URL:

https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b

Full analysis: https://app.any.run/tasks/82a45d73-8a2d-4d6c-a05a-79ab33010382
Verdict: Malicious activity
Analysis date: January 23, 2024, 21:10:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

47B8AB739BF0BC018425CFC712E73614

SHA1:

6B58C71B8D610EEEDE65CD43B6251E110C540B6B

SHA256:

7F089F95680B646D18D98F428A8FCB688706C54D3BC1482D3B45B80C2EA5CEA0

SSDEEP:

24:2Cl7qEfvjRHxHIccS4UUFpV5VDyksG9Xl+CHdaq:9qIb/oVSE5/sG9t9aq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 1036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
2
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1036"C:\Program Files\Internet Explorer\iexplore.exe" "https://mcas-proxyweb.mcas.ms/certificate-checker?login=false&originalUrl=https%3A%2F%2Femail.em.teachable.com.mcas.ms%2Fc%2FeJyEkU-PojAYhz8N3iSlf0AOHBwdFGJxxlFULqQtVepQYKGMq59-Q-Jmj3t98sv7JO9TBJwwAoQ7kYHjAQIAwp4_kZqpKu-kkKo1uSoCh7jezEEEg0kZIEIY4-zCgOf4grvcEwUiaOZ6xCXSQRMVuIQB7BduIbiHcwewC0PC97ELLQxUO3XAFEwdF02xLQW0VW1kV7PKHr2TKiiNaXsLzS0YWjDs-8Y2komS8UraotEjk2LopAVDAmcQIwuGqpC1UeZhwVA09UV12kKhab5lbaGlfMQlXwm1VXF0eEZOomLfHmFx_BxhxY9hy0P_xiHR7BSb82nXcojVZhFXcj1X29s7ossDpMvrI3le-0hXZbGIXLoX92Q_v9PnJ9ou7oqdkmd0a5SA5kJXpKe3N01P7-OdX8Xqe3SVVNNBrMs6PaSDgDE87otUwGIh0FuWrNohe5D1dpUedt-N2VXVBz1dcbYONUVZn4U-itRdCZSq0cPqtOTa-RE6fZ6hPz_r5L7RyQ__IvfsK-ojnZrzser_v419O99HovzA6JHF8Xpz-e0kO3r9AB3R6Dy_Ut1uBqwExQc5s6A7GJ33zdAJaaHlv-8TGA697PIxpexeOy0LNegxxIhfUDDdMnWt_-L81Y0Z1dSTLrgNrNZNJ3vRWBhw0Y7t7Vb-CQAA__8AWOXT%3FMcasTsid%3D20893&McasCSRF=25d6a2b0115d177aa89c243ff278ff3354929a8d4458efa6c803b4d8af0ab27b"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2468"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1036 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
Total events
19 697
Read events
19 613
Write events
78
Delete events
6

Modification events

(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1036) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
35
Text files
89
Unknown types
2

