeskpilot.onrender.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-19 | View scan → |
| envisn.onrender.com | Document - FuiTQ | Page text | {"verdict": "High Risk (Possible Docusign Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (envisn.onrender.com)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Docusign brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (envisn.onrender.com) — consistent with credential phishing.", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (envisn.onrender.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-19 | View scan → |
| aspeducators.onrender.com | Document - FuiTQ | Page text | {"verdict": "High Risk (Possible Docusign Phishing on cloud hosting)", "confidence": 80, "risk level": "high", "risk factors": ["Mixed Content", "Brand Impersonation (Docusign)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary", "🔐 Website serves insecure content - data may be intercepted"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (aspeducators.onrender.com)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 30, "issues": ["Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected"], "mixed content": true, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 1, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Docusign brand impersonation with a credential form on a disposable cloud-hosting/storage subdomain (aspeducators.onrender.com) — consistent with credential phishing.", "Mixed content detected (HTTP resources on HTTPS page)", "1 insecure HTTP requests detected", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (aspeducators.onrender.com)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-19 | View scan → |
| njj.standard.us-east-1.oortstorages.com | Docusign | #1 in Electronic Signature and Intelligent Agreement Managemen | Page text | {"verdict": "High Risk", "confidence": 60, "risk level": "high", "risk factors": ["Brand Impersonation (Docusign)", "Threat-intel IoC on scanned domain (known attacker): njj.standard.us-east-1.oortstorages.com", "Favicon matches DocuSign but domain 'njj.standard.us-east-1.oortstorages.com' is not a legitimate DocuSign domain (credential form present)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (njj.standard.us-east-1.oortstorages.com)"], "password fields": 5, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ioc matches": {"primary": [{"indicator": "njj.standard.us-east-1.oortstorages.com", "threat type": "known attacker"}], "infra ip": [], "score floor": 60}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 2, "valid count": 12, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 18, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 55, "issues": ["Favicon matches DocuSign but domain 'njj.standard.us-east-1.oortstorages.com' is not a legitimate DocuSign domain (credential form present)"], "details": {"favicon brand": {"brand": "DocuSign", "source": "curated", "penalty": 45, "embed risk": "low", "corroborated": true}, "matched brand": "DocuSign", "signals detected": ["favicon brand mismatch"], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 1, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 0, "distinct redirect patterns": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["Matched 1 threat-intel indicator(s) on site infrastructure: njj.standard.us-east-1.oortstorages.com", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (njj.standard.us-east-1.oortstorages.com)", "Favicon matches DocuSign but domain 'njj.standard.us-east-1.oortstorages.com' is not a legitimate DocuSign domain (credential form present)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-18 | View scan → |
| maindoc-app-md8gw.ondigitalocean.app | Document - OQSveW | Page text | {"verdict": "Low Risk", "confidence": 73, "risk level": "low", "risk factors": ["Brand Impersonation (Docusign)"], "overall score": 27, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 65, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": []}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 3, "total risk": 0, "valid count": 3, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 6, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (maindoc-app-md8gw.ondigitalocean.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-18 | View scan → |
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 34, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 2, "valid count": 10, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 18, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 45, "issues": [], "total redirects": 4, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 1, "distinct redirect patterns": 1, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1422, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-15 | View scan → |
