IOC Report
https://app.hellosign.com/t/12d97f79eb97705150d8f8046b386cc7edf916a9?utm_campaign=multisigner_complete&utm_source=default&utm_channel=product_promo&utm_medium=email&utm_content=original

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:18:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:18:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:18:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:18:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 12:18:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 121
ASCII text, with very long lines (1353)
downloaded
Chrome Cache Entry: 122
PNG image data, 1275 x 1650, 8-bit grayscale, non-interlaced
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (519)
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (2186)
downloaded
Chrome Cache Entry: 125
ASCII text
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (544)
downloaded
Chrome Cache Entry: 127
TrueType Font data, digitally signed, 21 tables, 1st "DSIG", 54 names, Macintosh, \251 2006 Microsoft Corporation. All Rights Reserved.GeorgiaRegularAscender - Georgia RegularVer
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (2334)
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (30377)
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (2314)
downloaded
Chrome Cache Entry: 131
JSON data
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (16909)
downloaded
Chrome Cache Entry: 133
PNG image data, 458 x 58, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (15368)
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (40479)
downloaded
Chrome Cache Entry: 136
JSON data
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (65155)
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (5082)
downloaded
Chrome Cache Entry: 139
Web Open Font Format (Version 2), TrueType, length 48580, version 1.66
downloaded
Chrome Cache Entry: 140
ASCII text
downloaded
Chrome Cache Entry: 141
Web Open Font Format (Version 2), TrueType, length 54666, version 1.0
downloaded
Chrome Cache Entry: 142
Unicode text, UTF-8 text, with very long lines (50826), with NEL line terminators
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (10533)
downloaded
Chrome Cache Entry: 144
ASCII text
downloaded
Chrome Cache Entry: 145
PNG image data, 1275 x 1650, 1-bit grayscale, non-interlaced
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (8391)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (31230)
downloaded
Chrome Cache Entry: 148
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (4828)
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (57485)
downloaded
Chrome Cache Entry: 151
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 152
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 153
MS Windows icon resource - 1 icon, -75x-56, 32 bits/pixel
downloaded
Chrome Cache Entry: 154
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (33484)
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (23788)
downloaded
Chrome Cache Entry: 157
PNG image data, 1275 x 1650, 8-bit grayscale, non-interlaced
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (33043)
downloaded
Chrome Cache Entry: 159
PNG image data, 1275 x 1650, 1-bit grayscale, non-interlaced
dropped
Chrome Cache Entry: 160
PNG image data, 1275 x 1650, 8-bit grayscale, non-interlaced
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (655)
downloaded
Chrome Cache Entry: 162
Web Open Font Format (Version 2), TrueType, length 43308, version 1.66
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (12494)
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 165
Unicode text, UTF-8 text, with very long lines (43197), with LF, NEL line terminators
downloaded
Chrome Cache Entry: 166
TrueType Font data, 15 tables, 1st "FFTM", 14 names, Macintosh
