Additional Info:
Date of Investigation: Sep, 06, 2024, 01:59 AM
Alert Title: Unauthorized Access to NTDS.dit File Detected
Time to investigate: 52 Minutes
Retrospective Note:
If I were to revisit this today, I would make sure to list the two IP addresses marked as malicious on the network connections page, as well as the timestamps for those connections. As for the terminal history, note down the commands used, timestamps, and the IP used for exfiltration. Once on the host, point out whether I should be looking at Sysmon or security logs, along with the full timestamps. I did notice I input the GitHub page contacted on the case, but would put it in the notes as well. The biggest thing here is that I didn’t point out that the ninjacopy tool was used to dump the NTDS .dit file, and that the credentials dump was what was exfiltrated. This results in a true positive for the alert title “Unauthorized access to NTDS”.
Affected systems and users
Endpoint IP: 172.16.17.223
Malicious IP: 185.107.56.72
Hostname: Paul
Steps taken in the investigation
Checked Mitre and found the GitHub of the tool listed in the alert. The tool uses direct volume access for defense evasion. Checked endpoint security for network connections, and found 3 IP addresses, 2 being reported by 1 vendor as malicious in Virustotal. After checking the terminal history, I can confirm that exfiltration has occurred to one of these IP addresses.
On the endpoint, logs show that the Malicious IP logged on via RDP over the network at 12:17:28. The second IP marked by VirusTotal appears to be the GitHub where the tool was downloaded from. The Ntds file and the tool still exist in the machine's temp folder.
Actions taken
The system is contained.
References
https://attack.mitre.org/techniques/T1006/
https://www.virustotal.com/gui/ip-address/185.107.56.72/detection
https://www.abuseipdb.com/check/185.107.56.72
https://www.virustotal.com/gui/file/975803e4b80db0c3b3c8a1e8074da3f5a5c77c710cbf96de38caf9744dd76c9b
----------- (Artifacts below were separate from notes but input into case management)
Extracted Artifacts:
Type Value
Requested URL: hxxps[://]185[.]107[.]56[.]72[:]8000/upload
Requested URL: hxxps[://]raw.githubusercontent[.]com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-NinjaCopy[.]ps1
IP Address: 185.107.56[.]72
MD5 Hash: 7415795492e4d3afdd1bbdf3da6cbb9e