Dropped files

PID
Process
Filename
Type
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187binary
MD5:E05409CB0EBF9C64D95AEBE46A8AA2A7
SHA256:3AFC3D9426E1639CCC0CB06832C6F4975392275D846CABF39F9042A1A02D3C7F
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\lodash-core.min[1].jstext
MD5:305753FF93FBC439257153952C2CD20F
SHA256:DE1FAC0AD3A03174F4E49969F48D2E499D19AFCD076DB19431D7B1CD707832FA
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:795B7BDFA6DBC5A56708B21E2E8C1AC3
SHA256:FCDEA161A594DD826F1EE30B7188A8EB4FE12665258861F2731485E1B1D9C4AE
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\certificate-checker[1].htmhtml
MD5:79B88A120BC1778261F6A2DA30D084FB
SHA256:79EA8C8CF894F37D8ECADBEA6215976D7B70A06A84C66A51DBB6B33F93C45849
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\handlebars.min[1].jstext
MD5:23A22FFCC70E2746BEADCC16682C2389
SHA256:0E5416F145E7BF16C58504356C732FE7E99671F4696194C5B140A252DB02F0AF
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5IWPIAR9\handlebars-intl-v1.1.2.min[1].jsbinary
MD5:B2D049BAF2998B71856541F52B4A1011
SHA256:CBD968CB519449BEC69DA9BAEF057689EE7DBB042F2FFDC4591C02E90BD57FC3
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\proxyweb-all.min[1].csstext
MD5:94FA56261D8B4D71DFEA8466FF9F9A82
SHA256:DF1D1F6EA96445DFFF2B82AF551E05F8EC85001E2D8BE7B2D457BFE74DFAED33
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\DY534W2X\latest[1].eotbinary
MD5:E861E84403ED028B18BF256583877718
SHA256:374D3C940693B5B5839F847CA15E3EE5A878C52B613AED91E8A08D93A2D42440
2468iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_363582827213C09529A76F35FB615187binary
MD5:A59CABD8398E72586491F86FF906B8C0
SHA256:15745720A92C8A6416DEFEDCF439B0DFB8B7ADF520A2852F2CFFDD3AD2834F4C
2468iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\YTOWV792\latest[1].eotbinary
MD5:E812BA8B7E2A657F2B70CFACE93C7682
SHA256:3330C1DEAC468874238DD0C6BF902179A8731EDA8A208C7D01DAC0AB1EAE1BC9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
53
DNS requests
28
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2468
iexplore.exe
GET
304
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?674f97faf1601d44
unknown
unknown
2468
iexplore.exe
GET
304
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3eeb0d7dd137312c
unknown
unknown
2468
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
binary
471 b
unknown
2468
iexplore.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIoVNkZjNmdUeUY4AAAAihU0%3D
unknown
binary
1.74 Kb
unknown
2468
iexplore.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSzT%2FzqwcqNvhP9i4c4sCPz2JbzrAQU%2FglxQFUFEETYpIF1uJ4a6UoGiMgCEzMAIasL6Thd7aENMDIAAAAhqws%3D
unknown
binary
1.74 Kb
unknown
2468
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
binary
471 b
unknown
1036
iexplore.exe
GET
304
173.222.108.147:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5899fa93c88d99e3
unknown
unknown
1036
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
binary
312 b
unknown
1036
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e2ddf83a2417bb20
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2468
iexplore.exe
20.90.50.115:443
mcas-proxyweb.mcas.ms
MICROSOFT-CORP-MSN-AS-BLOCK
GB
unknown
2468
iexplore.exe
173.222.108.147:80
ctldl.windowsupdate.com
Akamai International B.V.
CH
unknown
2468
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2468
iexplore.exe
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2468
iexplore.exe
13.107.246.62:443
mcasproxy.cdn.mcas.ms
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2468
iexplore.exe
2.19.229.121:443
c.s-microsoft.com
AKAMAI-AS
FR
unknown
1036
iexplore.exe
13.107.246.62:443
mcasproxy.cdn.mcas.ms
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
mcas-proxyweb.mcas.ms
  • 20.90.50.115
unknown
ctldl.windowsupdate.com
  • 173.222.108.147
  • 173.222.108.226
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
mcasproxy.cdn.mcas.ms
  • 13.107.246.62
  • 13.107.213.62
unknown
c.s-microsoft.com
  • 2.19.229.121
whitelisted
api.bing.com
  • 13.107.5.80
whitelisted
www.bing.com
  • 104.126.37.145
  • 104.126.37.131
  • 2.23.209.133
  • 2.23.209.130
  • 2.23.209.187
  • 2.23.209.182
  • 2.23.209.149
  • 2.20.142.163
  • 2.20.142.154
  • 2.20.142.179
  • 2.20.142.184
  • 2.20.142.187
  • 2.20.142.153
  • 2.20.142.186
  • 2.20.142.181
  • 2.20.142.3
  • 2.23.209.179
  • 2.23.209.140
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted

Threats

No threats detected
No debug info