| URL: | https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b |
| Full analysis: | https://app.any.run/tasks/82a45d73-8a2d-4d6c-a05a-79ab33010382 |
| Verdict: | Malicious activity |
| Analysis date: | January 23, 2024, 21:10:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 47B8AB739BF0BC018425CFC712E73614 |
| SHA1: | 6B58C71B8D610EEEDE65CD43B6251E110C540B6B |
| SHA256: | 7F089F95680B646D18D98F428A8FCB688706C54D3BC1482D3B45B80C2EA5CEA0 |
| SSDEEP: | 24:2Cl7qEfvjRHxHIccS4UUFpV5VDyksG9Xl+CHdaq:9qIb/oVSE5/sG9t9aq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1036 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2468 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1036 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C389FD106AACA95B265CC81A85B3522B_245866DC0962C292EE48EAD4527DEA95 | binary | |
MD5:E7C967A9A5911784BE8BE6C6FD6130A2 | SHA256:B43154DC3BB5DE8A7B4C014BB1AA208E414866D6735C571DE47B1EE923C32CFF | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C389FD106AACA95B265CC81A85B3522B_245866DC0962C292EE48EAD4527DEA95 | binary | |
MD5:AB491C10725FD2A0C4A6DC084804D90B | SHA256:63C863F8CC80FE61B86578F3D0DD3A9C6E542D7B81E4E61C012CE0F5A55410BC | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:795B7BDFA6DBC5A56708B21E2E8C1AC3 | SHA256:FCDEA161A594DD826F1EE30B7188A8EB4FE12665258861F2731485E1B1D9C4AE | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C389FD106AACA95B265CC81A85B3522B_3158BCFDC795D01E20AFDD162190388C | binary | |
MD5:475320B19121AC7D30F9BE628F9E2D0E | SHA256:0A8DA35C644779C964C5E0EA48154AD982735B4A2359B7D9F43929F01EE5CB40 | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\certificate-checker[1].htm | html | |
MD5:79B88A120BC1778261F6A2DA30D084FB | SHA256:79EA8C8CF894F37D8ECADBEA6215976D7B70A06A84C66A51DBB6B33F93C45849 | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187 | binary | |
MD5:A59CABD8398E72586491F86FF906B8C0 | SHA256:15745720A92C8A6416DEFEDCF439B0DFB8B7ADF520A2852F2CFFDD3AD2834F4C | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | binary | |
MD5:4467722E91AC2199B905EE7115742C4A | SHA256:B47D32BB71E759D8D6019D6B35FA0EEDDFEAA1C74B51EE8E29240C540FE28C50 | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C389FD106AACA95B265CC81A85B3522B_3158BCFDC795D01E20AFDD162190388C | binary | |
MD5:06C0B5297B34B1FE847CC027E0188914 | SHA256:60683053FCD5C49FD93A07DA4BEA0F756167BB4ED2D62C65F1FBBB5718229F6F | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\lodash-core.min[1].js | text | |
MD5:305753FF93FBC439257153952C2CD20F | SHA256:DE1FAC0AD3A03174F4E49969F48D2E499D19AFCD076DB19431D7B1CD707832FA | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | binary | |
MD5:B949F40F5DF580C7B487760A9567597A | SHA256:247E7644427A21F2689FABADB58A583470E0E6966F44237DE8C876FBB21C24EB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2468 | iexplore.exe | GET | 304 | 173.222.108.147:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3eeb0d7dd137312c | unknown | — | — | unknown |
1080 | svchost.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e2ddf83a2417bb20 | unknown | compressed | 65.2 Kb | unknown |
2468 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAZuec12JMYxMMd6vraou5Q%3D | unknown | binary | 314 b | unknown |
1036 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | binary | 471 b | unknown |
1036 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D | unknown | binary | 471 b | unknown |
2468 | iexplore.exe | GET | 200 | 95.101.54.130:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgN9CTE47eMSeLbyfgcUnzbrtg%3D%3D | unknown | binary | 503 b | unknown |
2468 | iexplore.exe | GET | 304 | 173.222.108.147:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?674f97faf1601d44 | unknown | — | — | unknown |
2468 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | binary | 471 b | unknown |
2468 | iexplore.exe | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIoVNkZjNmdUeUY4AAAAihU0%3D | unknown | binary | 1.74 Kb | unknown |
2468 | iexplore.exe | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIasL6Thd7aENMDIAAAAhqws%3D | unknown | binary | 1.74 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2468 | iexplore.exe | 20.90.50.115:443 | mcas-proxyweb.mcas.ms | MICROSOFT-CORP-MSN-AS-BLOCK | GB | unknown |
2468 | iexplore.exe | 173.222.108.147:80 | ctldl.windowsupdate.com | Akamai International B.V. | CH | unknown |
2468 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2468 | iexplore.exe | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2468 | iexplore.exe | 13.107.246.62:443 | mcasproxy.cdn.mcas.ms | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2468 | iexplore.exe | 2.19.229.121:443 | c.s-microsoft.com | AKAMAI-AS | FR | unknown |
1036 | iexplore.exe | 13.107.246.62:443 | mcasproxy.cdn.mcas.ms | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
mcas-proxyweb.mcas.ms |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
mcasproxy.cdn.mcas.ms |
| unknown |
c.s-microsoft.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |