Phishing Users to Take a Test - MDSec
Common Information
Type Value
UUID fbaf310e-b885-4559-a081-2bb8f8d55b38
Fingerprint 2c1a891a292db114
Analysis status DONE
Considered CTI value 0
Text language
Published March 9, 2021, 10:42 a.m.
Added to db Jan. 18, 2023, 11:29 p.m.
Last updated Nov. 17, 2024, 11:40 p.m.
Headline Phishing Users to Take a Test
Title Phishing Users to Take a Test - MDSec
Detected Hints/Tags/Attributes 32/2/26
Attributes
Details Type #Events CTI Value
Details Domain 281
docs.microsoft.com
Details Domain 4128
github.com
Details Domain 1
securebrowserapispecification.md
Details Domain 831
example.com
Details Domain 1
takeatest.blob.core.windows.net
Details Domain 1
securebrowser.security
Details Domain 49
xhr.open
Details Domain 67
microsoft.windows
Details File 1
takeatest.blob
Details File 1
testpage.html
Details File 1
secureassessmentbrowser.exe
Details File 2
'onedrive.exe
Details File 1
'vpnui.exe
Details File 5
'notepad.exe
Details File 1
secureassessment_jsbridge.dll
Details Github username 1
smarterapp
Details Github username 6
mdsecactivebreach
Details Url 1
https://docs.microsoft.com/en-us/education/windows/take-tests-in-windows-10
Details Url 1
https://docs.microsoft.com/en-us/education/windows/take-a-test-app-technical
Details Url 1
https://github.com/smarterapp/sb_birt/blob/master/irp/doc/req/securebrowserapispecification.md
Details Url 1
https://example.com/#enforcelockdown
Details Url 1
https://takeatest.blob.core.windows.net/takeatest-link-generator/testpage.html
Details Url 1
https://example.com/?getdeviceinfo
Details Url 1
https://example.com/?getmacaddress=
Details Url 1
https://example.com/?examineprocesslist=
Details Url 1
https://github.com/mdsecactivebreach/takeatest