Docusign112101 malware family
Docusign112101 is a malware family tracked by MalwareAnalyzer by Cyble across 34 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-23. Observed ATT&CK techniques include T1105.
Corpus statistics
- Publicly analyzed samples: 34
- First seen: 2026-08-04
- Last seen: 2026-08-23
- Verdicts: malicious 34
- File types: office-ooxml 18, email 8, zip 8
ATT&CK techniques used by Docusign112101
- T1105 - 10 samples
Recent Docusign112101 samples
- e3f6121ad266467e6ffb14242cf1ca81f3625890a7d758863195f89a5d1c9041 - malicious (2026-08-23)
- b1945c4ad1f3b04e7689262e5bac23a40437a1a380dfbb3f702a2ca2acbeb710 - malicious (2026-08-23)
- CLM-1780971899-Nov-12.zip - malicious (2026-08-22)
- 2f623292706d573d568e0ad121f968f5bcb30c7a88a0a2b5aadd068aed7a9f53 - malicious (2026-08-22)
- f1b0cc0c0f71ffde7f1ca81695e92a56719351b129b097c5b78295b8113590ad - malicious (2026-08-22)
- CLM-858944315-Nov-12.zip - malicious (2026-08-22)
- 6738d6dc5271d7840ece8d0a90f6798fe6348b4191b71872b0d518ceb0a8748a - malicious (2026-08-22)
- 2b5c005563c27851ff7bc1465931ee28bc9712ebb83558e61941c835a8967e32 - malicious (2026-08-21)
- 55a67500afa6a7ec35d3e74a535c56e2e18d7efc582190fa113a4dd4873d1bd7 - malicious (2026-08-21)
- 10a1bb71c4f105bc17da506b3119f56d19e7adecf6c8a4e61d9bd39ac6f5ab05 - malicious (2026-08-21)
- 1ce0d820cc005207b82f02c5f99c86decb4686b6abc836eebc100849a8ab4109 - malicious (2026-08-20)
- a0da18c7940d3c9ce5c21ec0269bba94b63d682ee615988567538993d6da3732 - malicious (2026-08-20)
- 1fb4e106a0ec86ff9b8295d985181c8208bd1992da3bac66e6a26c9b2d702db2 - malicious (2026-08-20)
- bcdbf05d9ce37ad3802f34b13366e41a212e2bd26dffc1151ab82a4a4dee0b4c - malicious (2026-08-20)
- Srv-Interrupt-687878989-Nov-10.zip - malicious (2026-08-19)
- 9ff816f6eaf14f22b2d3663957de22bf4b672880e8e728ce40443c9e74667d5c - malicious (2026-08-19)
- CLM-595545271-Nov-12.zip - malicious (2026-08-19)
- bba8161c10e399ab4458f291740b7b61b0ac6e11b37b7f7db3f55193e6523dc3 - malicious (2026-08-19)
- e3aaf3257fa484d4cadcde9a8314af2ba34de391b638815260d1402bd9308086 - malicious (2026-08-19)
- 2953ee556474482c1b4e426de140dc7f6b931da94cf9309ab584993483051990 - malicious (2026-08-15)
- CLM-517701879-Nov-12.zip - malicious (2026-08-15)
- 528744f2aaa6f858940b1e48366772e48adcfc246dfacfb8ab9cfe73cffeaabf - malicious (2026-08-15)
- ca80cd89c710e442d447b4905f38a51b5985e072bcbd31cff0e2ad9a451b32c0 - malicious (2026-08-15)
- b264436b0bb0ca5ff0d512a3f681aea0eecd166488a0dceebfb84725cafc1029 - malicious (2026-08-14)
Frequently asked about Docusign112101
- What is Docusign112101?
- Docusign112101 is a malware family tracked by MalwareAnalyzer by Cyble across 34 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-23. Observed ATT&CK techniques include T1105.
- How many Docusign112101 samples have been analyzed?
- MalwareAnalyzer by Cyble holds 34 publicly analyzed samples attributed to Docusign112101, first seen 2026-08-04 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Docusign112101 use?
- Across our Docusign112101 samples the most frequently observed techniques are T1105 (10). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Docusign112101 use?
- Docusign112101 samples in this corpus are distributed as office-ooxml (18), email (8), zip (8).
- Is Docusign112101 malicious?
- 34 of 34 analyzed Docusign112101 samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends