Suspicious

Phishings targeting DocuSign

Suspicious and active websites


Phishings targeting Docusign

Suspicious and active websites


Active
6
New (7d)
3
Trend (7d)
About
AIE-signature target. Phishing mimics a 'document awaiting signature' notification — a well-worn wrapper for both credential harvest and malware delivery, since the fake link looks routine in a business inbox.
Countries
United StatesUnited States (4) · MalaysiaMalaysia (1) · BulgariaBulgaria (1)
TLS certs
YR1 (2) · YR2 (1) · WR3 (1)

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

Last check (UTC) First seen (UTC) URL Screenshot Flags Details
2026-09-22 01:02 2026-09-22 01:02
https://portalvox.com.br/docusign_redirect.html
Screenshot of portalvox.com.br OpenPhish Details
2026-09-21 21:30 2026-09-20 13:02
https://docusign-server.github.io/RFP2026
Screenshot of docusign-server.github.io OpenPhish Details
2026-09-21 21:30 2026-09-17 01:04
https://docusignfile-review-security-page--newstoolin.replit.app/?naps
Screenshot of docusignfile-review-security-page--newstoolin.replit.app OpenPhish urlscan Details
2026-09-21 21:30 2026-09-06 01:04
https://objectstorage.ap-kulai-2.oraclecloud.com/n/axqwdn9ov3iw/b/buc…
Screenshot of objectstorage.ap-kulai-2.oraclecloud.com OpenPhish Details
2026-09-21 21:30 2026-09-03 01:03
https://geotehnica.com/docusignreader
Screenshot of geotehnica.com OpenPhish Details
2026-09-21 21:30 2026-08-26 13:02
https://njj.standard.us-east-1.oortstorages.com/docusign.luk?EMAIL=da…
Screenshot of njj.standard.us-east-1.oortstorages.com OpenPhish Details

Suspicious sites — confidence is not always 100%. Use for Threat Hunting or watchlists.

URL Screenshot Details
https://portalvox.com.br/docu…
OpenPhish
Screenshot of portalvox.com.br Details
https://docusign-server.githu…
OpenPhish
Screenshot of docusign-server.github.io Details
https://docusignfile-review-s…
OpenPhish urlscan
Screenshot of docusignfile-review-security-page--newstoolin.replit.app Details
https://objectstorage.ap-kula…
OpenPhish
Screenshot of objectstorage.ap-kulai-2.oraclecloud.com Details
https://geotehnica.com/docusi…
OpenPhish
Screenshot of geotehnica.com Details
https://njj.standard.us-east-…
OpenPhish
Screenshot of njj.standard.us-east-1.oortstorages.com Details

AIHow to verify a real DocuSign URL

  • Legitimate DocuSign URLs always end in docusign.com (e.g. www.docusign.com, account.docusign.com). Anything else — including look-alike typosquats, hyphenated variations, or unfamiliar TLDs like .xyz / .top / .vip — is not DocuSign.
  • The padlock icon proves TLS is active, not that the site is safe. Free DV certificates are issued to attackers in minutes; every active site listed above has a valid TLS certificate.
  • If you got the link from email, SMS, or social media, do not click it. Open docusign.com from your browser bookmark or type the domain manually.
  • Real DocuSign pages almost never ask for credentials immediately after clicking from a message — treat any such redirect as a phishing attempt until the domain is verified.