Wednesday, September 30, 2026
The Traceback
Tracing the connections behind cybercrime and digital threats.
By Ayansh Kumar
Research

Beyond the Florida Lure: Tracing Earlier DocuSign-to-ScreenConnect Infrastructure

Follow-on research into earlier infrastructure and delivery paths linked to a Florida-themed ScreenConnect lure

Beyond the Florida Lure: Tracing Earlier DocuSign-to-ScreenConnect Infrastructure

On September 10, 2026, Menlo Security documented a phishing chain that used a Florida healthcare background-screening lure to deliver ConnectWise ScreenConnect through a malicious HTA. Its analysis established the path from a Cloudflare Pages landing page to the HTA and the unauthorized ScreenConnect installation.

Pivoting from Menlo’s published indicators through VirusTotal, CAPE, and URLScan identified a separate Florida-themed HTA observed earlier in August, ScreenConnect packages associated with the same rshiahub infrastructure, and an alternate redirect path to the Cloudflare Worker documented by Menlo. The evidence extends the observable timeline of the associated infrastructure but does not identify the operator, establish victim counts, or prove that every rshiahub package used the Florida lure.

Figure 0: Summary of Menlo Security’s documented Florida lure and the additional infrastructure and delivery relationships identified during this follow-on research.

What Menlo Security established

Menlo documented a DocuSign-themed page at floridalicense.pages[.]dev/floridahealthcarescreeningnoticeforlicenseholders. After user interaction, the page requested a download from docusig-document-sign6702.docusign-sign.workers[.]dev/download. The Worker returned an archive containing Florida Background Screening Notice.hta (1d5ab21ee92e4212ece319a383dd7593e3b4a998df135bfefc7fad7874c90587).

Menlo found that the HTA retrieved and silently installed ScreenConnect from admin.rshiahub[.]com and opened a Dropbox-hosted f1040.pdf as a decoy.

Earlier ScreenConnect activity around rshiahub

Figure 1: VirusTotal relationships for rshiahub.com, showing associated admin and relay infrastructure and ScreenConnect-related files observed during July and August

VirusTotal recorded three distinct ScreenConnect MSI hashes associated with rshiahub infrastructure during July and August 2026. The earliest of these was first submitted to VirusTotal on July 27. Its relationship data included an admin.rshiahub[.]com deployment URL configured with e=Access and y=Guest; other July and August ScreenConnect packages communicated with relay.rshiahub[.]com. (Note: these are VirusTotal observation dates, not proof of when the files were first deployed.)

Figure 2: VirusTotal relationships for the July 27 ScreenConnect installer, including the deployment URL configured with Access and Guest parameters

A separate Florida HTA was present in August

VirusTotal first received another file named Florida Background Screening Notice.hta on August 27:

  • a472a201884e7a49d5ec25d3a972ad3c2255e80f63e062633e0405e36abb34fc

VirusTotal relationship data associated the earlier HTA with a request to admin.rshiahub[.]com/Bin/ScreenConnect.ClientSetup.exe containing e=Access and y=Guest. The same HTA also contacted Dropbox for f1040.pdf, the same decoy filename documented by Menlo in the later chain.

Figure 3: VirusTotal relationships for the August 27 Florida HTA, showing the ScreenConnect bootstrapper request and the f1040.pdf decoy relationship

A CAPE run captured mshta.exe launching the HTA and Adobe Acrobat opening C:\ProgramData\f1040.pdf. It did not capture the ScreenConnect bootstrapper or MSI being written and executed. The execution therefore confirms execution of the HTA and the opening of f1040.pdf, not completion of the ScreenConnect installation.

Figure 4: CAPE execution showing the earlier Florida HTA launched by mshta.exe and Adobe Acrobat opening C:\ProgramData\f1040.pdf

The two HTAs share several specific characteristics: both use the Florida background-screening narrative, both reference admin.rshiahub[.]com and both reference f1040.pdf as a decoy filename. Menlo’s later sample was shown to retrieve and silently install ScreenConnect. The earlier August sample requested a ScreenConnect bootstrapper configured with Access and Guest parameters, although its installation stage was not captured in the available CAPE execution. Taken together, these overlaps support, with moderate confidence, that the two HTAs are related components of the same Florida-themed delivery cluster. They do not establish a common operator.

An alternate redirect path

URLScan captured an alternate Florida landing path on August 31:

floridalicense.pages[.]dev/floridadepartmentofhealthbackgroundscreeningrecordstatusnotice
→ rebrand[.]ly/Florida-Health-Care-Screening-Record-Not-Found
→ rebrand[.]ly/Florida-Department-of-Health-Background-Screening
→ docusig-document-sign6702.docusign-sign.workers[.]dev

The capture establishes an alternate path from a Florida-themed Cloudflare Pages URL, through two Rebrandly redirects, to the same Worker documented by Menlo.

Figure 5: URLScan capture showing two Rebrandly redirects between the alternate Florida landing path and the Cloudflare Worker documented by Menlo

The automated URLScan session did not complete the Turnstile interaction or independently reproduce the archive download. That later stage is established separately by Menlo’s analysis.

Figure 6: URLScan redirect chain showing the two Rebrandly hops between the alternate Florida landing path and the Worker documented by Menlo

Conclusion

The independent evidence adds three observations to Menlo’s original reporting. A separate Florida-themed HTA was present by August 27 and shared the same admin.rshiahub[.]com delivery infrastructure and the f1040.pdf decoy filename documented in Menlo’s later sample. Distinct ScreenConnect MSI packages associated with rshiahub infrastructure were already visible in VirusTotal during July and August. URLScan also captured an alternate Florida landing path that passed through two Rebrandly redirects before reaching the same Cloudflare Worker documented by Menlo.

Taken together, these observations support, with moderate confidence, that the two Florida-themed HTAs are related components of the same delivery cluster. The evidence does not identify the operator, establish victim counts or show that every rshiahub-associated ScreenConnect package was delivered through this lure.

Observed infrastructure and artifacts

  • floridalicense.pages[.]dev/floridahealthcarescreeningnoticeforlicenseholders
  • floridalicense.pages[.]dev/floridadepartmentofhealthbackgroundscreeningrecordstatusnotice
  • rebrand[.]ly/Florida-Health-Care-Screening-Record-Not-Found
  • rebrand[.]ly/Florida-Department-of-Health-Background-Screening
  • docusig-document-sign6702.docusign-sign.workers[.]dev
  • admin.rshiahub[.]com
  • relay.rshiahub[.]com
  • rshiahub[.]com

File hashes observed during the research

  • Earlier Florida HTA: a472a201884e7a49d5ec25d3a972ad3c2255e80f63e062633e0405e36abb34fc
  • Menlo-analyzed HTA: 1d5ab21ee92e4212ece319a383dd7593e3b4a998df135bfefc7fad7874c90587
  • July ScreenConnect MSI: 07fb67680948d5da8031dd24a515dc33124e9d5bfcf19ab1bf5cbb1e99ac3f8d
  • Additional July ScreenConnect MSI: f72689ce96e2f8567c8ff37f789ada576ba39a741ac5a7fd13a2bc1ca31fc795
  • August ScreenConnect MSI: 5fdbdd388d303c59d619b0096af6dc9cb243eebb07659e8dd9055eeb34c1657f

The ScreenConnect hashes above are included because of their observed relationships with the rshiahub infrastructure. ScreenConnect is legitimate software, and these hashes should not be interpreted outside that context as generic malicious indicators.

Reference

Thanks for reading Hunting The Hunters!