From Fake DocuSign to ScreenConnect: Attack Blocked
A sophisticated web campaign was blocked that used fake DocuSign workflows and deceptive cloud infrastructure to socially engineer victims into downloading malicious files. The attack employed a ZIP archive with a malicious HTA file using encoded VBScript, fake Adobe interfaces, privilege escalation, and registry modifications to bypass security. It leveraged native Windows tools to silently install ConnectWise ScreenConnect clients, enabling unauthorized remote access. The campaign was stopped at the web entry point before any payload delivery occurred.
AI Analysis
Technical Summary
Threat actors conducted a complex web-based campaign impersonating trusted brands like DocuSign and using cloud services such as Cloudflare Pages with fake verification workflows to appear legitimate. Victims were tricked into downloading a ZIP archive containing a malicious HTA file that used Base64-encoded VBScript, fake Adobe UI elements, UAC privilege escalation, and Microsoft Defender SmartScreen registry changes. The attack utilized living-off-the-land techniques with native Windows utilities (mshta.exe, curl.exe, msiexec.exe) to silently install ConnectWise ScreenConnect Access clients, providing unauthorized remote access. The campaign was classified as Zero Hour Fraudulent and was blocked before payload delivery.
Potential Impact
If successful, the attack would have resulted in unauthorized remote access to victim systems via silently installed ScreenConnect clients. This could allow threat actors to control affected machines remotely. However, the campaign was blocked at the web entry point, preventing payload delivery and exploitation.
Mitigation Recommendations
The attack was blocked before payload delivery, indicating existing defenses were effective. Organizations should remain vigilant against social engineering lures impersonating trusted brands and monitor for suspicious downloads of ZIP archives containing HTA files. No specific patch is applicable. Maintaining updated endpoint protection and user awareness can help prevent similar attacks.
Indicators of Compromise
- hash: 1d5ab21ee92e4212ece319a383dd7593e3b4a998df135bfefc7fad7874c90587
- url: http://admin.rshiahub.com/Bin/ScreenConnect.ClientSetup.msi.
- domain: admin.rshiahub.com
From Fake DocuSign to ScreenConnect: Attack Blocked
Description
A sophisticated web campaign was blocked that used fake DocuSign workflows and deceptive cloud infrastructure to socially engineer victims into downloading malicious files. The attack employed a ZIP archive with a malicious HTA file using encoded VBScript, fake Adobe interfaces, privilege escalation, and registry modifications to bypass security. It leveraged native Windows tools to silently install ConnectWise ScreenConnect clients, enabling unauthorized remote access. The campaign was stopped at the web entry point before any payload delivery occurred.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Threat actors conducted a complex web-based campaign impersonating trusted brands like DocuSign and using cloud services such as Cloudflare Pages with fake verification workflows to appear legitimate. Victims were tricked into downloading a ZIP archive containing a malicious HTA file that used Base64-encoded VBScript, fake Adobe UI elements, UAC privilege escalation, and Microsoft Defender SmartScreen registry changes. The attack utilized living-off-the-land techniques with native Windows utilities (mshta.exe, curl.exe, msiexec.exe) to silently install ConnectWise ScreenConnect Access clients, providing unauthorized remote access. The campaign was classified as Zero Hour Fraudulent and was blocked before payload delivery.
Potential Impact
If successful, the attack would have resulted in unauthorized remote access to victim systems via silently installed ScreenConnect clients. This could allow threat actors to control affected machines remotely. However, the campaign was blocked at the web entry point, preventing payload delivery and exploitation.
Defensive Guidance
The attack was blocked before payload delivery, indicating existing defenses were effective. Organizations should remain vigilant against social engineering lures impersonating trusted brands and monitor for suspicious downloads of ZIP archives containing HTA files. No specific patch is applicable. Maintaining updated endpoint protection and user awareness can help prevent similar attacks.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.menlosecurity.com/blog/from-fake-docusign-to-screenconnect-web-attack-stopped-before-payload-delivery"]
- Pulse Id
- 6aa374470d15d76b861b2f68
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash1d5ab21ee92e4212ece319a383dd7593e3b4a998df135bfefc7fad7874c90587 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://admin.rshiahub.com/Bin/ScreenConnect.ClientSetup.msi. | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainadmin.rshiahub.com | — |
Threat ID: 6aa4147d91cc7f38484bd3a3
Added to database: 09/11/2026, 14:47:25 UTC
Last enriched: 09/11/2026, 15:05:29 UTC
Last updated: 09/11/2026, 15:05:29 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.