| 9cmw-idx4-47fs.george-vandevorde-smithinsurancellc-com-s-account.workers.dev | DocuSign - Review Document | Page text | {"verdict": "High Risk (IDS: ET PHISHING Generic Device Code Landing Page 2026-04-07 +1 more)", "confidence": 82, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)", "References flagged external domain(s): george-vandevorde-smithinsurancellc-com-s-account.workers.dev"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (9cmw-idx4-47fs.george-vandevorde-smithinsurancellc-com-s-account.workers.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ids alerts": {"total": 2, "category": "Possible Social Engineering Attempted", "detected": true, "severity": "high", "signature name": "ET PHISHING Generic Device Code Landing Page 2026-04-07"}, "ioc matches": {"external": [{"indicator": "george-vandevorde-smithinsurancellc-com-s-account.workers.dev", "threat type": "known attacker"}]}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 10, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (9cmw-idx4-47fs.george-vandevorde-smithinsurancellc-com-s-account.workers.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-13 | View scan → |
| 3cud-je09-uln1.accounting-coralridgetowerssouth-com-s-account.workers.dev | DocuSign - Review Document | Page text | {"verdict": "High Risk (IDS: ET PHISHING Generic Device Code Landing Page 2026-04-07 +1 more)", "confidence": 82, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)", "References flagged external domain(s): accounting-coralridgetowerssouth-com-s-account.workers.dev"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (3cud-je09-uln1.accounting-coralridgetowerssouth-com-s-account.workers.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ids alerts": {"total": 2, "category": "Possible Social Engineering Attempted", "detected": true, "severity": "high", "signature name": "ET PHISHING Generic Device Code Landing Page 2026-04-07"}, "ioc matches": {"external": [{"indicator": "accounting-coralridgetowerssouth-com-s-account.workers.dev", "threat type": "known attacker"}]}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 9, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (3cud-je09-uln1.accounting-coralridgetowerssouth-com-s-account.workers.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-10 | View scan → |
| 3cud-je09-uln1.accounting-coralridgetowerssouth-com-s-account.workers.dev | DocuSign - Review Document | Page text | {"verdict": "High Risk (IDS: ET PHISHING Generic Device Code Landing Page 2026-04-07 +1 more)", "confidence": 82, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)", "References flagged external domain(s): accounting-coralridgetowerssouth-com-s-account.workers.dev"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (3cud-je09-uln1.accounting-coralridgetowerssouth-com-s-account.workers.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ids alerts": {"total": 2, "category": "Possible Social Engineering Attempted", "detected": true, "severity": "high", "signature name": "ET PHISHING Generic Device Code Landing Page 2026-04-07"}, "ioc matches": {"external": [{"indicator": "accounting-coralridgetowerssouth-com-s-account.workers.dev", "threat type": "known attacker"}]}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 9, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (3cud-je09-uln1.accounting-coralridgetowerssouth-com-s-account.workers.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-10 | View scan → |
| outer-pink-uep6emb5-dpghxhzc85yu.edgeone.app | DocuSign - Review Document | Page text | {"verdict": "Low Risk", "confidence": 72, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 28, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (outer-pink-uep6emb5-dpghxhzc85yu.edgeone.app)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 1, "total risk": 0, "valid count": 1, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 1, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (outer-pink-uep6emb5-dpghxhzc85yu.edgeone.app)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-10 | View scan → |
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Low Risk", "confidence": 66, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 34, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 11, "total risk": 2, "valid count": 10, "invalid count": 0, "not found count": 1}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 21, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 40, "issues": [], "total redirects": 7, "blob url detected": false, "protocol downgrades": 0, "same site redirects": 0, "suspicious patterns": 0, "cross domain redirects": 2, "distinct redirect patterns": 2, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1415, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-08 | View scan → |
| xmlf-ag9n-th11.mgeorgatos-netw1-com-s-account.workers.dev | DocuSign - Review Document | Page text | {"verdict": "High Risk (IDS: ET PHISHING Generic Device Code Landing Page 2026-04-07 +1 more)", "confidence": 82, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)", "References flagged external domain(s): mgeorgatos-netw1-com-s-account.workers.dev"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (xmlf-ag9n-th11.mgeorgatos-netw1-com-s-account.workers.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ids alerts": {"total": 2, "category": "Possible Social Engineering Attempted", "detected": true, "severity": "high", "signature name": "ET PHISHING Generic Device Code Landing Page 2026-04-07"}, "ioc matches": {"external": [{"indicator": "mgeorgatos-netw1-com-s-account.workers.dev", "threat type": "known attacker"}]}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 4, "total risk": 0, "valid count": 4, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 7, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 10, "rdap data": null, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (xmlf-ag9n-th11.mgeorgatos-netw1-com-s-account.workers.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-07 | View scan → |
