Analyst Note Sample – LetsDefend Event ID 198


Additional Info:
Date of Investigation: Nov, 05, 2024, 06:16 AM
Alert title: Unauthorized Access – Hack Tool Executed
Time to investigate: 16 minutes

Retrospective note:
If I were to revisit this today, I would list the command used to download Mimikatz and its timestamp, as well as the time it was executed. Include the SIEM Query to detect the brute-force attack, and note the offending IP and the timestamp of the successful login. As well as the query made to check for outbound connections and scope. On the host, take note of the malicious file paths that were removed.

Affected systems and users

Endpoint Address IP: 172.16.17.168
Hostname: Oliver
Suspected Malicious IP:37.19.205.153

Steps taken in the investigation
I checked the Endpoint Security Module. Terminal history shows that Mimikatz was downloaded and executed on the system. Endpoint security also gave us the file hash, and it’s confirmed that 63 vendors mark the file as malicious and as Mimikatz. I confirmed that the initial entry was made through a brute-force attack. The Malicious IP also has a history of malicious activity and is flagged as malicious by three vendors on Virustotal. SIEM doesn’t show any additional data exfiltration. This endpoint seems to be the only one affected by this attack.

Artifacts
hxxps[://]files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/static/test[.]zip
E930b05efe23891d19bc354a4209be3e
37[.]19.205.153

Actions taken
Contained System. Removed malicious files

References
https://www.virustotal.com/gui/ip-address/37.19.205.153
https://www.abuseipdb.com/check/37.19.205.153
https://www.virustotal.com/gui/file/92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50