case.edu - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned case.edu and returned a suspicious verdict (score 35), categorised as phishing. The page resolved to 23.185.0.3 on Pantheon in US. 16 domains and 1 IP were contacted, over 4 HTTP requests. 22 malware samples communicate with this URL (Genpack, HUILoader). The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 35) · Confidence 38%
- Scanned URL:
https://cwru.edu/ - Domain: case.edu · IP: 23.185.0.3 · AS54113 · US
- Server: Apache
- Page title: Case Western Reserve University: One of the nation's best
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 5 14: · subject CN=case.edu
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-22 10:06:59 UTC
Redirect chain
https://cwru.edu/https://case.edu/
Malware communicating with this URL (22)
These samples were observed contacting or being served from case.edu. Each links to its full analysis.
- Genpack - referenced ·
6c2f106594d0074d030911d67142ba59· first seen 2026-08-22 - HUILoader - referenced ·
7ecf817020c0aba03d78f6ee1243a657· first seen 2026-08-22 - 5b6e45b78e3ec7042d523d8e2247f28f4e2a1c99d4c014cbc356a003e3bbe349 - referenced ·
5b6e45b78e3ec7042d523d8e2247f28f· first seen 2026-08-22 - 3d81893ea51c83f1883c4b0e4d5dfc44de4c528675677c1909783c4486078f8d - referenced ·
3d81893ea51c83f1883c4b0e4d5dfc44· first seen 2026-08-21 - Genpack - referenced ·
f86512124d0b148f3a0f065448ec9156· first seen 2026-08-21 - Genpack - referenced ·
7b50a460f3c491761b726927f1bbac27· first seen 2026-08-21 - Genpack - referenced ·
5f8927626487cf418223556650776fc1· first seen 2026-08-21 - Genpack - referenced ·
8c185d6cd1d387230296836ed68ebc64· first seen 2026-08-21 - Genpack - referenced ·
d77c0ab6a9d9f9585da088d8aac0af2b· first seen 2026-08-20 - HUILoader - referenced ·
e97db28f8312c4d1182120750f957486· first seen 2026-08-20 - HUILoader - referenced ·
ef1c74ee797131db2d62f5dec3f3fab9· first seen 2026-08-20 - Genpack - referenced ·
7fcf1dc3e823c3319fe8651187a19ff9· first seen 2026-08-19 - Genpack - referenced ·
55645c363092d003a978246b75a134cb· first seen 2026-08-17 - ee1151c0bc7e127363105145ba04e6f290a2847079dc961de6dd707f20b5abbd - referenced ·
ee1151c0bc7e127363105145ba04e6f2· first seen 2026-08-16 - 8ddd700c118dec6bedb39ec95094630cd76c4cad94a8da68f3363c758d6cac81 - referenced ·
8ddd700c118dec6bedb39ec95094630c· first seen 2026-08-15
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Domain impersonates chase (typosquat)
Detected technologies
- Apache
- Fastly
- Google Analytics
Contacted infrastructure
- 23.185.0.3 - AS54113 Pantheon (United States)
Observed indicators
- case.edu
- www.googletagmanager.com
- fonts.googleapis.com
- dudbm6bcnmy8e.cloudfront.net
- webapps.case.edu
- player.vimeo.com
- athletics.case.edu
- community.case.edu
- www.facebook.com
- instagram.com
- www.tiktok.com
- www.linkedin.com
- www.youtube.com
- x.com
- canvas.case.edu
- mail.google.com
- 23.185.0.3
- https://case.edu/
- https://www.googletagmanager.com/gtm.js?id=
- https://case.edu/styles.ed5de666ca5a173bc15d.css
Other scans of case.edu (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
Questions about case.edu
- Is case.edu safe?
- No. MalwareAnalyzer scanned case.edu on 22 Aug 2026 and returned a suspicious verdict with a score of 35 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with case.edu?
- 22 analysed samples communicate with this URL, including Genpack, HUILoader.
- How was case.edu checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of case.edu
Scanned on MalwareAnalyzer by Cyble · Open interactive scan