URL:

https://docsendsign.com/

Full analysis: https://app.any.run/tasks/a6a3941b-f73a-4589-8dfc-85455c010f33
Verdict: Malicious activity
Analysis date: September 03, 2025, 16:30:27
OS: Windows 11 Professional (build: 22000, 64 bit)
Tags:
possible-phishing
anti-evasion
nodejs
Indicators:
MD5:

286634FA4A2940E4DCA8279941EC8D74

SHA1:

364050C19110F24F1E0D3DE824422E85D7A554A9

SHA256:

B9E39128C1848EE0B937DEB34788EC86D570FEA5577DE5E0EC13552ACC9D0C22

SSDEEP:

3:N8S29c3:2SAc3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Collects BIOS Properties (Win32_BIOS) (SCRIPT)

      • powershell.exe (PID: 5116)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • DocsSign3.1.7.exe (PID: 7684)
      • powershell.exe (PID: 5304)
    • Process drops legitimate windows executable

      • DocsSign3.1.7.exe (PID: 7684)
    • Drops 7-zip archiver for unpacking

      • DocsSign3.1.7.exe (PID: 7684)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • DocsSign3.1.7.exe (PID: 7684)
    • Executable content was dropped or overwritten

      • DocsSign3.1.7.exe (PID: 7684)
    • Reads security settings of Internet Explorer

      • DocsSign3.1.7.exe (PID: 7684)
    • Reads the Internet Settings

      • powershell.exe (PID: 5304)
      • powershell.exe (PID: 5916)
      • powershell.exe (PID: 5116)
      • powershell.exe (PID: 5204)
      • powershell.exe (PID: 1800)
      • Dropbox DocSend.exe (PID: 8180)
    • Get information on the list of running processes

      • cmd.exe (PID: 7456)
      • Dropbox DocSend.exe (PID: 8180)
    • Starts CMD.EXE for commands execution

      • Dropbox DocSend.exe (PID: 8180)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 7500)
      • cmd.exe (PID: 204)
      • cmd.exe (PID: 1208)
      • cmd.exe (PID: 3860)
      • cmd.exe (PID: 4372)
      • cmd.exe (PID: 1044)
    • There is functionality for taking screenshot (YARA)

      • DocsSign3.1.7.exe (PID: 7684)
    • Gets CPU ID (POWERSHELL)

      • powershell.exe (PID: 5204)
    • Application launched itself

      • Dropbox DocSend.exe (PID: 8180)
    • Reads settings of System Certificates

      • Dropbox DocSend.exe (PID: 8180)
  • INFO

    • Reads the computer name

      • identity_helper.exe (PID: 7212)
      • DocsSign3.1.7.exe (PID: 7684)
      • Dropbox DocSend.exe (PID: 8180)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 2408)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 3976)
    • Application launched itself

      • msedge.exe (PID: 2408)
    • Checks supported languages

      • identity_helper.exe (PID: 7212)
      • DocsSign3.1.7.exe (PID: 7684)
      • Dropbox DocSend.exe (PID: 8180)
      • Dropbox DocSend.exe (PID: 6200)
      • Dropbox DocSend.exe (PID: 3804)
    • Reads Environment values

      • identity_helper.exe (PID: 7212)
    • Reads settings of System Certificates

      • explorer.exe (PID: 3976)
    • Reads the Internet Settings

      • explorer.exe (PID: 3976)
    • Checks proxy server information

      • explorer.exe (PID: 3976)
      • Dropbox DocSend.exe (PID: 8180)
    • Creates files or folders in the user directory

      • explorer.exe (PID: 3976)
      • Dropbox DocSend.exe (PID: 8180)
    • The sample compiled with english language support

      • DocsSign3.1.7.exe (PID: 7684)
    • Create files in a temporary directory

      • DocsSign3.1.7.exe (PID: 7684)
    • Node.js compiler has been detected

      • Dropbox DocSend.exe (PID: 8180)
    • Reads the machine GUID from the registry

      • Dropbox DocSend.exe (PID: 8180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
173
Monitored processes
66
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
204C:\Windows\system32\cmd.exe /d /s /c "powershell "(Get-CimInstance -ClassName Win32_BIOS).SerialNumber""C:\Windows\SysWOW64\cmd.exeDropbox DocSend.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
600\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
1044C:\Windows\system32\cmd.exe /d /s /c "powershell "Get-CimInstance -ClassName Win32_VideoController | Select-Object -First 1 -ExpandProperty Name""C:\Windows\SysWOW64\cmd.exeDropbox DocSend.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
1188\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
1208C:\Windows\system32\cmd.exe /d /s /c "powershell "(Get-CimInstance -ClassName Win32_Processor).ProcessorId""C:\Windows\SysWOW64\cmd.exeDropbox DocSend.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
1800powershell "Get-CimInstance -ClassName Win32_VideoController | Select-Object -First 1 -ExpandProperty Name"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
1876"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6552,i,5831158745278776519,8418107024028665654,262144 --variations-seed-version --mojo-platform-channel-handle=7044 /prefetch:14C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1904powershell "(Get-CimInstance -ClassName Win32_DiskDrive).SerialNumber" C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
1980reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography" /v MachineGuidC:\Windows\SysWOW64\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
1
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
2408"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" "https://docsendsign.com/"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
44 967
Read events
44 704
Write events
239
Delete events
24