| server-index-page--eefostar.replit.app | Sign in to your account | Logo / favicon | {"verdict": "High Risk (Possible Microsoft 365 Phishing)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)", "References flagged external domain(s): l2.io", "Favicon matches DocuSign but domain 'server-index-page--eefostar.replit.app' is not a legitimate DocuSign domain (credential form present)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (server-index-page--eefostar.replit.app)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "l2.io", "threat type": "ipinfo (suspicious)"}]}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 0, "valid count": 13, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 30, "issues": ["Favicon matches DocuSign but domain 'server-index-page--eefostar.replit.app' is not a legitimate DocuSign domain (credential form present)"], "details": {"favicon brand": {"brand": "DocuSign", "source": "curated", "penalty": 45, "embed risk": "low", "corroborated": true}, "matched brand": "Microsoft 365", "signals detected": ["favicon brand mismatch", "title domain mismatch"], "is legitimate domain": false}, "warnings": ["Page title matches Microsoft 365 login pattern but domain 'server-index-page--eefostar.replit.app' is not a legitimate Microsoft 365 domain"]}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (server-index-page--eefostar.replit.app)", "Favicon matches DocuSign but domain 'server-index-page--eefostar.replit.app' is not a legitimate DocuSign domain (credential form present)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": ["Page title matches Microsoft 365 login pattern but domain 'server-index-page--eefostar.replit.app' is not a legitimate Microsoft 365 domain"]}} | 2026-07-02 | View scan → |
| server-index-page--eefostar.replit.app | Sign in to your account | Page text | {"verdict": "High Risk (Possible Microsoft 365 Phishing)", "confidence": 80, "risk level": "high", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)", "References flagged external domain(s): l2.io", "Favicon matches DocuSign but domain 'server-index-page--eefostar.replit.app' is not a legitimate DocuSign domain (credential form present)"], "overall score": 60, "recommendations": ["⚠️ Avoid visiting this website - high security risk detected", "🔒 Use additional security measures if access is necessary"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (server-index-page--eefostar.replit.app)"], "password fields": 1, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "ioc matches": {"external": [{"indicator": "l2.io", "threat type": "ipinfo (suspicious)"}]}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 0, "valid count": 13, "invalid count": 0, "not found count": 0}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 16, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 30, "issues": ["Favicon matches DocuSign but domain 'server-index-page--eefostar.replit.app' is not a legitimate DocuSign domain (credential form present)"], "details": {"favicon brand": {"brand": "DocuSign", "source": "curated", "penalty": 45, "embed risk": "low", "corroborated": true}, "matched brand": "Microsoft 365", "signals detected": ["favicon brand mismatch", "title domain mismatch"], "is legitimate domain": false}, "warnings": ["Page title matches Microsoft 365 login pattern but domain 'server-index-page--eefostar.replit.app' is not a legitimate Microsoft 365 domain"]}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": ["Credential Phishing"], "security indicators": {"negative": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (server-index-page--eefostar.replit.app)", "Favicon matches DocuSign but domain 'server-index-page--eefostar.replit.app' is not a legitimate DocuSign domain (credential form present)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": ["Page title matches Microsoft 365 login pattern but domain 'server-index-page--eefostar.replit.app' is not a legitimate Microsoft 365 domain"]}} | 2026-07-02 | View scan → |
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date", "📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 4, "valid count": 11, "invalid count": 0, "not found count": 2}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 15, "issues": ["Excessive redirects (7)", "Excessive cross-domain redirects (5)"], "total redirects": 7, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 5, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1408, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "Excessive redirects (7)", "Excessive cross-domain redirects (5)", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-01 | View scan → |
| pub-5de0eeee09ff443eac563eb154d4aa6c.r2.dev | DocuSign Share File | Logo / favicon | {"verdict": "Low Risk", "confidence": 67, "risk level": "low", "risk factors": ["Suspicious URL Patterns"], "overall score": 33, "recommendations": [], "detailed analysis": {"html forms": {"score": 50, "issues": [], "impersonated brand": null, "brand mismatch detected": false, "disguised password fields": 0, "brand impersonation detected": false}, "url analysis": {"score": 10, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 18, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive": ["Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2025-12-05 | View scan → |