Analyst Note Sample – LetsDefend Event ID 182


Additional Info:
Date of investigation: Dec, 04, 2024, 10:27 PM
Alert title: Possible MalDoc in PDF was Detected
Time to investigate: 27 minutes

Retrospective Note:
If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact query used to find the logs tied to the RAR file and include the timestamps for those actions. As well as the timestamp and URL of the site contacted. As well as noting down the paths where the malicious files were dropped.

Affected systems and users

Endpoint Address IP:172.16.17.143
Hostname: Angela
Malicious IP: 146[.]70.45.83

Steps taken in the investigation
Hash is reported as malicious by 37 vendors, according to VirusTotal. Internal threat intelligence marks the file as known malicious. Checked Anyrun, but all the reports there are labeled as non-malicious. I can see that the files had to be user-executed and that a second executable file is dropped; this executable checked for information on the system. Checked SIEM and confirmed that the .rar file was downloaded, unpacked, and executed. After execution, we can see a connection being made to a site. This site is marked as malicious by 15 vendors. 

Artifacts
Support AT impressiondigitals[.]agency
146[.]70.45.83
cba6bd373e42a7bcbc4c7251bc188b69
179[.]60.147.117
hxxp[://]web365metrics.[]com/

Actions taken
Contained the system. Deleted the files from the endpoint.

References
https://www.virustotal.com/gui/file/098796e1b82c199ad226bff056b6310262b132f6d06930d3c254c57bdf548187
https://app.any.run/tasks/6a9e9ea2-836d-49cf-8ea5-946eaddfeeae
https://www.virustotal.com/gui/ip-address/179.60.147.117
https://www.abuseipdb.com/check/179.60.147.117
https://www.virustotal.com/gui/url/91f63156aca5cf7a80d131ba0e5cc288acf9001abc6c6d20d814c792f566b530/detection
https://www.virustotal.com/gui/ip-address/146.70.45.83
https://www.abuseipdb.com/check/146.70.45.83
https://www.virustotal.com/gui/domain/impressiondigitals.agency