Phishing detection: cvmac.id
DocuSign Investigate
Domain
cvmac.id4 CT hosts on apex
IP
41.216.184.159
URL
https://cvmac.id/wp-includes/docusign/Windows/utility.php
Cert
YR2
Phishunt analysis Beta
18
noiseheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +4.1 Brand in screenshot
- +3.0 OpenPhish
- +1.1 ASN reputation
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.7 Bulletproof DNS
- +0.6 Brand impersonation in path
- +0.6 Registrar reputation
- +0.6 Suspicious TLD
- +0.2 Long domain
- +0.2 Executable page
13 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
A PHP script embedded in a WordPress site impersonates DocuSign to harvest credentials, with the brand appearing only in the URL path rather than the host. Hosted on Psychz Networks (ASN 40676) and confirmed malicious by OpenPhish.
OpenPhishBrand impersonation in pathExecutable page
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-27 · confidence 60%
Domain & Network
Whois
Registrar
PT Digital Registra Indonesia
Network
Country
United States
Hosting
Psychz Networks
ASN
AS40676
TLS Cert
YR2
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise