IOC Report
https://www.docusign.net/Signing/EmailStart.aspx?a=f176c56b-b71d-44e1-9c45-e2efc3d4ff81&acct=ee915e91-2c9c-458d-81ca-6faa60f27a9e&er=6172ccaa-1aa9-4c65-9f82-00c40e81b808

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 12 18:31:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 12 18:31:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 12 18:31:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 12 18:31:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Feb 12 18:31:01 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (5663)
downloaded
Chrome Cache Entry: 130
ASCII text
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (1281), with no line terminators
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (50871), with NEL line terminators
downloaded
Chrome Cache Entry: 133
PNG image data, 294 x 38, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 134
ASCII text, with very long lines (473)
downloaded
Chrome Cache Entry: 135
Unicode text, UTF-8 text, with very long lines (29606)
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (65446)
downloaded
Chrome Cache Entry: 137
Web Open Font Format, CFF, length 34820, version 0.0
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (33778)
downloaded
Chrome Cache Entry: 140
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (65380)
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (65380)
downloaded
Chrome Cache Entry: 143
Web Open Font Format, CFF, length 29496, version 1.200
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (32029), with CRLF line terminators
downloaded
Chrome Cache Entry: 145
PNG image data, 231 x 76, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 146
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 147
Web Open Font Format, TrueType, length 47748, version 1.0
downloaded
Chrome Cache Entry: 148
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 149
JSON data
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (569)
downloaded
Chrome Cache Entry: 152
gzip compressed data, was "tmp7zukgsan", last modified: Wed Jan 31 15:14:40 2024, max compression, original size modulo 2^32 255107
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (64827)
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (6423)
downloaded
Chrome Cache Entry: 156
ASCII text
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (1207)
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 161
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 162
JSON data
dropped
Chrome Cache Entry: 163
ASCII text, with very long lines (607)
downloaded
Chrome Cache Entry: 164
PNG image data, 260 x 58, 8-bit/color RGBA, interlaced
downloaded
Chrome Cache Entry: 165
Web Open Font Format, CFF, length 33752, version 0.0
downloaded
Chrome Cache Entry: 166
Web Open Font Format, TrueType, length 44632, version 1.0
downloaded
Chrome Cache Entry: 167
Unicode text, UTF-8 text, with very long lines (25824)
downloaded
Chrome Cache Entry: 168
JSON data
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (65380)
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 173
ASCII text
downloaded
Chrome Cache Entry: 174
HTML document, ASCII text, with very long lines (486), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 176
JSON data
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (21475)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (26453)
downloaded
Chrome Cache Entry: 179
PNG image data, 300 x 188, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 180
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 181
ASCII text
downloaded
Chrome Cache Entry: 182
Web Open Font Format, TrueType, length 37560, version 1.0
downloaded
Chrome Cache Entry: 183
PNG image data, 10 x 10, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 184
MS Windows icon resource - 3 icons, 48x48, 8 bits/pixel, 32x32, 8 bits/pixel
downloaded
Chrome Cache Entry: 185
ASCII text
dropped
Chrome Cache Entry: 186
ASCII text, with very long lines (5955)
downloaded
Chrome Cache Entry: 187
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (45076)
downloaded
Chrome Cache Entry: 190
ASCII text
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (688)
downloaded
Chrome Cache Entry: 192
ASCII text, with very long lines (40042)
downloaded
Chrome Cache Entry: 193
JSON data
downloaded
Chrome Cache Entry: 195
PNG image data, 132 x 120, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 196
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (941)
downloaded
Chrome Cache Entry: 198
JSON data
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 201
ASCII text, with very long lines (47916)
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (566)
downloaded
Chrome Cache Entry: 204
JSON data
downloaded
Chrome Cache Entry: 205
ASCII text, with very long lines (65380)
downloaded
Chrome Cache Entry: 207
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 208
PNG image data, 511 x 518, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 209
Unicode text, UTF-8 text, with very long lines (65504), with no line terminators
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 212
PNG image data, 132 x 120, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 213
ASCII text, with very long lines (32180)
downloaded
Chrome Cache Entry: 214
gzip compressed data, original size modulo 2^32 7690
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (65380)
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (533)
downloaded
Chrome Cache Entry: 219
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 221
HTML document, Unicode text, UTF-8 text, with very long lines (5753), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 222
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 223
ASCII text, with very long lines (56853)
downloaded
Chrome Cache Entry: 224
JSON data
dropped
Chrome Cache Entry: 226
ASCII text, with very long lines (638)
downloaded
Chrome Cache Entry: 231
JSON data
downloaded
Chrome Cache Entry: 232
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 234
ASCII text, with very long lines (21778), with no line terminators
downloaded
Chrome Cache Entry: 235
GIF image data, version 89a, 1 x 1
downloaded
There are 82 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://www.docusign.net/Signing/EmailStart.aspx?a=f176c56b-b71d-44e1-9c45-e2efc3d4ff81&acct=ee915e91-2c9c-458d-81ca-6faa60f27a9e&er=6172ccaa-1aa9-4c65-9f82-00c40e81b808
https://support.docusign.com/apex/zoomin_app__ZoominGAPage
https://www.docusign.net/Signing/Error.aspx?e=deaceb1e-6a2f-4c66-99df-8d8573ce0452&scope=67618838-2420-409e-8828-e30b08045801
about:blank
https://www.docusign.net/Signing/SessionTimeout.aspx?scope=67618838-2420-409e-8828-e30b08045801
https://support.docusign.com/s/?language=en_US

