Analysis
9 MIN READ
TL;DR
This campaign delivers a high-quality phishing page that impersonates a Microsoft Excel shared-document access dialog. The full infection chain is:
Victim (primarily business-affiliated) receives a DocuSign-branded email claiming business files are ready for review.
The call-to-action button is tracked via Monday.com and lands on an intermediate page hosted at
atecevents.com.hk.The intermediate page extracts a base64-encoded email address from the URL fragment, then redirects to a Cloudflare Workers domain that uses the same campaign identifier seen in the final kit.
The final page presents a convincing Excel / Office modal, pre-fills the email when available, forces up to three password attempts with realistic error messages, and exfiltrates credentials to a relative
/api/capture-credsendpoint.After the final attempt it shows a fake success screen and redirects the victim. Extensive anti-devtools code is present, and the page is designed for a commercial-style phishing platform whose backend runs on Supabase.
The combination of a trusted brand in the email, clean intermediate redirects, high visual fidelity, deliberate retry logic, and strong client-side protection makes the kit more effective than many crude one-off pages sent to the spam-fill.
Infection Chain
Stage 1 – DocuSign Email

A representative sample observed on 21 August 2026:
Field | Observed Value | Notes |
|---|---|---|
Subject |
| — |
From |
| Spoofed display name; real domain is unrelated |
Call-to-action | Large yellow button: VIEW COMPLETED DOCUMENT | Primary click target |
Body text | “You have recieved some business files on DocuSign.” | Spelling error (“recieved”) |
Key red flags
The true sending domain (
brushme.com.ua) has no relationship to DocuSign.Legitimate DocuSign notifications originate from
@docusign.comor@docusign.netand normally name the specific document and sender.Basic spelling mistakes are uncommon in official product emails.
Language is deliberately vague (“some business files”, “completed document”) so the same template can be reused across many recipients.
Stage 2 – Tracking & Intermediate Redirect
The button in the email points to a Monday.com tracking URL of the form:
After the tracking hop the victim is sent to:
The page at this location is a minimal HTML/JavaScript redirector. Its sole purpose is to extract the base64-encoded email address from the URL fragment and forward the victim to the next stage while preserving that email, without the needed email address, it fails and doesn't continue.
Relevant logic (simplified):
The path component 2043391f72954820 and the subdomain prefix accounts-2043391f both contain the campaign identifier 2043391f. This same identifier appears later as the PID value inside the final phishing page, confirming that all stages belong to the same operation rather than distributed.
Stage 3 – Final Phishing Page
The victim ultimately lands on the Excel / Office shared-document page (or a closely related variant hosted under the Workers domain). This is the page analysed in detail below.
Landing Page – Visual Impersonation

The final page presents a full-screen background image with a centred modal that closely mimics a Windows / Office window:
Fake title bar using the four Microsoft logo colours and the word “Office”
Large green “Excel” heading that matches official Excel branding
Email and password fields with matching green borders
“Keep me signed in” checkbox (pre-checked)
Primary action button labelled Download
Loading spinner followed by a success state with a checkmark icon
The favicon is an inline SVG of a green rounded square containing a white “X”. The page also sets robots meta tags to discourage indexing and disables pinch-to-zoom on mobile.
At a glance the interface is credible, especially for users who regularly receive legitimate shared-document notifications from Microsoft 365 or OneDrive.
Credential Capture Flow
The core capture logic lives in a self-contained script:
On load the script attempts to extract and decode an email address from the URL (
cid,info, or hash) and pre-fills the email field.It also injects two long random query parameters (
sidandrid) viahistory.replaceState. These appear to serve tracking or session-correlation purposes.When the user clicks Download, basic validation is performed (email must contain
@, password must not be empty).Credentials are serialised as JSON and sent to
location.origin + "/api/capture-creds"usingfetch, with a retry and anavigator.sendBeaconfallback.A configurable retry counter (default 3) is enforced. On intermediate attempts the password field is cleared and a realistic Microsoft-style error is displayed:
The account or password you entered is incorrect. Please try again.
After the final attempt the form is replaced by a loader, then a success screen, and the browser is redirected (to a configured
finalUrl, the victim’s email domain, or the current origin).
This multi-attempt design is deliberate: many users will re-type their password when they see a familiar error message, giving the attacker a higher chance of obtaining the correct credential.
Anti-Analysis Measures