Modification events

(PID) Process:(3976) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000007400790070006500
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(3976) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000202A6
Operation:writeName:VirtualDesktop
Value:
1000000030304456E64BE2562B64DB4CA4AF596EA6D7EE7A
(PID) Process:(2408) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
Executable files
41
Suspicious files
678
Text files
144
Unknown types
0

Dropped files

PID
Process
Filename
Type
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\BrowserMetrics\BrowserMetrics-68B86D31-968.pma
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\ClientCertificates\LOG.old~RFf1a36.TMP
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\ClientCertificates\LOG.old
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\discounts_db\LOG.old~RFf1a45.TMP
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\parcel_tracking_db\LOG.old~RFf1a55.TMP
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\PersistentOriginTrials\LOG.old~RFf1a55.TMP
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\discounts_db\LOG.old
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\parcel_tracking_db\LOG.old
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\commerce_subscription_db\LOG.old~RFf1a45.TMP
MD5:
SHA256:
2408msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Profile 1\commerce_subscription_db\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
40
TCP/UDP connections
134
DNS requests
113
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1364
firefox.exe
POST
200
2.17.190.73:80
http://ocsp.digicert.com/
DE
binary
471 b
whitelisted
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?6d350899be445aa7
US
whitelisted
1300
svchost.exe
GET
200
23.55.161.164:80
http://www.msftconnecttest.com/connecttest.txt
DE
text
22 b
whitelisted
1352
pingsender.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?86e3fbce45be85ce
US
whitelisted
1352
pingsender.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAo1CNVcKSsBffitZcAP9%2BQ%3D
DE
binary
471 b
whitelisted
2744
svchost.exe
GET
200
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/pinrulesstl.cab?cf9509f5c6f512bf
US
compressed
7.61 Kb
whitelisted
1352
pingsender.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTk45WiKdPUwcMf8JgMC07ACYqr2AQUt2ui6qiqhIx56rTaD5iyxZV2ufQCEAOav%2F2w8K4jHzmTOaTzWTM%3D
DE
binary
471 b
whitelisted
2744
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3afb9106213b9abd
US
whitelisted
2744
svchost.exe
GET
200
72.246.169.163:80
http://x1.c.lencr.org/
DE
binary
734 b
whitelisted
6748
msedge.exe
GET
200
150.171.28.11:80
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:ktAuXCNREQPhLWWwQxvwgjBipju8uaJWsXo2tscftLY&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
US
text
99 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
52.109.32.97:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
5564
OfficeC2RClient.exe
52.109.32.97:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
1300
svchost.exe
23.55.161.164:80
Akamai International B.V.
DE
unknown
1364
firefox.exe
34.120.208.123:443
incoming.telemetry.mozilla.org
GOOGLE-CLOUD-PLATFORM
US
whitelisted
1352
pingsender.exe
34.120.208.123:443
incoming.telemetry.mozilla.org
GOOGLE-CLOUD-PLATFORM
US
whitelisted
34.120.208.123:443
incoming.telemetry.mozilla.org
GOOGLE-CLOUD-PLATFORM
US
whitelisted
5056
svchost.exe
104.102.63.189:443
fs.microsoft.com
AKAMAI-AS
US
whitelisted
1364
firefox.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
incoming.telemetry.mozilla.org
  • 34.120.208.123
whitelisted
telemetry-incoming.r53-2.services.mozilla.com
  • 34.120.208.123
whitelisted
google.com
  • 142.250.185.110
whitelisted
fs.microsoft.com
  • 104.102.63.189
whitelisted
ocsp.digicert.com
  • 2.17.190.73
  • 184.30.131.245
whitelisted
e3913.cd.akamaiedge.net
  • 2.17.190.73
unknown
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
ecs.office.com
  • 52.123.129.14
  • 52.123.128.14
whitelisted

Threats

PID
Process
Class
Message
1300
svchost.exe
Misc activity
ET INFO Microsoft Connection Test
6748
msedge.exe
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket
6748
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] CloudFlare Public R2.dev Bucket
6748
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] CloudFlare Public R2.dev Bucket
6748
msedge.exe
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Abuse Public R2.dev Bucket
6748
msedge.exe
A Network Trojan was detected
ET INFO Observed DNS Query to Cloudflare R2 Public Bucket (r2 .dev) Domain
6748
msedge.exe
A Network Trojan was detected
ET INFO Observed DNS Query to Cloudflare R2 Public Bucket (r2 .dev) Domain
6748
msedge.exe
Misc activity
ET INFO Observed Cloudflare R2 Public Bucket (r2 .dev) Domain in TLS SNI
6748
msedge.exe
Misc activity
ET INFO Observed Cloudflare R2 Public Bucket (r2 .dev) Domain in TLS SNI
No debug info