Security Scan Report: docusign-glm.rough-rice-b41b.workers.dev

Site favicon
Submitted: Oct 1, 2026, 9:18:15 AMCompleted: Oct 1, 2026, 9:19:21 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Confirmed DocuSign-branded phishing page on a throwaway Cloudflare Workers subdomain using an EvilToken-style device-code kit to trick victims into authorizing a Microsoft login. Do not interact.

Risk Factors (6)
Brand impersonation of DocuSign on a non-DocuSign domain
Known phishing kit family (EvilToken / Cloudflare Workers device-code kit)
HIGH-severity phishing YARA match (EvilTokens_Ghost_Loader AES-GCM cloaking loader)
Network IDS flagged the page as a generic device-code phishing landing page (3 HIGH alerts)
Disposable platform subdomain with unknown actual creation date, unranked domain reputation
Deliberate anti-analysis obfuscation (encrypted inline payload written via document.write)
Domain age information unavailable

Details

Page Title

DocuSign - Review Document

Scan Type

public

Domain Name Analysis

You're looking at domain 'docusign-glm.rough-rice-b41b.workers.dev' on the developer-focused generic top-level domain (.dev) and includes subdomain 'docusign-glm.rough-rice-b41b'. Count 7 characters in 'workers' containing 2 vowels alongside 5 consonants. Tokenizing the label suggests 1 word: workers. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://docusign-glm.rough-rice-b41b.workers.dev/ed65c61f4c64380d

Page Load Overview

5.42s
Total Load Time
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:511 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software56% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
56%
documentation technical
52%
cryptocurrency blockchain
47%
government public service
36%
corporate business
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2104.21.7.223Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
274.125.29.95Google · CDNUnited States
AS15169Google LLC
2142.251.13.94Google · CDNUnited States
AS15169Google LLC
2142.251.14.95Google · CDNUnited States
AS15169Google LLC
84--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T160A29E33A748283CB93B45D2E36577DD70618363F51B10106AA82668C4CAEBBDF37788

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:eplr1Ai5fT6wsyImzHar2gp0UhN8JTdmQ22uTAmjiU:epRNzHar2ENATdmQ22uTPjiU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:22174:HwiImKSmBAhbgjyCAQOMglGYBscJXYgoERBjylCmCOcAoAkAqIvJGSLFjIildFUAICzAgaTIhD4QCBFJDQAQtgRYFQMHiSXh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffef1818180000
Perceptual Hash:999ca60c9e1c9e3e
Difference Hash:20041832a2300008
Wavelet Hash:ffffef5d18180000
Color Hash:#785b3a

Other Hashes

Crop Resistant:20041832a2300008

Scan History

Scan history not available

Unable to load historical scan data