case.edu - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned case.edu and returned a suspicious verdict (score 35), categorised as phishing. The page resolved to 23.185.0.3 on Pantheon in US. 16 domains and 1 IP were contacted, over 4 HTTP requests. 26 malware samples communicate with this URL (Ausiv, Genpack, HUILoader). The request followed 1 redirect before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 35) · Confidence 38%
- Scanned URL:
https://cwru.edu/ - Domain: case.edu · IP: 23.185.0.3 · AS54113 · US
- Server: Apache
- Page title: Case Western Reserve University: One of the nation's best
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 5 14: · subject CN=case.edu
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-23 15:57:42 UTC
Redirect chain
https://cwru.edu/https://case.edu/
Malware communicating with this URL (26)
These samples were observed contacting or being served from case.edu. Each links to its full analysis.
- Ausiv - referenced ·
da193049cd2aa56bd238af23b6e33ba6· first seen 2026-08-23 - Genpack - referenced ·
5faad36c1aeb7d28db013fce9bf5fd28· first seen 2026-08-23 - aa9d6c9ac0d7f13bbbc306763ab9ee9087908a3a494826decb966b612e221ee5 - referenced ·
aa9d6c9ac0d7f13bbbc306763ab9ee90· first seen 2026-08-22 - d889e8b7caf30f77f95ac8f1a386cd627b5176f0bc6133a9c0d58e7b7779ca16 - referenced ·
d889e8b7caf30f77f95ac8f1a386cd62· first seen 2026-08-22 - Genpack - referenced ·
6c2f106594d0074d030911d67142ba59· first seen 2026-08-22 - HUILoader - referenced ·
7ecf817020c0aba03d78f6ee1243a657· first seen 2026-08-22 - 5b6e45b78e3ec7042d523d8e2247f28f4e2a1c99d4c014cbc356a003e3bbe349 - referenced ·
5b6e45b78e3ec7042d523d8e2247f28f· first seen 2026-08-22 - 3d81893ea51c83f1883c4b0e4d5dfc44de4c528675677c1909783c4486078f8d - referenced ·
3d81893ea51c83f1883c4b0e4d5dfc44· first seen 2026-08-21 - Genpack - referenced ·
f86512124d0b148f3a0f065448ec9156· first seen 2026-08-21 - Genpack - referenced ·
7b50a460f3c491761b726927f1bbac27· first seen 2026-08-21 - Genpack - referenced ·
5f8927626487cf418223556650776fc1· first seen 2026-08-21 - Genpack - referenced ·
8c185d6cd1d387230296836ed68ebc64· first seen 2026-08-21 - Genpack - referenced ·
d77c0ab6a9d9f9585da088d8aac0af2b· first seen 2026-08-20 - HUILoader - referenced ·
e97db28f8312c4d1182120750f957486· first seen 2026-08-20 - HUILoader - referenced ·
ef1c74ee797131db2d62f5dec3f3fab9· first seen 2026-08-20
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Domain impersonates chase (typosquat)
Detected technologies
- Apache
- Fastly
- Google Analytics
Contacted infrastructure
- 23.185.0.3 - AS54113 Pantheon (United States)
Observed indicators
- case.edu
- www.googletagmanager.com
- fonts.googleapis.com
- dudbm6bcnmy8e.cloudfront.net
- webapps.case.edu
- player.vimeo.com
- athletics.case.edu
- community.case.edu
- www.facebook.com
- instagram.com
- www.tiktok.com
- www.linkedin.com
- www.youtube.com
- x.com
- canvas.case.edu
- mail.google.com
- 23.185.0.3
- https://case.edu/
- https://www.googletagmanager.com/gtm.js?id=
- https://case.edu/styles.ed5de666ca5a173bc15d.css
Other scans of case.edu (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
Questions about case.edu
- Is case.edu safe?
- No. MalwareAnalyzer scanned case.edu on 23 Aug 2026 and returned a suspicious verdict with a score of 35 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with case.edu?
- 26 analysed samples communicate with this URL, including Ausiv, Genpack, HUILoader.
- How was case.edu checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of case.edu
Scanned on MalwareAnalyzer by Cyble · Open interactive scan