Alert: New Phishing Campaigns Discovered

DocuSign has discovered several new phishing campaigns that spoof DocuSign and are COVID-related. All below campaigns were found in the wild. Details are shared for each below.

  1. From: "Payment Request via DocuSign" <user[@]puabenefit-pay8645752893[.]info> or <filling[@]serv-docpay873644[.]com>
    Reply-to: user[@]doc-pay[.]info
    Sent: Thursday, May 21
    Subject: "RE: YOUR COVID19 PAYMENT FILLING STATUS" or "COVID-19 HEALTH PAYMENT STATUS" or similar
    Link displays as: hxxps://mindscriptstech[.]com/wp-admin/documen0t9853/doc-new/
     
  2. From: "DocuSign Via Arnulfo Smitham" <docusign-donot-reply[@]Yourpad[.]com>
    Sent: Thursday, May 21
    Subject: "Affidavit_for_Covid-19 from Yourpad[.]com" or similar
    Link displays as: hxxps://bit[.]ly/3bnBEsw
    Links redirects to: hxxps://realestatesproperties[.]estate/x787xe8ruh22@/11d4b7f8a0da369d11a95c2ee2267796/
    95aed2504a6a43d4034b22cacbba5607/login.php?cmd=login_submit&id=5aea4dece5073ba5a0f7113d90b4b62
    35aea4dece5073ba5a0f7113d90b4b623&session=5aea4dece5073ba5a0f7113d90b4b6235aea4dece5073ba5a0f
    7113d90b4b623
     
  3. From: "KEVIN WATSON" <grayshillrealty[@]yahoo[.]com>
    Sent: Wednesday, May 20
    Subject: "Re:  Docu  sign. :Complete : File NO 8874871 COVID-19 Report ,termi AND HUD approver QWKLDQXPSO" or similiar
    Link displays as: No URL was provided in the message