IOC Report
https://www.docusign.net/Signing/EmailStart.aspx?a=468f8847-c3e7-4714-847d-595d8340ad46&etti=24&acct=d5bf1001-4e62-4986-9942-0a2accf78f43&er=b62a6350-ed0b-4482-b295-7844ad412faf

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 127
ASCII text, with very long lines (6455)
downloaded
Chrome Cache Entry: 128
HTML document, ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (16718)
downloaded
Chrome Cache Entry: 130
Unicode text, UTF-8 text, with very long lines (65452)
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 132
ASCII text, with very long lines (52240)
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 134
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 135
ASCII text
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (57931)
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (9377)
dropped
Chrome Cache Entry: 139
ASCII text, with very long lines (57931)
downloaded
Chrome Cache Entry: 140
Unicode text, UTF-8 text, with very long lines (63087)
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (631), with no line terminators
downloaded
Chrome Cache Entry: 142
Unicode text, UTF-8 text, with very long lines (65439)
dropped
Chrome Cache Entry: 143
Unicode text, UTF-8 text, with very long lines (30984)
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (19766)
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (65440)
downloaded
Chrome Cache Entry: 147
Unicode text, UTF-8 text, with very long lines (63087)
downloaded
Chrome Cache Entry: 148
Unicode text, UTF-8 text, with very long lines (16888)
downloaded
Chrome Cache Entry: 149
ASCII text
downloaded
Chrome Cache Entry: 150
Unicode text, UTF-8 text, with very long lines (65439)
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 152
ASCII text, with very long lines (27974)
dropped
Chrome Cache Entry: 153
Unicode text, UTF-8 text, with very long lines (65446)
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (6455)
dropped
Chrome Cache Entry: 155
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (19766)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (7965)
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (20560)
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 160
Unicode text, UTF-8 text, with very long lines (13863)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 162
Unicode text, UTF-8 text, with very long lines (30984)
downloaded
Chrome Cache Entry: 163
Unicode text, UTF-8 text, with very long lines (65452)
dropped
Chrome Cache Entry: 164
JSON data
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (65446)
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (46070)
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (32844)
dropped
Chrome Cache Entry: 170
ASCII text, with very long lines (65443)
dropped
Chrome Cache Entry: 171
Unicode text, UTF-8 text, with very long lines (13863)
dropped
Chrome Cache Entry: 172
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 174
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (17329)
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (46070)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (65440)
dropped
Chrome Cache Entry: 180
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 181
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 182
JSON data
dropped
Chrome Cache Entry: 183
ASCII text, with very long lines (17329)
dropped
Chrome Cache Entry: 184
Unicode text, UTF-8 text, with very long lines (65169)
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (65446)
dropped
Chrome Cache Entry: 186
ASCII text, with very long lines (27974)
downloaded
Chrome Cache Entry: 187
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 188
Unicode text, UTF-8 text, with very long lines (65169)
downloaded
Chrome Cache Entry: 189
Unicode text, UTF-8 text, with very long lines (65433)
downloaded
Chrome Cache Entry: 190
Unicode text, UTF-8 text, with very long lines (65433)
dropped
Chrome Cache Entry: 191
ASCII text, with very long lines (7965)
downloaded
Chrome Cache Entry: 192
ASCII text, with very long lines (65438)
dropped
Chrome Cache Entry: 193
ASCII text, with very long lines (20560)
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (9667)
downloaded
Chrome Cache Entry: 195
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 196
ASCII text, with very long lines (65438)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (631), with no line terminators
dropped
Chrome Cache Entry: 198
ASCII text, with very long lines (9377)
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (30012)
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 201
ASCII text, with very long lines (52240)
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (16718)
dropped
Chrome Cache Entry: 203
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 204
Unicode text, UTF-8 text, with very long lines (16888)
dropped
Chrome Cache Entry: 205
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 206
ASCII text, with very long lines (9667)
dropped
Chrome Cache Entry: 207
HTML document, ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 209
ASCII text, with very long lines (32844)
downloaded
Chrome Cache Entry: 210
ASCII text, with very long lines (30012)
dropped
Chrome Cache Entry: 211
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 212
SVG Scalable Vector Graphics image
downloaded
There are 77 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1860 --field-trial-handle=2064,i,11361945895874972093,6294843009696709850,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.docusign.net/Signing/EmailStart.aspx?a=468f8847-c3e7-4714-847d-595d8340ad46&etti=24&acct=d5bf1001-4e62-4986-9942-0a2accf78f43&er=b62a6350-ed0b-4482-b295-7844ad412faf"

URLs

Name
IP
Malicious
https://www.docusign.net/Signing/EmailStart.aspx?a=468f8847-c3e7-4714-847d-595d8340ad46&etti=24&acct=d5bf1001-4e62-4986-9942-0a2accf78f43&er=b62a6350-ed0b-4482-b295-7844ad412faf
https://developer.mozilla.org/en-US/docs/DOM/XMLHttpRequest#withCredentials
unknown
http://documentcloud.github.com/underscore/
unknown
http://www.ecma-international.org/ecma-262/5.1/#sec-12.4
unknown
https://github.com/douglascrockford/JSON-js/blob/master/json_parse.js
unknown
https://gist.github.com/1930440
unknown
https://github.com/zloirock/core-js
unknown
https://www.docusign.net/Signing/?ti=baa7c2977e5d4d55bfc1221898f85a69
http://dbj.org/dbj/?p=286
unknown
http://hacks.mozilla.org/2009/07/cross-site-xmlhttprequest-with-cors/
unknown
https://cdn.optimizely.com/datafiles/MUGKFLCdCtxUSgrSTyhbw.json
104.18.65.57
https://a.docusign.com/ds_arya_wrapper.min.js?f=1
52.35.199.106
http://dean.edwards.name/weblog/2005/10/add-event/
unknown
https://github.com/zloirock/core-js/blob/v3.30.2/LICENSE
unknown
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cdn.optimizely.com
104.18.65.57
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
142.250.186.68
api.mixpanel.com
35.186.241.51
fp2e7a.wpc.phicdn.net
192.229.221.95
arya-1323461286.us-west-2.elb.amazonaws.com
52.35.199.106
a.docusign.com
unknown
www.docusign.net
unknown
docucdn-a.akamaihd.net
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
35.186.241.51
api.mixpanel.com
United States
104.18.66.57
unknown
United States
104.18.65.57
cdn.optimizely.com
United States
52.35.199.106
arya-1323461286.us-west-2.elb.amazonaws.com
United States
52.42.45.237
unknown
United States
192.168.2.6
unknown
unknown
35.190.25.25
unknown
United States
239.255.255.250
unknown
Reserved
142.250.186.100
unknown
United States

DOM / HTML

URL
Malicious
https://www.docusign.net/Signing/?ti=baa7c2977e5d4d55bfc1221898f85a69
https://www.docusign.net/Signing/?ti=baa7c2977e5d4d55bfc1221898f85a69