Additional Info:
Date of Investigation: Aug, 29, 2024, 11:15 PM
Alert Title: Meterpreter or Empire activity detected
Time to investigate: 42 Minutes
Retrospective Note:
If I were to revisit this today, I’d use more accurate wording on the specific tool being used. For example, instead of “Checking the endpoint”, I would say “After checking the endpoint security tool/module…”, since this was me checking the EDR equivalent rather than connecting directly to the host. I would also note down the exact commands shown in the terminal history that the threat actor ran. Then include the queries run on the SIEM and Email Tool to check for scope and entry vector. As well as including the value of any IP or Hash that was brought up. I also noticed that in the case management, I marked it as a True Positive, but realistically, I would mark this as a False Positive and recommend adding cobalt to the title. The case management didn’t list the trigger reason, so I can’t comment on that.
Affected systems and users
Endpoint/SRC IP: 172.16.17.55
C2 IP: 120.79.181.138
Hostname: Alex - HP
IP Connected to LOLB: 221.181.185.200
Steps taken in the investigation
Ran hash in Virustotal. It was flagged as Malicious by 67 vendors. Hybrid analysis reports as malicious. Any.run has reports on the executable. Internal Threat Intelligence returned no data.
Checking the endpoint, Network activity shows that the last IP contacted has a history of being used as a Cobalt Strike C2 server. The endpoint contacted a C2 on March 15th, 2021. Important to note that the last login date is December 22, 2020.
Terminal History shows suspicious activity using LOLB techniques dating back to December 2020, which may be part of this current alert, as I wasn’t able to find how the Cobalt Strike script got onto the system. Attempted to look for the file name in logs and emails.
Actions taken
Contained Endpoint
References
https://www.virustotal.com/gui/file/b9321c27be4295c15d7f92fafc20d7ccac5f21204b79ebc2fed583dda0197cf9/detection
https://www.virustotal.com/gui/ip-address/120.79.181.138/community
https://www.virustotal.com/gui/ip-address/221.181.185.200/community
https://app.any.run/tasks/39e84711-2652-41b1-ad67-e2198baf2f43/
https://www.hybrid-analysis.com/search?query=+24d99ba5654cdf31141c66fd9417b7e0
----------- (Artifacts below were separate from notes but input into case management)
Extracted Artifacts:
Type Value Comment
MD5 Hash 24d99ba5654cdf31141c66fd9417b7e0
IP Address 120.79.181[.]138 C2 IP
IP Address 221.181.185[.]200 LOLB IP
Requested URL 1: hxxps[://]221[.]181[.]185[.]200:8080/services[.]exe
Requested URL 2: hxxps[://]221[.]181[.]185[.]200:8080/svchosts[.]exe
