← back to portfolio
Threat Hunting

Masqueraded Executable Intrusion

Category
Threat Hunting
Status
Complete
Platform
LetsDefend
Host
DESKTOP-ND6FH5D
Method
Sysmon telemetry analysis
MITRE ATT&CK
T1036 Masquerading T1204.002 User Execution T1105 Ingress Tool Transfer T1033 System Owner/User Discovery T1057 Process Discovery T1136.001 Create Local Account T1059.001 PowerShell
Executive Summary A user executed a downloaded file masquerading as a PDF, which established outbound network communication and spawned a command shell. The attacker performed basic host enumeration, created a new local account for persistence, then bypassed PowerShell's execution policy to run an additional downloaded script. Containment was applied at the network layer by blocking outbound communication to the identified remote host.
Table of Contents
  1. Scenario
  2. Evidence Collected
  3. Timeline
  4. Key Findings
  5. Attack Chain
  6. Lessons Learned
  7. Questions to Revisit

Scenario

Investigate suspicious activity using Sysmon logs to identify the attack chain from initial access through containment.

Evidence Collected

ArtifactSourceWhy It Mattered
application_form.pdf.exe Sysmon Logs Executable masqueraded as a PDF document
cmd.exe Sysmon Logs Spawned as a child process of the malicious executable shortly after execution
hxxp://13.232.55[.]12:8080/ Sysmon Logs Confirms internet source download and possible C2 communication
whoami.exe, tasklist.exe Sysmon Logs Child processes indicating basic host enumeration by the threat actor
net1.exe / net user jumpadmin ... /add Sysmon Logs New local account created for persistence
powershell.exe -ep bypass Sysmon Logs Execution policy bypass observed
C:\Windows\Temp\tmp.ps1 Sysmon Logs Script downloaded for additional post-exploitation

Timeline

Time (UTC)UserEventSource
09:24:11LetsDefendInternet download metadata (Zone.Identifier) recorded for application_form.pdf.exeSysmon EID 15
09:24:18LetsDefendDownloaded executable written to disk with Zone.Identifier ADSSysmon EID 11
09:28:07LetsDefendMalware established outbound network connectionSysmon EID 3
09:28:55LetsDefendcmd.exe spawned, followed by whoami.exe and tasklist.exe — host enumerationSysmon EID 1
09:31:57LetsDefendLocal account "jumpadmin" created for persistenceSysmon EID 1
09:41:44LetsDefendScript downloaded for additional post-exploitationSysmon EID 11
09:42:08LetsDefendPowerShell launched with ExecutionPolicy Bypass after tmp.ps1 was createdSysmon EID 11
09:46:03LOCAL SERVICEOutbound firewall rule added to block communication with the identified remote IPSysmon EID 13

Key Findings

Attack Chain

Initial Access
User executed a downloaded executable masquerading as a PDF document.
Execution
The malware gained code execution on the host.
Discovery
Basic host enumeration was performed via whoami and tasklist.
Persistence
A new local administrator account was created to maintain access.
Post-Exploitation
PowerShell was executed with ExecutionPolicy Bypass, and an additional script was deployed.

Lessons Learned

Questions to Revisit