URL:

https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b

Full analysis: https://app.any.run/tasks/82a45d73-8a2d-4d6c-a05a-79ab33010382
Verdict: Malicious activity
Analysis date: January 23, 2024, 21:10:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

47B8AB739BF0BC018425CFC712E73614

SHA1:

6B58C71B8D610EEEDE65CD43B6251E110C540B6B

SHA256:

7F089F95680B646D18D98F428A8FCB688706C54D3BC1482D3B45B80C2EA5CEA0

SSDEEP:

24:2Cl7qEfvjRHxHIccS4UUFpV5VDyksG9Xl+CHdaq:9qIb/oVSE5/sG9t9aq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1036"C:\Program Files\Internet Explorer\iexplore.exe" "https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2468"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1036 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
19 697
Read events
19 613
Write events
78
Delete events
6

Modification events

(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
35
Text files
89
Unknown types
2

Dropped files

PID
Process
Filename
Type
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C389FD106AACA95B265CC81A85B3522B_245866DC0962C292EE48EAD4527DEA95binary
MD5:E7C967A9A5911784BE8BE6C6FD6130A2
SHA256:B43154DC3BB5DE8A7B4C014BB1AA208E414866D6735C571DE47B1EE923C32CFF
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C389FD106AACA95B265CC81A85B3522B_245866DC0962C292EE48EAD4527DEA95binary
MD5:AB491C10725FD2A0C4A6DC084804D90B
SHA256:63C863F8CC80FE61B86578F3D0DD3A9C6E542D7B81E4E61C012CE0F5A55410BC
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:795B7BDFA6DBC5A56708B21E2E8C1AC3
SHA256:FCDEA161A594DD826F1EE30B7188A8EB4FE12665258861F2731485E1B1D9C4AE
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C389FD106AACA95B265CC81A85B3522B_3158BCFDC795D01E20AFDD162190388Cbinary
MD5:475320B19121AC7D30F9BE628F9E2D0E
SHA256:0A8DA35C644779C964C5E0EA48154AD982735B4A2359B7D9F43929F01EE5CB40
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\certificate-checker[1].htmhtml
MD5:79B88A120BC1778261F6A2DA30D084FB
SHA256:79EA8C8CF894F37D8ECADBEA6215976D7B70A06A84C66A51DBB6B33F93C45849
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187binary
MD5:A59CABD8398E72586491F86FF906B8C0
SHA256:15745720A92C8A6416DEFEDCF439B0DFB8B7ADF520A2852F2CFFDD3AD2834F4C
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:4467722E91AC2199B905EE7115742C4A
SHA256:B47D32BB71E759D8D6019D6B35FA0EEDDFEAA1C74B51EE8E29240C540FE28C50
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C389FD106AACA95B265CC81A85B3522B_3158BCFDC795D01E20AFDD162190388Cbinary
MD5:06C0B5297B34B1FE847CC027E0188914
SHA256:60683053FCD5C49FD93A07DA4BEA0F756167BB4ED2D62C65F1FBBB5718229F6F
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\lodash-core.min[1].jstext
MD5:305753FF93FBC439257153952C2CD20F
SHA256:DE1FAC0AD3A03174F4E49969F48D2E499D19AFCD076DB19431D7B1CD707832FA
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04binary
MD5:B949F40F5DF580C7B487760A9567597A
SHA256:247E7644427A21F2689FABADB58A583470E0E6966F44237DE8C876FBB21C24EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
53
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2468
iexplore.exe
GET
304
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3eeb0d7dd137312c
unknown
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e2ddf83a2417bb20
unknown
compressed
65.2 Kb
unknown
2468
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAZuec12JMYxMMd6vraou5Q%3D
unknown
binary
314 b
unknown
1036
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
unknown
1036
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAxq6XzO1ZmDhpCgCp6lMhQ%3D
unknown
binary
471 b
unknown
2468
iexplore.exe
GET
200
95.101.54.130:80
http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgN9CTE47eMSeLbyfgcUnzbrtg%3D%3D
unknown
binary
503 b
unknown
2468
iexplore.exe
GET
304
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?674f97faf1601d44
unknown
unknown
2468
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
binary
471 b
unknown
2468
iexplore.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIoVNkZjNmdUeUY4AAAAihU0%3D
unknown
binary
1.74 Kb
unknown
2468
iexplore.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIasL6Thd7aENMDIAAAAhqws%3D
unknown
binary
1.74 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2468
iexplore.exe
20.90.50.115:443
mcas-proxyweb.mcas.ms
MICROSOFT-CORP-MSN-AS-BLOCK
GB
unknown
2468
iexplore.exe
173.222.108.147:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
2468
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2468
iexplore.exe
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2468
iexplore.exe
13.107.246.62:443
mcasproxy.cdn.mcas.ms
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2468
iexplore.exe
2.19.229.121:443
c.s-microsoft.com
AKAMAI-AS
FR
unknown
1036
iexplore.exe
13.107.246.62:443
mcasproxy.cdn.mcas.ms
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
mcas-proxyweb.mcas.ms
  • 20.90.50.115
unknown
ctldl.windowsupdate.com
  • 173.222.108.147
  • 173.222.108.226
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
mcasproxy.cdn.mcas.ms
  • 13.107.246.62
  • 13.107.213.62
unknown
c.s-microsoft.com
  • 2.19.229.121
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.131
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.187
  • 2.23.209.182
  • 2.23.209.149
  • 2.20.142.163
  • 2.20.142.154
  • 2.20.142.179
  • 2.20.142.184
  • 2.20.142.187
  • 2.20.142.153
  • 2.20.142.186
  • 2.20.142.181
  • 2.20.142.3
  • 2.23.209.179
  • 2.23.209.140
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
No debug info