On September 10, 2026, Menlo Security documented a phishing chain that used a Florida healthcare background-screening lure to deliver ConnectWise ScreenConnect through a malicious HTA. Its analysis established the path from a Cloudflare Pages landing page to the HTA and the unauthorized ScreenConnect installation.
Pivoting from Menlo’s published indicators through VirusTotal, CAPE, and URLScan identified a separate Florida-themed HTA observed earlier in August, ScreenConnect packages associated with the same rshiahub infrastructure, and an alternate redirect path to the Cloudflare Worker documented by Menlo. The evidence extends the observable timeline of the associated infrastructure but does not identify the operator, establish victim counts, or prove that every rshiahub package used the Florida lure.

What Menlo Security established
Menlo documented a DocuSign-themed page at floridalicense.pages[.]dev/floridahealthcarescreeningnoticeforlicenseholders. After user interaction, the page requested a download from docusig-document-sign6702.docusign-sign.workers[.]dev/download. The Worker returned an archive containing Florida Background Screening Notice.hta (1d5ab21ee92e4212ece319a383dd7593e3b4a998df135bfefc7fad7874c90587).
Menlo found that the HTA retrieved and silently installed ScreenConnect from admin.rshiahub[.]com and opened a Dropbox-hosted f1040.pdf as a decoy.
Earlier ScreenConnect activity around rshiahub

VirusTotal recorded three distinct ScreenConnect MSI hashes associated with rshiahub infrastructure during July and August 2026. The earliest of these was first submitted to VirusTotal on July 27. Its relationship data included an admin.rshiahub[.]com deployment URL configured with e=Access and y=Guest; other July and August ScreenConnect packages communicated with relay.rshiahub[.]com. (Note: these are VirusTotal observation dates, not proof of when the files were first deployed.)

A separate Florida HTA was present in August
VirusTotal first received another file named Florida Background Screening Notice.hta on August 27:
- a472a201884e7a49d5ec25d3a972ad3c2255e80f63e062633e0405e36abb34fc
VirusTotal relationship data associated the earlier HTA with a request to admin.rshiahub[.]com/Bin/ScreenConnect.ClientSetup.exe containing e=Access and y=Guest. The same HTA also contacted Dropbox for f1040.pdf, the same decoy filename documented by Menlo in the later chain.

A CAPE run captured mshta.exe launching the HTA and Adobe Acrobat opening C:\ProgramData\f1040.pdf. It did not capture the ScreenConnect bootstrapper or MSI being written and executed. The execution therefore confirms execution of the HTA and the opening of f1040.pdf, not completion of the ScreenConnect installation.

The two HTAs share several specific characteristics: both use the Florida background-screening narrative, both reference admin.rshiahub[.]com and both reference f1040.pdf as a decoy filename. Menlo’s later sample was shown to retrieve and silently install ScreenConnect. The earlier August sample requested a ScreenConnect bootstrapper configured with Access and Guest parameters, although its installation stage was not captured in the available CAPE execution. Taken together, these overlaps support, with moderate confidence, that the two HTAs are related components of the same Florida-themed delivery cluster. They do not establish a common operator.
An alternate redirect path
URLScan captured an alternate Florida landing path on August 31:
floridalicense.pages[.]dev/floridadepartmentofhealthbackgroundscreeningrecordstatusnotice
→ rebrand[.]ly/Florida-Health-Care-Screening-Record-Not-Found
→ rebrand[.]ly/Florida-Department-of-Health-Background-Screening
→ docusig-document-sign6702.docusign-sign.workers[.]dev
The capture establishes an alternate path from a Florida-themed Cloudflare Pages URL, through two Rebrandly redirects, to the same Worker documented by Menlo.

The automated URLScan session did not complete the Turnstile interaction or independently reproduce the archive download. That later stage is established separately by Menlo’s analysis.

Conclusion
The independent evidence adds three observations to Menlo’s original reporting. A separate Florida-themed HTA was present by August 27 and shared the same admin.rshiahub[.]com delivery infrastructure and the f1040.pdf decoy filename documented in Menlo’s later sample. Distinct ScreenConnect MSI packages associated with rshiahub infrastructure were already visible in VirusTotal during July and August. URLScan also captured an alternate Florida landing path that passed through two Rebrandly redirects before reaching the same Cloudflare Worker documented by Menlo.
Taken together, these observations support, with moderate confidence, that the two Florida-themed HTAs are related components of the same delivery cluster. The evidence does not identify the operator, establish victim counts or show that every rshiahub-associated ScreenConnect package was delivered through this lure.
Observed infrastructure and artifacts
floridalicense.pages[.]dev/floridahealthcarescreeningnoticeforlicenseholdersfloridalicense.pages[.]dev/floridadepartmentofhealthbackgroundscreeningrecordstatusnoticerebrand[.]ly/Florida-Health-Care-Screening-Record-Not-Foundrebrand[.]ly/Florida-Department-of-Health-Background-Screeningdocusig-document-sign6702.docusign-sign.workers[.]devadmin.rshiahub[.]comrelay.rshiahub[.]comrshiahub[.]com
File hashes observed during the research
- Earlier Florida HTA:
a472a201884e7a49d5ec25d3a972ad3c2255e80f63e062633e0405e36abb34fc - Menlo-analyzed HTA:
1d5ab21ee92e4212ece319a383dd7593e3b4a998df135bfefc7fad7874c90587 - July ScreenConnect MSI:
07fb67680948d5da8031dd24a515dc33124e9d5bfcf19ab1bf5cbb1e99ac3f8d - Additional July ScreenConnect MSI:
f72689ce96e2f8567c8ff37f789ada576ba39a741ac5a7fd13a2bc1ca31fc795 - August ScreenConnect MSI:
5fdbdd388d303c59d619b0096af6dc9cb243eebb07659e8dd9055eeb34c1657f
The ScreenConnect hashes above are included because of their observed relationships with the
rshiahubinfrastructure. ScreenConnect is legitimate software, and these hashes should not be interpreted outside that context as generic malicious indicators.
Reference
- Menlo Security, “From Fake DocuSign to ScreenConnect: Inside a Web Attack Stopped Before Payload Delivery,” September 10, 2026.
Thanks for reading Hunting The Hunters!
