Security Scan Report: docusign-9vs.jhon1213488-outlook-com-s-account.workers.dev

Site favicon
Submitted: Oct 1, 2026, 9:18:20 AMCompleted: Oct 1, 2026, 9:19:24 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

DocuSign-branded device-code phishing kit (EvilToken) on a disposable *.workers.dev subdomain, confirmed by kit-roster match, EvilTokens_Ghost_Loader YARA hit, and HIGH ET PHISHING device-code IDS alerts. Do not enter codes or authorise Microsoft sign-in.

Risk Factors (5)
Brand impersonation of DocuSign on a non-DocuSign domain
Known phishing kit (Cloudflare Workers device-code / EvilToken) identified by analyst-vetted roster
EvilTokens_Ghost_Loader YARA malware pattern in page script
HIGH IDS alerts for generic device-code phishing landing page
Disposable hosting-platform subdomain with random/gibberish namespace embedding an email-like string
Domain age information unavailable

Details

Page Title

DocuSign - Review Document

Scan Type

public

Domain Name Analysis

The domain 'docusign-9vs.jhon1213488-outlook-com-s-account.workers.dev' uses the developer-focused generic top-level domain (.dev); it also runs on subdomain 'docusign-9vs.jhon1213488-outlook-com-s-account'. The second-level label 'workers' is 7 characters long with 2 vowels and 5 consonants. Splitting it apart reveals one word: workers. Median word length comes out to seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://docusign-9vs.jhon1213488-outlook-com-s-account.workers.dev/c1f3f4af0aa29477

Page Load Overview

2.52s
Total Load Time
164 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:511 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software56% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
56%
documentation technical
52%
cryptocurrency blockchain
47%
government public service
36%
corporate business
29%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4172.67.182.149Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
174.125.29.95Google · CDNUnited States
AS15169Google LLC
1142.251.13.94Google · CDNUnited States
AS15169Google LLC
1104.21.36.4Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
85--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F5A27C72B258183D3A2789C2F63073ED705582ABE95B604479BD2378C0C9DABDD37798

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:KzbOtg/doyD172kI6L23GQ2w+hA8JTdmQ22ugAmLiU:KfOqhB72j6Q2wsAATdmQ22ugPLiU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21928:YYUDpAUAKRQHAKFBQCiSx1RWQwBECLRgkwGaAgbPYEElAwAkKIdA4rgYRnBEgARyFKi0J5oKAsIKBQgCAAQoigBCgYBRJImI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffef1818180000
Perceptual Hash:999ca60c9e1c9e3e
Difference Hash:20041832a2300008
Wavelet Hash:ffffef5d18180000
Color Hash:#ac7a53

Other Hashes

Crop Resistant:20041832a2300008

Scan History

Scan history not available

Unable to load historical scan data