A large defensive script actively hinders both human analysts and automated tools:
Right-click, text selection (outside inputs), copy, cut and drag are blocked
Common developer shortcuts (F12, Ctrl+Shift+I/J/C, Ctrl+U, Ctrl+S, Ctrl+P, etc.) are intercepted
Window size is polled; if the difference between outer and inner dimensions suggests DevTools is open, the entire page is replaced with an “Access Denied” message
The
consoleobject is overridden so logging methods become no-opsPrinting is blocked via CSS and the
beforeprinteventIframe breakout is attempted
The
view-source:protocol is detected and the page is blankedAggressive CSS forces
user-select: noneand disables image dragging
These techniques are characteristic of commercial phishing kits that try to raise the cost of analysis.
Campaign Backend
Near the bottom of the final page a set of global configuration variables reveal the supporting infrastructure:
A geo-IP language detection call is made to the same Supabase Edge Function so the form text can be localised (support exists for Chinese, French, German, Spanish, Portuguese, Japanese, Korean, Arabic and others). Additional flags for cookie capture, MFA capture and token handling are present but disabled in the examined sample.
The primary credential sink remains the relative /api/capture-creds endpoint hosted on the phishing domain itself; the Supabase project appears to handle campaign management, telemetry and localisation.
The repeated appearance of the identifier 2043391f across the intermediate redirect, the Workers subdomain, and the final-page PID value ties the entire chain together.
Indicators of Compromise
Domains & Hosts
brushme.com.ua(email sending domain)trackingservice.monday.com(tracking hop)atecevents.com.hk(intermediate redirector)accounts-2043391f.faytriecu04n.workers.dev(Cloudflare Workers stage)qctazjekftdaugwaxwyc.supabase.co(campaign backend)
Notable Paths & Endpoints
/ter/onatecevents.com.hk/2043391f72954820on the Workers domainRelative endpoint
/api/capture-creds(credential collection)
Strings & Selectors
CSS classes:
eg-overlay,eg-modal,eg-titlebar,eg-excel-titleJavaScript identifiers:
window.__WEBAPP_CFG,sendCapture,autoGrab,injectParamsMarker comment:
WEBAPP_SELF_CONTAINEDConfiguration keys:
LOADER_PRESET,SUITE_TYPE = "webapp"Publishable key prefix beginning
sb_publishable_WuERWAB_...
Campaign Identifiers
Behavioural Indicators
Injection of long random
sid+ridquery parameters on page loadPassword form that forces multiple submission attempts while displaying the exact error string quoted above
POST of JSON objects containing
email,passwordandattemptfieldsContinuous outer/inner window-size polling that blanks the page when DevTools is detected
Intermediate page that performs
atob()on a URL fragment and immediately redirects
MITRE ATT&CK Mapping
Tactic | Technique | ID | Observation |
|---|---|---|---|
Initial Access | Phishing | T1566 | DocuSign-themed email lure |
Initial Access | Spearphishing Link | T1566.002 | Link carries pre-filled (base64) email parameter |
Credential Access | Input Capture | T1056 | Form-based harvesting of email + password |
Defense Evasion | Obfuscated Files or Information | T1027 | Heavy client-side anti-analysis code |
Defense Evasion | Indicator Removal | T1070 | DevTools detection + page blanking |
Collection | Data from Information Repositories | T1213 | Credentials collected from the login form |
Command and Control | Web Service | T1102 | Supabase Edge Function + relative capture API |
Command and Control | Proxy | T1090 | Intermediate redirector + tracking service |