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (54939)
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (27926), with no line terminators
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 170
JSON data
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (4787)
downloaded
Chrome Cache Entry: 172
Web Open Font Format (Version 2), TrueType, length 46188, version 1.66
downloaded
Chrome Cache Entry: 173
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (40848)
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (4720)
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (65505)
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (345)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (19894), with no line terminators
downloaded
Chrome Cache Entry: 179
MS Windows icon resource - 1 icon, -75x-56, 32 bits/pixel
dropped
Chrome Cache Entry: 180
Web Open Font Format (Version 2), TrueType, length 43308, version 1.66
downloaded
Chrome Cache Entry: 181
ASCII text
downloaded
Chrome Cache Entry: 182
PNG image data, 458 x 58, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 183
Unicode text, UTF-8 text, with very long lines (35043)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (2962)
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (65372)
downloaded
Chrome Cache Entry: 186
ASCII text, with very long lines (55161)
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (47981)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (605)
downloaded
Chrome Cache Entry: 189
C source, ASCII text, with very long lines (1046)
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (54939)
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (21663)
downloaded
Chrome Cache Entry: 192
PNG image data, 1275 x 1650, 8-bit grayscale, non-interlaced
downloaded
Chrome Cache Entry: 193
ASCII text
downloaded
Chrome Cache Entry: 194
ASCII text
downloaded
There are 71 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://app.hellosign.com/t/12d97f79eb97705150d8f8046b386cc7edf916a9?utm_campaign=multisigner_complete&utm_source=default&utm_channel=product_promo&utm_medium=email&utm_content=original
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1972,i,4750712491697218838,6996479479991682598,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://app.hellosign.com/t/12d97f79eb97705150d8f8046b386cc7edf916a9?utm_campaign=multisigner_complete&utm_source=default&utm_channel=product_promo&utm_medium=email&utm_content=original
https://cdn.hellosign.com/15282e1/build/jquery3.js
13.226.52.92
https://github.com/google/material-design-icons
unknown
http://jquery.org/license
unknown
https://cdn.hellosign.com/15282e1/build/110.6d11a1f1c88962a22771.js
13.226.52.92
https://github.com/szimek/signature_pad
unknown
https://cdn.hellosign.com/15282e1/build/signer.js
13.226.52.92
http://underscorejs.org
unknown
http://paulirish.com/2011/requestanimationframe-for-smart-animating/
unknown
https://twitter.com/benjsperry
unknown
http://jqueryui.com
unknown
http://www.ascendercorp.com/http://ascendercorp.com/eula10.htmlNormaaliNorm
unknown
https://cdn.hellosign.com/15282e1/build/8931083ec8bb40af521ec1f7fec2e419.woff2
13.226.52.92
https://app.hellosign.com/
unknown
https://app.hellosign.com/signer/ready?tsm_guid=39251484fa39c3b9a96f490a75249a4a49e44a5d&token=36c5ed1ec48f66db&_c=1714137520359
3.232.63.46
https://www.dropbox.com/log/ux_analytics
162.125.5.18
https://www.gstatic.cn/charts/%
unknown
https://cdn.hellosign.com/15282e1/build/93b6f18ec99bcb7c3fa7ea570a75e240.woff2
13.226.52.92
https://app.hellosign.com/sign/bd3e3662b74f8ab7612343a062786a19bd12b415#/sign/component_331367850_5
https://cdn.hellosign.com/15282e1/build/signer.css
13.226.52.92
https://twitter.com/ionicframework
unknown
https://app.hellosign.com/sign/bd3e3662b74f8ab7612343a062786a19bd12b415
