JELAJAH SOC
YO

ALT-2400 · Sysmon

Encoded PowerShell spawned by Microsoft Word

WINWORD.EXE spawned powershell.exe with a base64 encoded command block moments after a macro-enabled attachment was opened. Behaviour matches a phishing-to-loader chain.

Back to queue
criticalEscalatedconfidence 61% · 1970-01-01 01:33:00Z · rule DET-0142 Office Child Process — Encoded CommandLinked to INC-1041

Detection summary

WINWORD.EXE spawned powershell.exe with a base64 encoded command block moments after a macro-enabled attachment was opened. Behaviour matches a phishing-to-loader chain.

Affected host
WS-FIN-014
Affected user
a.pratama
Source IP
10.20.14.61
Detection rule
DET-0142 Office Child Process — Encoded Command
Log source
Sysmon
Assignee
Unassigned

Recommended actions

  • Isolate the endpoint from the network
  • Collect the parent document and submit for detonation
  • Reset credentials for the affected user
  • Block the C2 IP at the perimeter firewall

Analyst decision

Triage checklist

  • 1. Confirm the detection logic matched genuine activity.
  • 2. Check user and asset context for expected behaviour.
  • 3. Pivot on host, user, IP and hash in the Log Explorer.
  • 4. Enrich IOCs with threat intelligence.
  • 5. Set a verdict and record your reasoning.