| URL: | https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b |
| Full analysis: | https://app.any.run/tasks/82a45d73-8a2d-4d6c-a05a-79ab33010382 |
| Verdict: | Malicious activity |
| Analysis date: | January 23, 2024, 21:10:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MD5: | 47B8AB739BF0BC018425CFC712E73614 |
| SHA1: | 6B58C71B8D610EEEDE65CD43B6251E110C540B6B |
| SHA256: | 7F089F95680B646D18D98F428A8FCB688706C54D3BC1482D3B45B80C2EA5CEA0 |
| SSDEEP: | 24:2Cl7qEfvjRHxHIccS4UUFpV5VDyksG9Xl+CHdaq:9qIb/oVSE5/sG9t9aq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1036 | "C:\Program Files\Internet Explorer\iexplore.exe" "https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b" | C:\Program Files\Internet Explorer\iexplore.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2468 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1036 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 0 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 30847387 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 30847437 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1036) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187 | binary | |
MD5:E05409CB0EBF9C64D95AEBE46A8AA2A7 | SHA256:3AFC3D9426E1639CCC0CB06832C6F4975392275D846CABF39F9042A1A02D3C7F | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\lodash-core.min[1].js | text | |
MD5:305753FF93FBC439257153952C2CD20F | SHA256:DE1FAC0AD3A03174F4E49969F48D2E499D19AFCD076DB19431D7B1CD707832FA | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:795B7BDFA6DBC5A56708B21E2E8C1AC3 | SHA256:FCDEA161A594DD826F1EE30B7188A8EB4FE12665258861F2731485E1B1D9C4AE | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\certificate-checker[1].htm | html | |
MD5:79B88A120BC1778261F6A2DA30D084FB | SHA256:79EA8C8CF894F37D8ECADBEA6215976D7B70A06A84C66A51DBB6B33F93C45849 | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\handlebars.min[1].js | text | |
MD5:23A22FFCC70E2746BEADCC16682C2389 | SHA256:0E5416F145E7BF16C58504356C732FE7E99671F4696194C5B140A252DB02F0AF | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\handlebars-intl-v1.1.2.min[1].js | binary | |
MD5:B2D049BAF2998B71856541F52B4A1011 | SHA256:CBD968CB519449BEC69DA9BAEF057689EE7DBB042F2FFDC4591C02E90BD57FC3 | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\proxyweb-all.min[1].css | text | |
MD5:94FA56261D8B4D71DFEA8466FF9F9A82 | SHA256:DF1D1F6EA96445DFFF2B82AF551E05F8EC85001E2D8BE7B2D457BFE74DFAED33 | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\latest[1].eot | binary | |
MD5:E861E84403ED028B18BF256583877718 | SHA256:374D3C940693B5B5839F847CA15E3EE5A878C52B613AED91E8A08D93A2D42440 | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187 | binary | |
MD5:A59CABD8398E72586491F86FF906B8C0 | SHA256:15745720A92C8A6416DEFEDCF439B0DFB8B7ADF520A2852F2CFFDD3AD2834F4C | |||
| 2468 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\latest[1].eot | binary | |
MD5:E812BA8B7E2A657F2B70CFACE93C7682 | SHA256:3330C1DEAC468874238DD0C6BF902179A8731EDA8A208C7D01DAC0AB1EAE1BC9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2468 | iexplore.exe | GET | 304 | 173.222.108.147:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?674f97faf1601d44 | unknown | — | — | unknown |
2468 | iexplore.exe | GET | 304 | 173.222.108.147:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3eeb0d7dd137312c | unknown | — | — | unknown |
2468 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | binary | 471 b | unknown |
2468 | iexplore.exe | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIoVNkZjNmdUeUY4AAAAihU0%3D | unknown | binary | 1.74 Kb | unknown |
2468 | iexplore.exe | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIasL6Thd7aENMDIAAAAhqws%3D | unknown | binary | 1.74 Kb | unknown |
2468 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | binary | 471 b | unknown |
1036 | iexplore.exe | GET | 304 | 173.222.108.147:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5899fa93c88d99e3 | unknown | — | — | unknown |
1036 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 312 b | unknown |
1036 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
1080 | svchost.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e2ddf83a2417bb20 | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2468 | iexplore.exe | 20.90.50.115:443 | mcas-proxyweb.mcas.ms | MICROSOFT-CORP-MSN-AS-BLOCK | GB | unknown |
2468 | iexplore.exe | 173.222.108.147:80 | ctldl.windowsupdate.com | Akamai International B.V. | CH | unknown |
2468 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2468 | iexplore.exe | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2468 | iexplore.exe | 13.107.246.62:443 | mcasproxy.cdn.mcas.ms | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2468 | iexplore.exe | 2.19.229.121:443 | c.s-microsoft.com | AKAMAI-AS | FR | unknown |
1036 | iexplore.exe | 13.107.246.62:443 | mcasproxy.cdn.mcas.ms | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
mcas-proxyweb.mcas.ms |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
mcasproxy.cdn.mcas.ms |
| unknown |
c.s-microsoft.com |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |