Scan report · about 2 months agoPublic

cheshmandazpars.ir

185.147.162.130AS43754 · IR

a fake verification checkbox gates a document workflow ("docusign") and pressing it advances a multi-step flow

no genuine challenge resource backs the widget
Engine tags
ClickFix
Verdict

What happened

Step by step, from what the scanner recorded.
Load 24.2 s · 1 requests
01 · Visitor openscheshmandazpars.ir/css/
02 · Page shown
ShareSync – document sharedstyled as DocuSign · low
03 · File delivered · maliciousInternal_Audit_Report_FY2025.htaHanded over by the page, not served at the scanned address.
04 · OutcomeThe visitor runs the payload themselvesPaste, Enter — no download and no login form for a filter to catch.

Dangerous — confirmed threat

Automated

Its page title claims to be DocuSign, which this address is not associated with. It is listed on external threat-intelligence feeds. The file it serves was analysed and found malicious. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
MalwareMalware found in the downloaded file
Internal_Audit_Report_FY2025.hta

We analysed the file this page delivered — it is Malicious.

Success

SHA-256 4371553fa3ed91651a0a4518254346e6d774d5efd4717fabc79309653651e6d0

InfoBrand impersonation detected
DocuSign · low

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteLow/medium confidence (keyword only) — can be a news article or partner page. Corroborate before acting.

File

Stored by the engine

What you download may be live malware. Open it only in an isolated environment, and do not double-click it.

The ZIP is encrypted. Password:infected

Inside the ZIP the file carries a name the engine generated, not the one the page used.

Delivered fileMaliciousInternal_Audit_Report_FY2025.hta

SHA-2564371553fa3ed91651a0a4518254346e6d774d5efd4717fabc79309653651e6d0

Fromhxxps://t90141444206[.]p[.]clickup-attachments[.]com/t90141444206/266aa5e5-9805-442c-8b30-b364c376b870/Internal_Audit_Report_FY2025[.]zip?view=open

Infrastructure

IP
185.147.162.130ASIATECH - Asiatech Data Transmission company, IR · AS43754IR
TLS
CN=YR2, O=Let's Encrypt, C=US · expires Sep 27, 2026
193 malicious2 suspicious

Hashes & fingerprints

Page capture

Live

Title “ShareSync – document shared” · brand shown: DocuSign (low)

Engines

8 · time to verdict

Page

HTTP
200 · Completed
Title
ShareSync – document shared
Load
24.15 s · 1 requests
Stack · 1HTTP/3