IOC Report
https://na2.docusign.net/Signing/EmailStart.aspx?a=c6104538-ac3b-4407-b24b-a0b641ee4589&etti=24&acct=7853161b-6814-4528-85bc-ffe96cfca42f&er=09ab18a7-8de5-4c92-931d-cb9cd9f7b00d

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 145
ASCII text, with very long lines (6455)
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (21847)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (12839)
dropped
Chrome Cache Entry: 148
HTML document, ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (16718)
downloaded
Chrome Cache Entry: 150
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 151
Unicode text, UTF-8 text, with very long lines (65452)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (52240)
dropped
Chrome Cache Entry: 154
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 155
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 156
ASCII text
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (57931)
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (9377)
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (57931)
downloaded
Chrome Cache Entry: 161
Unicode text, UTF-8 text, with very long lines (63087)
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (631), with no line terminators
downloaded
Chrome Cache Entry: 163
Unicode text, UTF-8 text, with very long lines (65439)
dropped
Chrome Cache Entry: 164
Unicode text, UTF-8 text, with very long lines (30984)
dropped
Chrome Cache Entry: 165
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (19766)
dropped
Chrome Cache Entry: 167
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (65440)
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 170
GIF image data, version 89a, 145 x 60
downloaded
Chrome Cache Entry: 171
Unicode text, UTF-8 text, with very long lines (63087)
downloaded
Chrome Cache Entry: 172
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 173
Unicode text, UTF-8 text, with very long lines (16888)
downloaded
Chrome Cache Entry: 174
ASCII text
downloaded
Chrome Cache Entry: 175
Unicode text, UTF-8 text, with very long lines (65439)
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 177
ASCII text, with very long lines (27974)
dropped
Chrome Cache Entry: 178
Unicode text, UTF-8 text, with very long lines (65446)
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (6455)
dropped
Chrome Cache Entry: 180
GIF image data, version 89a, 180 x 180
dropped
Chrome Cache Entry: 181
ASCII text, with very long lines (12839)
downloaded
Chrome Cache Entry: 182
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 183
GIF image data, version 89a, 180 x 180
downloaded
Chrome Cache Entry: 184
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (19766)
downloaded
Chrome Cache Entry: 186
ASCII text, with very long lines (7965)
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (20560)
dropped
Chrome Cache Entry: 188
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 189
Unicode text, UTF-8 text, with very long lines (13863)
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 191
Unicode text, UTF-8 text, with very long lines (30984)
downloaded
Chrome Cache Entry: 192
Unicode text, UTF-8 text, with very long lines (65452)
dropped
Chrome Cache Entry: 193
JSON data
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (65446)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (17950)
downloaded
Chrome Cache Entry: 198
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (46070)
dropped
Chrome Cache Entry: 200
ASCII text, with very long lines (32844)
dropped
Chrome Cache Entry: 201
ASCII text, with very long lines (65443)
dropped
Chrome Cache Entry: 202
Unicode text, UTF-8 text, with very long lines (13863)
dropped
Chrome Cache Entry: 203
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (17950)
dropped
Chrome Cache Entry: 205
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 206
Web Open Font Format (Version 2), TrueType, length 29516, version 1.0
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (17329)
downloaded
Chrome Cache Entry: 210
ASCII text, with very long lines (46070)
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 212
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 213
Web Open Font Format (Version 2), TrueType, length 31468, version 1.0
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (65440)
dropped
Chrome Cache Entry: 215
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 217
JSON data
dropped
Chrome Cache Entry: 218
ASCII text, with very long lines (17329)
dropped
Chrome Cache Entry: 219
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 220
ASCII text
downloaded
Chrome Cache Entry: 221
Unicode text, UTF-8 text, with very long lines (65169)
dropped
Chrome Cache Entry: 222
ASCII text, with very long lines (65446)
dropped
Chrome Cache Entry: 223
ASCII text, with very long lines (27974)
downloaded
Chrome Cache Entry: 224
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 225
Unicode text, UTF-8 text, with very long lines (65169)
downloaded
Chrome Cache Entry: 226
Unicode text, UTF-8 text, with very long lines (65446)
dropped
Chrome Cache Entry: 227
Unicode text, UTF-8 text, with very long lines (65433)
downloaded
Chrome Cache Entry: 228
Unicode text, UTF-8 text, with very long lines (65433)
dropped
Chrome Cache Entry: 229
ASCII text, with very long lines (7965)
downloaded
Chrome Cache Entry: 230
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 231
ASCII text
dropped
Chrome Cache Entry: 232
ASCII text, with very long lines (65438)
dropped
Chrome Cache Entry: 233
ASCII text, with very long lines (20560)
downloaded
Chrome Cache Entry: 234
GIF image data, version 89a, 145 x 60
dropped
Chrome Cache Entry: 235
ASCII text, with very long lines (9667)
downloaded
Chrome Cache Entry: 236
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 237
ASCII text, with very long lines (65438)
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (631), with no line terminators
dropped
Chrome Cache Entry: 239
ASCII text, with very long lines (9377)
downloaded
Chrome Cache Entry: 240
ASCII text, with very long lines (30012)
downloaded
Chrome Cache Entry: 241
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (52240)
downloaded
Chrome Cache Entry: 243
ASCII text, with very long lines (16718)
dropped
Chrome Cache Entry: 244
ASCII text, with very long lines (65457)
dropped
Chrome Cache Entry: 245
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 246
Unicode text, UTF-8 text, with very long lines (16888)
dropped
Chrome Cache Entry: 247
ASCII text, with very long lines (11612)
downloaded
Chrome Cache Entry: 248
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 249
ASCII text, with very long lines (9667)
dropped
Chrome Cache Entry: 250
HTML document, ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 251
Web Open Font Format, TrueType, length 13780, version 1.0
downloaded
Chrome Cache Entry: 252
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 253
ASCII text, with very long lines (32844)
downloaded
Chrome Cache Entry: 254
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 255
ASCII text, with very long lines (30012)
dropped
Chrome Cache Entry: 256
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (21847)
dropped
Chrome Cache Entry: 258
Web Open Font Format, CFF, length 33752, version 0.0
downloaded
Chrome Cache Entry: 259
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 260
HTML document, ASCII text, with very long lines (7195), with CRLF line terminators
downloaded
Chrome Cache Entry: 261
ASCII text, with very long lines (11612)
dropped
Chrome Cache Entry: 262
SVG Scalable Vector Graphics image
downloaded
There are 109 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1924,i,11185015050101401236,4459558692237115738,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://na2.docusign.net/Signing/EmailStart.aspx?a=c6104538-ac3b-4407-b24b-a0b641ee4589&etti=24&acct=7853161b-6814-4528-85bc-ffe96cfca42f&er=09ab18a7-8de5-4c92-931d-cb9cd9f7b00d"

