Docusign112101 malware family
Docusign112101 is a malware family tracked by MalwareAnalyzer by Cyble across 44 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-26. Observed ATT&CK techniques include T1105.
Corpus statistics
- Publicly analyzed samples: 44
- First seen: 2026-08-04
- Last seen: 2026-08-26
- Verdicts: malicious 44
- File types: office-ooxml 24, email 10, zip 10
ATT&CK techniques used by Docusign112101
- T1105 - 16 samples
Recent Docusign112101 samples
- dbd6679dd39a73b2ec3a395df9ac326a1deac08532775440d10da1f41d7e2f66 - malicious (2026-08-26)
- 9e9d81ca42f0a51465cbc20851b61b346b64aec81ba4afbaff02c7db5ae993ca - malicious (2026-08-26)
- 027296d9dd3a8980f723b7941bc0f9477404a731b9774e75190b8666e591c427 - malicious (2026-08-25)
- CLM-1836839811-Nov-12.zip - malicious (2026-08-25)
- caa9c62ece6d3d43ad611b3da6963d9f5bc8764cbed14b942490526a0ddbcb00 - malicious (2026-08-25)
- 98cc3caf70f33290a476ce3f10fb59d213aff043c6b688cbed322e2935e95fc3 - malicious (2026-08-25)
- Srv-Interrupt-828922134-Nov-10.zip - malicious (2026-08-25)
- ec2468b2eba2dbb291dd1463766660c26d9c7a4db89cb2549944f85bacc760b4 - malicious (2026-08-25)
- 6e835422d8cbac94602e569eeafdcb67de5cecd7f44a985db424fb8834430173 - malicious (2026-08-24)
- b677f66762f17529d3d4846b3848686395917f92a44e6beac35b592a90316e4d - malicious (2026-08-24)
- e3f6121ad266467e6ffb14242cf1ca81f3625890a7d758863195f89a5d1c9041 - malicious (2026-08-23)
- b1945c4ad1f3b04e7689262e5bac23a40437a1a380dfbb3f702a2ca2acbeb710 - malicious (2026-08-23)
- CLM-1780971899-Nov-12.zip - malicious (2026-08-22)
- 2f623292706d573d568e0ad121f968f5bcb30c7a88a0a2b5aadd068aed7a9f53 - malicious (2026-08-22)
- f1b0cc0c0f71ffde7f1ca81695e92a56719351b129b097c5b78295b8113590ad - malicious (2026-08-22)
- CLM-858944315-Nov-12.zip - malicious (2026-08-22)
- 6738d6dc5271d7840ece8d0a90f6798fe6348b4191b71872b0d518ceb0a8748a - malicious (2026-08-22)
- 2b5c005563c27851ff7bc1465931ee28bc9712ebb83558e61941c835a8967e32 - malicious (2026-08-21)
- 55a67500afa6a7ec35d3e74a535c56e2e18d7efc582190fa113a4dd4873d1bd7 - malicious (2026-08-21)
- 10a1bb71c4f105bc17da506b3119f56d19e7adecf6c8a4e61d9bd39ac6f5ab05 - malicious (2026-08-21)
- 1ce0d820cc005207b82f02c5f99c86decb4686b6abc836eebc100849a8ab4109 - malicious (2026-08-20)
- a0da18c7940d3c9ce5c21ec0269bba94b63d682ee615988567538993d6da3732 - malicious (2026-08-20)
- 1fb4e106a0ec86ff9b8295d985181c8208bd1992da3bac66e6a26c9b2d702db2 - malicious (2026-08-20)
- bcdbf05d9ce37ad3802f34b13366e41a212e2bd26dffc1151ab82a4a4dee0b4c - malicious (2026-08-20)
Frequently asked about Docusign112101
- What is Docusign112101?
- Docusign112101 is a malware family tracked by MalwareAnalyzer by Cyble across 44 publicly analyzed samples. First seen 2026-08-04, most recently 2026-08-26. Observed ATT&CK techniques include T1105.
- How many Docusign112101 samples have been analyzed?
- MalwareAnalyzer by Cyble holds 44 publicly analyzed samples attributed to Docusign112101, first seen 2026-08-04 and most recently 2026-08-26. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Docusign112101 use?
- Across our Docusign112101 samples the most frequently observed techniques are T1105 (16). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Docusign112101 use?
- Docusign112101 samples in this corpus are distributed as office-ooxml (24), email (10), zip (10).
- Is Docusign112101 malicious?
- 44 of 44 analyzed Docusign112101 samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends