logo

DocuSign Plus Invoice: A 12-Day-Old Domain and an esvalabs Redirect Chain That Scanners Missed

ID: cb383750-2c1d-5638-919e-1ef71131990e

STIX ID: report--cb383750-2c1d-5638-919e-1ef71131990e

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: [email protected] (Audian Paxson)

...
...

A high-severity phishing campaign used a dual pretext (DocuSign notification + invoice thread), a clean PDF attachment as legitimacy, and a multi-hop redirect chain via urlsand.esvalabs.com to deliver credential-harvesting pages; the sender domain twitterbugg.com was a 12-day-old, privacy-protected registration sending authenticated email through Amazon SES, and Themis quarantined the messages after identifying the converging suspicious signals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.