https://reactjs.org/link/react-polyfills
unknown
https://cdn.hellosign.com/15282e1/js/foundation.js
13.226.52.92
http://www.opensource.org/licenses/mit-license.php
unknown
https://cdn.hellosign.com/15282e1/build/107.96aebe0cfadb350f1510.js
13.226.52.92
https://www.dropbox.com/pithos/host%3Aapp.hellosign.com/privacy_consent
162.125.5.18
https://www.dropbox.com/2/client_metrics/record
162.125.5.18
https://www.dropbox.com/ccpa_iframe?hide_gdpr=false&is_ccpa_enabled=true&should_disable_banner=false&gpc_signal=false&origin=https%253A%252F%252Fapp.hellosign.com&sandbox_redirect=false&uri_for_logging=app.hellosign.com&locale_override=en&should_auto_open_options=false&privacy_consent_upgrade_flag=true&csrf_origin=https%253A%252F%252Fapp.hellosign.com
162.125.5.18
http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.htmlThis
unknown
https://tinyurl.com/y2uuvskb
unknown
https://app.hellosign.com/attachment/view?sig_guid=483623cf627fe7b155e56777fe26f8d8a59e81e1
52.201.163.195
http://flesler.blogspot.com/2007/10/jqueryscrollto.html
unknown
https://www.dropbox.com/pithos/privacy_consent
162.125.5.18
http://creativecommons.org/licenses/by/4.0/
unknown
http://jedwatson.github.io/classnames
unknown
https://github.com/paulirish/matchMedia.js
unknown
http://fontforge.sf.net)IoniconsIoniconsMediumMediumFontForge
unknown
https://cdn.userleap.com/shim.js?id=B0gYx8LpZM
13.226.52.82
http://www.ascendercorp.com/0
unknown
https://app.hellosign.com/signature/list?type_code=I&ux_version=2&preloaded_tsm_group_key=default
3.232.63.46
https://cdn.hellosign.com/15282e1/build/b177eba3bbeef5293fd6fd690523d3f8.svg
13.226.52.92
http://fontforge.sf.net)
unknown
https://jqueryvalidation.org/
unknown
https://maps-api-ssl.google.com/maps?jsapiRedirect=true&file=googleapi
unknown
https://cdn.hellosign.com/15282e1/build/873357982e6eda6c4c02f5c5de800c2f.ttf
13.226.52.92
https://cdn.hellosign.com/15282e1/build/ebee194a9b773f166dc16096f8614aaa.woff2
13.226.52.123
https://app.hellosign.com/signer/save?c=1714137545640
3.232.63.46
http://my.opera.com/emoller/blog/2011/12/20/requestanimationframe-for-smart-er-animating
unknown
https://cdn.hellosign.com/15282e1/build/dfc5e24cbc1b134e0c00c61e84ec999a.woff2
13.226.52.92
https://www.dropbox.com/2/udcl/log_timing
162.125.5.18
https://reactjs.org/docs/error-decoder.html?invariant=
unknown
http://hammerjs.github.io/
unknown
http://api.jqueryui.com/category/ui-core/
unknown
https://app.hellosign.com/signer/load?guid=bd3e3662b74f8ab7612343a062786a19bd12b415&tsm_guid=39251484fa39c3b9a96f490a75249a4a49e44a5d&status_token=36c5ed1ec48f66db&_c=1714137521013
3.232.63.46
http://api.jqueryui.com/position/
unknown
https://www.dropbox.com/page_success/end?edison_page_name=ccpa_iframe&path=%2Fen%2Fccpa_iframe&request_id=ccc7b591a160469c8a073edfc16dc74f&time=1714137515
162.125.5.18
https://cdn.hellosign.com/15282e1/build/24712f6c47821394fba7942fbb52c3b2.ttf
13.226.52.92
https://www.gstatic.cn/charts/debug/%
unknown
http://www.ascendercorp.com/http://ascendercorp.com/eula10.html
unknown
https://app.hellosign.com/t/12d97f79eb97705150d8f8046b386cc7edf916a9?utm_campaign=multisigner_complete&utm_source=default&utm_channel=product_promo&utm_medium=email&utm_content=original
3.232.63.46
http://ionicons.com/
unknown
https://cdn.hellosign.com/15282e1/build/5.5f8f6191bd9af571fa9d.js
13.226.52.92
http://www.ascendercorp.com/http://ascendercorp.com/eula10.htmlNormaloby
unknown
https://github.com/driftyco/ionicons
unknown
https://github.com/gnarf37/jquery-requestAnimationFrame
unknown
https://d.dropbox.com/api/4506197685370880/envelope/?sentry_key=f8e19270d07412b6be0c537098edb309&sentry_version=7&sentry_client=sentry.javascript.browser%2F7.13.0
162.125.6.20
https://app.hellosign.com/home/manage
unknown
https://www.dropbox.com/signatures?
