Phishing detection: ptai.in
DocuSign Investigate
Domain
ptai.in1 CT host on apex
IP
192.185.146.129
URL
https://ptai.in/docusign_redirect.html
Cert
YR2
Phishunt analysis Beta
95
critical suspicion phishingheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +5.1 Kit captured
- +4.1 Brand in screenshot
- +3.0 OpenPhish
- +1.1 ASN reputation
- +1.1 No CSP header
- +1.1 No HSTS header
- +0.9 Young certificate
- +0.7 Unrecognised DNS provider
- +0.6 Brand impersonation in path
- +0.6 Registrar reputation
- +0.6 Suspicious TLD
- +0.3 Free CA
- +0.1 Long domain
- +0.1 External scripts
- Boosted to 95: Kit captured
Kit archived:
2026/202609/ptai.in (dsb.zip)
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Site hosted on Oracle infrastructure uses a DocuSign-branded redirect path to impersonate the e-signature service. The brand appears only in the URL path on an otherwise unrelated domain. Confirmed malicious by OpenPhish, likely harvesting credentials under the DocuSign brand.
Brand impersonation in pathOpenPhishKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-23 · confidence 78%
Domain & Network
Whois
Registrar
GoDaddy
Network
Country
United States
Hosting
Oracle Corporation
ASN
AS31898
TLS Cert
YR2
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise