Suspicious

Phishings targeting DocuSign

Suspicious and active websites


Phishings targeting Docusign

Suspicious and active websites


Active
5
New (7d)
4
Trend (7d)
About
AIE-signature target. Phishing mimics a 'document awaiting signature' notification — a well-worn wrapper for both credential harvest and malware delivery, since the fake link looks routine in a business inbox.
Countries
United StatesUnited States (5)
TLS certs
YR2 (1) · YE1 (1) · WE1 (1)

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details
2026-09-01 21:30 2026-08-29 01:03
http://pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev/New-DocusignRedir2…
Screenshot of pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev OpenPhish TweetFeed Details
2026-09-01 21:30 2026-08-27 01:09
https://cvmac.id/wp-includes/docusign/Windows/utility.php
Screenshot of cvmac.id OpenPhish Details
2026-09-01 21:30 2026-08-26 13:02
https://njj.standard.us-east-1.oortstorages.com/docusign.luk?EMAIL=da…
Screenshot of njj.standard.us-east-1.oortstorages.com OpenPhish Details
2026-09-01 21:30 2026-08-26 13:02
https://docusign.login.adrpowersystem.com
Screenshot of docusign.login.adrpowersystem.com OpenPhish urlscan Details
2026-09-01 21:30 2026-08-13 15:11
https://071439625396510-na4-docusign-signingwe6ee67wd.pages.dev
Screenshot of 071439625396510-na4-docusign-signingwe6ee67wd.pages.dev urlscan Details

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

URL Screenshot Details
http://pub-d68525cbc6144dcaaa…
OpenPhish TweetFeed
Screenshot of pub-d68525cbc6144dcaaac2fc0354aa17dd.r2.dev Details
https://cvmac.id/wp-includes/…
OpenPhish
Screenshot of cvmac.id Details
https://njj.standard.us-east-…
OpenPhish
Screenshot of njj.standard.us-east-1.oortstorages.com Details
https://docusign.login.adrpow…
OpenPhish urlscan
Screenshot of docusign.login.adrpowersystem.com Details
https://071439625396510-na4-d…
urlscan
Screenshot of 071439625396510-na4-docusign-signingwe6ee67wd.pages.dev Details

AIHow to verify a real DocuSign URL

  • Legitimate DocuSign URLs always end in docusign.com (e.g. www.docusign.com, account.docusign.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not DocuSign.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open docusign.com from your browser bookmark or type the domain manually.
  • Real DocuSign pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.