Security Scan Report: www.account.docusign.us.ci

Redirected to:
https://www.account.docusign.us.ci/
Submitted: Sep 14, 2026, 12:45:14 AMCompleted: Sep 14, 2026, 12:45:38 AMpubliccompleted

This website contacted 3 IPs in 2 countries across 2 domains to perform 4 HTTP transactions. The main domain is account.docusign.us.ci and was registered 17 years ago.

Submitted URL: http://www.account.docusign.us.ci/

Effective URL:

https://www.account.docusign.us.ci/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Fake DocuSign 'human verification' page on an unrelated .us.ci domain uses a counterfeit CAPTCHA to push a file download and a code entry — a phishing/malware-lure impersonating DocuSign. Avoid and report.

Risk Factors
Brand impersonation of DocuSign on an unrelated .us.ci domain
Phishing threat-intelligence hit on the primary domain
Fake human-verification flow coercing users to download and run a file
Spoofed Cloudflare-style interstitial to appear trustworthy
Domain age information unavailable

Details

Page Title

Verifying you are human

Scan Type

public

Domain Name Analysis

Domain 'www.account.docusign.us.ci' uses the .ci country-code top-level domain, featuring subdomain 'www.account.docusign'. The core label 'us' covers 2 characters split between one vowel and 1 consonant. Tokenizing the label suggests 1 word: us. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://www.account.docusign.us.ci/

Page Load Overview

4.20s
Total Load Time
5 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:820 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software42% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
42%
cryptocurrency blockchain
41%
government public service
36%
documentation technical
35%
blog personal website
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
285.9.194.139Secaucus, New Jersey, United States
AS25697UpCloud USA Inc
123.76.204.158Akamai · CDNSchiphol, North Holland, Netherlands
AS20940Akamai International B.V.
123.76.204.155Akamai · CDNSchiphol, North Holland, Netherlands
AS20940Akamai International B.V.
43--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T181E1B71B77A6043261A360A5369BE7CA3201C413E507C9323EFC54A8CFDAE919AB37C5

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:cZibFAPqSr3y1jYt2IVRNKmcfKD0aZmfBaF:TbC32rKx

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7250:jkUCARER5bBQRVMAARQCWQQxERVIAQFA2p4AITECAkYaAAgAcgkA1KUAApAAAFgAgUQjIS1XWxQKAAIHIENh4RqmAEoohLCI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:000000183c000000
Perceptual Hash:99cc663399cc6633
Difference Hash:000000322a080000
Wavelet Hash:0c0c0c1c1f070f0f
Color Hash:#9179d2

Other Hashes

Crop Resistant:000000322a080000

Scan History

Scan history not available

Unable to load historical scan data