URLs

Name
IP
Malicious
https://na2.docusign.net/Signing/EmailStart.aspx?a=c6104538-ac3b-4407-b24b-a0b641ee4589&etti=24&acct=7853161b-6814-4528-85bc-ffe96cfca42f&er=09ab18a7-8de5-4c92-931d-cb9cd9f7b00d
malicious
https://developer.mozilla.org/en-US/docs/DOM/XMLHttpRequest#withCredentials
unknown
https://na2.docusign.net/Signing/?ti=c153824e93da45f49fc9777af7b40c3f
http://documentcloud.github.com/underscore/
unknown
http://www.ecma-international.org/ecma-262/5.1/#sec-12.4
unknown
https://github.com/douglascrockford/JSON-js/blob/master/json_parse.js
unknown
https://docucdn-a.akamaihd.net/production/1ds/widgets/
unknown
https://gist.github.com/1930440
unknown
https://github.com/zloirock/core-js
unknown
https://na2.docusign.net
unknown
https://wdk-agent-2.docusigntest.com/#Signing/Controllers/MonitoringController.cs
unknown
http://dbj.org/dbj/?p=286
unknown
http://hacks.mozilla.org/2009/07/cross-site-xmlhttprequest-with-cors/
unknown
https://cdn.optimizely.com/datafiles/MUGKFLCdCtxUSgrSTyhbw.json
104.18.66.57
https://apps.docusign.com/cdn/production/1ds/widgets/
unknown
https://a.docusign.com/ds_arya_wrapper.min.js?f=1
52.42.45.237
http://dean.edwards.name/weblog/2005/10/add-event/
unknown
https://github.com/zloirock/core-js/blob/v3.30.2/LICENSE
unknown
There are 7 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
cdn.optimizely.com
104.18.66.57
www.google.com
142.250.185.196
api.mixpanel.com
130.211.34.183
fp2e7a.wpc.phicdn.net
192.229.221.95
arya-1323461286.us-west-2.elb.amazonaws.com
52.42.45.237
a.docusign.com
unknown
docucdn-a.akamaihd.net
unknown
na2.docusign.net
unknown

IPs

IP
Domain
Country
Malicious
35.186.241.51
unknown
United States
104.18.66.57
cdn.optimizely.com
United States
130.211.34.183
api.mixpanel.com
United States
52.42.45.237
arya-1323461286.us-west-2.elb.amazonaws.com
United States
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
142.250.186.100
unknown
United States

DOM / HTML

URL
Malicious
https://na2.docusign.net/Signing/?ti=c153824e93da45f49fc9777af7b40c3f
https://na2.docusign.net/Signing/?ti=c153824e93da45f49fc9777af7b40c3f
https://na2.docusign.net/Signing/?ti=c153824e93da45f49fc9777af7b40c3f
https://na2.docusign.net/Signing/?ti=c153824e93da45f49fc9777af7b40c3f