DocuSign Plus Invoice: A 12-Day-Old Domain and an esvalabs Redirect Chain That Scanners Missed
ID: cb383750-2c1d-5638-919e-1ef71131990e
STIX ID: report--cb383750-2c1d-5638-919e-1ef71131990e
Feed Name: IRONSCALES
Threat Score
A high-severity phishing campaign used a dual pretext (DocuSign notification + invoice thread), a clean PDF attachment as legitimacy, and a multi-hop redirect chain via urlsand.esvalabs.com to deliver credential-harvesting pages; the sender domain twitterbugg.com was a 12-day-old, privacy-protected registration sending authenticated email through Amazon SES, and Themis quarantined the messages after identifying the converging suspicious signals.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
