Phishing detection: cvmac.id

DocuSign
https://cvmac.id/wp-includes/docusign/Windows/utility.php Access site
Screenshot
Screenshot of cvmac.id
Investigate
URL https://cvmac.id/wp-includes/docusign/Windows/utility.php
Phishunt analysis Beta
18 noiseheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +4.1 Brand in screenshot
  • +3.0 OpenPhish
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.7 Bulletproof DNS
  • +0.6 Brand impersonation in path
  • +0.6 Registrar reputation
  • +0.6 Suspicious TLD
  • +0.2 Long domain
  • +0.2 Executable page
13 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

A PHP script embedded in a WordPress site impersonates DocuSign to harvest credentials, with the brand appearing only in the URL path rather than the host. Hosted on Psychz Networks (ASN 40676) and confirmed malicious by OpenPhish.

OpenPhishBrand impersonation in pathExecutable page
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-27 · confidence 60%
Domain & Network
Whois
Network
Country United StatesUnited States
Hosting Psychz Networks
ASN AS40676
TLS Cert YR2
External detection OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-08-27 01:09 UTC  ·  Last refreshed 2026-08-28 09:30 UTC