Domains

Name
IP
Malicious
p01k.hs.eloqua.com
192.29.14.118
accounts.google.com
172.217.215.84
api-js.mixpanel.com
107.178.240.159
edge.fullstory.com
35.201.112.186
ia4.edge2.salesforce.com
13.109.180.6
arya-1323461286.us-west-2.elb.amazonaws.com
54.148.144.53
stats.g.doubleclick.net
74.125.138.155
rs.fullstory.com
35.186.194.58
analytics-alv.google.com
216.239.38.181
www.google.com
74.125.136.147
cdn4.mxpnl.com
130.211.5.208
api.mixpanel.com
35.186.241.51
clients.l.google.com
74.125.138.102
geo-1040374038.us-west-2.elb.amazonaws.com
35.83.136.158
cdn.cookielaw.org
104.18.130.236
geolocation.onetrust.com
172.64.155.119
clients1.google.com
unknown
support.docusign.com
unknown
geo.docusign.com
unknown
track.docusign.com
unknown
img.en25.com
unknown
www.docusign.net
unknown
www.docusign.com
unknown
clients2.google.com
unknown
a.docusign.com
unknown
docucdn-a.akamaihd.net
unknown
analytics.google.com
unknown
There are 17 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
23.209.188.5
unknown
United States
35.186.241.51
api.mixpanel.com
United States
151.101.130.133
unknown
United States
130.211.34.183
unknown
United States
104.18.130.236
cdn.cookielaw.org
United States
172.217.215.106
unknown
United States
35.186.194.58
rs.fullstory.com
United States
192.168.2.16
unknown
unknown
216.239.38.181
analytics-alv.google.com
United States
130.211.5.208
cdn4.mxpnl.com
United States
13.109.180.6
ia4.edge2.salesforce.com
United States
107.178.240.159
api-js.mixpanel.com
United States
142.250.9.94
unknown
United States
74.125.136.147
www.google.com
United States
35.83.136.158
geo-1040374038.us-west-2.elb.amazonaws.com
United States
142.251.15.147
unknown
United States
192.29.14.118
p01k.hs.eloqua.com
United States
74.125.138.155
stats.g.doubleclick.net
United States
74.125.138.102
clients.l.google.com
United States
74.125.136.94
unknown
United States
1.1.1.1
unknown
Australia
142.250.105.97
unknown
United States
74.125.136.139
unknown
United States
142.250.105.101
unknown
United States
173.194.219.102
unknown
United States
172.64.155.119
geolocation.onetrust.com
United States
23.79.48.90
unknown
United States
35.201.112.186
edge.fullstory.com
United States
239.255.255.250
unknown
Reserved
23.223.31.252
unknown
United States
151.101.2.133
unknown
United States
54.148.144.53
arya-1323461286.us-west-2.elb.amazonaws.com
United States
108.177.122.94
unknown
United States
162.248.184.178
unknown
United States
108.177.122.95
unknown
United States
172.217.215.84
accounts.google.com
United States
There are 26 hidden IPs, click here to show them.