{"id":1184,"date":"2026-07-07T19:34:47","date_gmt":"2026-07-07T19:34:47","guid":{"rendered":"https:\/\/victorcoil.tech\/?page_id=1184"},"modified":"2026-07-07T19:34:48","modified_gmt":"2026-07-07T19:34:48","slug":"analyst-note-sample-letsdefend-event-id-182","status":"publish","type":"page","link":"https:\/\/victorcoil.tech\/?page_id=1184","title":{"rendered":"Analyst Note Sample &#8211; LetsDefend Event ID 182"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Additional Info:<br>Date of investigation: Dec, 04, 2024, 10:27 PM<br>Alert title: Possible MalDoc in PDF was Detected<br>Time to investigate: 27 minutes<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Retrospective Note:<br>If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact query used to find the logs tied to the RAR file and include the timestamps for those actions. As well as the timestamp and URL of the site contacted. As well as noting down the paths where the malicious files were dropped.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Affected systems and users\n\nEndpoint Address IP:172.16.17.143\nHostname: Angela\nMalicious IP: 146&#91;.]70.45.83\n\nSteps taken in the investigation\nHash is reported as malicious by 37 vendors, according to VirusTotal. Internal threat intelligence marks the file as known malicious. Checked Anyrun, but all the reports there are labeled as non-malicious. I can see that the files had to be user-executed and that a second executable file is dropped; this executable checked for information on the system. Checked SIEM and confirmed that the .rar file was downloaded, unpacked, and executed. After execution, we can see a connection being made to a site. This site is marked as malicious by 15 vendors. \n\nArtifacts\nSupport AT impressiondigitals&#91;.]agency\n146&#91;.]70.45.83\ncba6bd373e42a7bcbc4c7251bc188b69\n179&#91;.]60.147.117\nhxxp&#91;:\/\/]web365metrics.&#91;]com\/\n\nActions taken\nContained the system. Deleted the files from the endpoint.\n\nReferences\nhttps:&#47;&#47;www.virustotal.com\/gui\/file\/098796e1b82c199ad226bff056b6310262b132f6d06930d3c254c57bdf548187\nhttps:\/\/app.any.run\/tasks\/6a9e9ea2-836d-49cf-8ea5-946eaddfeeae\nhttps:\/\/www.virustotal.com\/gui\/ip-address\/179.60.147.117\nhttps:\/\/www.abuseipdb.com\/check\/179.60.147.117\nhttps:\/\/www.virustotal.com\/gui\/url\/91f63156aca5cf7a80d131ba0e5cc288acf9001abc6c6d20d814c792f566b530\/detection\nhttps:\/\/www.virustotal.com\/gui\/ip-address\/146.70.45.83\nhttps:\/\/www.abuseipdb.com\/check\/146.70.45.83\nhttps:\/\/www.virustotal.com\/gui\/domain\/impressiondigitals.agency\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact query used to find the logs tied to the RAR file and include the timestamps for those actions. As well as the timestamp and URL of the site contacted. As well as noting down the paths where the malicious files were dropped.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"class_list":["post-1184","page","type-page","status-publish","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/victorcoil.tech\/?page_id=1184\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 182 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta property=\"og:description\" content=\"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/victorcoil.tech\/?page_id=1184\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-07-07T19:34:47+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-07T19:34:48+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Analyst Note Sample \u2013 LetsDefend Event ID 182 - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1184#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/victorcoil.tech\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1184#listItem\",\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 182\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1184#listItem\",\"position\":2,\"name\":\"Analyst Note Sample &#8211; LetsDefend Event ID 182\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1184#webpage\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1184\",\"name\":\"Analyst Note Sample \\u2013 LetsDefend Event ID 182 - Victor Coil | Security Operations & Detection Engineering\",\"description\":\"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1184#breadcrumblist\"},\"datePublished\":\"2026-07-07T19:34:47+00:00\",\"dateModified\":\"2026-07-07T19:34:48+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/\",\"name\":\"Victor Coil Portfolio\\\/Project Archive\",\"description\":\"Cybersecurity Projects\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Analyst Note Sample \u2013 LetsDefend Event ID 182 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact","canonical_url":"https:\/\/victorcoil.tech\/?page_id=1184","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/victorcoil.tech\/?page_id=1184#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","position":1,"name":"Home","item":"https:\/\/victorcoil.tech","nextItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1184#listItem","name":"Analyst Note Sample &#8211; LetsDefend Event ID 182"}},{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1184#listItem","position":2,"name":"Analyst Note Sample &#8211; LetsDefend Event ID 182","previousItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","name":"Home"}}]},{"@type":"WebPage","@id":"https:\/\/victorcoil.tech\/?page_id=1184#webpage","url":"https:\/\/victorcoil.tech\/?page_id=1184","name":"Analyst Note Sample \u2013 LetsDefend Event ID 182 - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/victorcoil.tech\/#website"},"breadcrumb":{"@id":"https:\/\/victorcoil.tech\/?page_id=1184#breadcrumblist"},"datePublished":"2026-07-07T19:34:47+00:00","dateModified":"2026-07-07T19:34:48+00:00"},{"@type":"WebSite","@id":"https:\/\/victorcoil.tech\/#website","url":"https:\/\/victorcoil.tech\/","name":"Victor Coil Portfolio\/Project Archive","description":"Cybersecurity Projects","inLanguage":"en-US","publisher":{"@id":"https:\/\/victorcoil.tech\/#person"}}]},"og:locale":"en_US","og:site_name":"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects","og:type":"article","og:title":"Analyst Note Sample \u2013 LetsDefend Event ID 182 - Victor Coil | Security Operations &amp; Detection Engineering","og:description":"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact","og:url":"https:\/\/victorcoil.tech\/?page_id=1184","article:published_time":"2026-07-07T19:34:47+00:00","article:modified_time":"2026-07-07T19:34:48+00:00","twitter:card":"summary_large_image","twitter:title":"Analyst Note Sample \u2013 LetsDefend Event ID 182 - Victor Coil | Security Operations &amp; Detection Engineering","twitter:description":"Additional Info:Date of investigation: Dec, 04, 2024, 10:27 PMAlert title: Possible MalDoc in PDF was DetectedTime to investigate: 27 minutes Retrospective Note:If I were to revisit this today, I would add that I learned the file had to be user-executed and that the second executable was through the anyrun sandbox. I would add the exact"},"aioseo_meta_data":{"post_id":"1184","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-07-06 02:54:08","updated":"2026-07-07 20:10:37","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/victorcoil.tech\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAnalyst Note Sample \u2013 LetsDefend Event ID 182\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/victorcoil.tech"},{"label":"Analyst Note Sample &#8211; LetsDefend Event ID 182","link":"https:\/\/victorcoil.tech\/?page_id=1184"}],"_links":{"self":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1184"}],"version-history":[{"count":3,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1184\/revisions"}],"predecessor-version":[{"id":1203,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1184\/revisions\/1203"}],"wp:attachment":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}