Phishing detection: ptai.in

DocuSign
https://ptai.in/docusign_redirect.html Access site
Screenshot
Screenshot of ptai.in
Phishunt analysis Beta
95 critical suspicion phishingheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 Site cluster
  • +5.1 Kit captured
  • +4.1 Brand in screenshot
  • +3.0 OpenPhish
  • +1.1 ASN reputation
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.9 Young certificate
  • +0.7 Unrecognised DNS provider
  • +0.6 Brand impersonation in path
  • +0.6 Registrar reputation
  • +0.6 Suspicious TLD
  • +0.3 Free CA
  • +0.1 Long domain
  • +0.1 External scripts
  • Boosted to 95: Kit captured
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site hosted on Oracle infrastructure uses a DocuSign-branded redirect path to impersonate the e-signature service. The brand appears only in the URL path on an otherwise unrelated domain. Confirmed malicious by OpenPhish, likely harvesting credentials under the DocuSign brand.

Brand impersonation in pathOpenPhishKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-23 · confidence 78%
Domain & Network
Whois
Registrar GoDaddy
Network
Country United StatesUnited States
ASN AS31898
TLS Cert YR2
External detection OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Report this phishing
Network / ASN Oracle Corporation

Tracked from 2026-09-23 13:03 UTC  ·  Last refreshed 2026-10-04 15:30 UTC