unknown
https://feross.org
unknown
https://jquery.org/license
unknown
https://feross.org/opensource
unknown
https://jquery.com/
unknown
https://api.sprig.com/sdk/1/environments/B0gYx8LpZM/config
3.228.185.195
http://foundation.zurb.com
unknown
http://flesler.blogspot.com
unknown
https://app.hellosign.com/signature/list?type_code=S&ux_version=2&preloaded_tsm_group_key=default
3.232.63.46
https://www.dropbox.com/en/ccpa_iframe?hide_gdpr=false&is_ccpa_enabled=true&should_disable_banner=false&gpc_signal=false&origin=https%253A%252F%252Fapp.hellosign.com&sandbox_redirect=false&uri_for_logging=app.hellosign.com&locale_override=en&should_auto_open_options=false&privacy_consent_upgrade_flag=true&csrf_origin=https%253A%252F%252Fapp.hellosign.com
https://cdn.hellosign.com/15282e1/build/chunks/e6c0b51bad713718e80c.style.css
13.226.52.92
http://fontforge.sf.net)Created
unknown
https://www.google.com/jsapi
142.251.35.228
https://cdn.hellosign.com/15282e1/images/dropbox-sign-favicon.ico
13.226.52.92
http://feross.org
unknown
https://sizzlejs.com/
unknown
https://js.foundation/
unknown
https://app.hellosign.com/signer/getData?cached_params_token=ba8d5d32691e143a2f926e4d757fc9a8
3.232.63.46
https://cdn.hellosign.com/15282e1/build/chunks/d96c648d3fda751c7989.style.css
13.226.52.92
There are 76 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s3.amazonaws.com
52.216.241.78
dyn550zzd47ox.cloudfront.net
13.226.52.92
cdn.userleap.com
13.226.52.82
api.sprig.com
3.228.185.195
www-env.dropbox-dns.com
162.125.5.18
d-edge.v.dropbox.com
162.125.6.20
www.google.com
142.251.35.228
app.hellosign.com
3.232.63.46
d.dropbox.com
unknown
www.dropbox.com
unknown
cfl.dropboxstatic.com
unknown
cdn.hellosign.com
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
3.228.185.195
api.sprig.com
United States
192.168.2.16
unknown
unknown
13.226.52.2
unknown
United States
52.201.163.195
unknown
United States
13.226.52.82
cdn.userleap.com
United States
13.226.52.123
unknown
United States
162.125.6.20
d-edge.v.dropbox.com
United States
162.125.5.18
www-env.dropbox-dns.com
United States
52.86.181.185
unknown
United States
52.216.241.78
s3.amazonaws.com
United States
13.226.52.92
dyn550zzd47ox.cloudfront.net
United States
142.250.217.196
unknown
United States
239.255.255.250
unknown
Reserved
142.251.35.228
www.google.com
United States
162.125.1.20
unknown
United States
3.232.63.46
app.hellosign.com
United States
3.88.120.146
unknown
United States
16.182.108.240
unknown
United States
There are 8 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://app.hellosign.com/sign/bd3e3662b74f8ab7612343a062786a19bd12b415
https://app.hellosign.com/sign/bd3e3662b74f8ab7612343a062786a19bd12b415
https://app.hellosign.com/sign/bd3e3662b74f8ab7612343a062786a19bd12b415
https://www.dropbox.com/en/ccpa_iframe?hide_gdpr=false&is_ccpa_enabled=true&should_disable_banner=false&gpc_signal=false&origin=https%253A%252F%252Fapp.hellosign.com&sandbox_redirect=false&uri_for_logging=app.hellosign.com&locale_override=en&should_auto_open_options=false&privacy_consent_upgrade_flag=true&csrf_origin=https%253A%252F%252Fapp.hellosign.com
https://www.dropbox.com/en/ccpa_iframe?hide_gdpr=false&is_ccpa_enabled=true&should_disable_banner=false&gpc_signal=false&origin=https%253A%252F%252Fapp.hellosign.com&sandbox_redirect=false&uri_for_logging=app.hellosign.com&locale_override=en&should_auto_open_options=false&privacy_consent_upgrade_flag=true&csrf_origin=https%253A%252F%252Fapp.hellosign.com
https://www.dropbox.com/en/ccpa_iframe?hide_gdpr=false&is_ccpa_enabled=true&should_disable_banner=false&gpc_signal=false&origin=https%253A%252F%252Fapp.hellosign.com&sandbox_redirect=false&uri_for_logging=app.hellosign.com&locale_override=en&should_auto_open_options=false&privacy_consent_upgrade_flag=true&csrf_origin=https%253A%252F%252Fapp.hellosign.com
https://app.hellosign.com/sign/bd3e3662b74f8ab7612343a062786a19bd12b415#/sign/component_331367850_5