JELAJAH SOC
YO

INC-1041 · owner S. Hartono

Phishing-led intrusion with credential dumping on WS-FIN-014

A macro-enabled invoice attachment delivered a PowerShell loader to a finance workstation. The loader established C2, dumped LSASS, and moved laterally to the SQL server via admin shares.

All incidents
criticalInvestigatingSLA 4h response · 2h 10m elapsedcollaborators: A. Pratama, You

Evidence panel

Pivotable entities

MITRE ATT&CK

T1566.001T1059.001T1003.001T1021.002

Attack timeline

Build the sequence of the intrusion

  1. 09:12

    Email received

    invoice_0824.docm delivered to a.pratama

  2. 09:15

    User opened attachment

    WINWORD.EXE macro execution enabled

  3. 09:17

    PowerShell loader

    powershell.exe -nop -w hidden -enc

  4. 09:18

    DNS query

    cdn-update-sync.net resolved

  5. 09:19

    C2 connection

    TLS session to 185.220.101.44:443

  6. 09:28

    Credential dumping

    rundll32 → lsass.exe handle 0x1410

  7. 09:35

    Lateral movement

    ADMIN$ write + service create on SRV-SQL-01

Linked alerts

Containment actions

  • WS-FIN-014 isolated at 09:41
  • C2 IP 185.220.101.44 blocked at perimeter
  • svc_backup credentials rotated

Recommendations

  • Block macro execution from internet-sourced documents via GPO
  • Enable LSASS protection (RunAsPPL) fleet-wide
  • Require MFA for all administrative SMB sessions

Case tasks

  • Acquire triage package from WS-FIN-014A. Pratama
  • Reset credentials for all users on the hostS. Hartono
  • Scope hash across the estateYou
  • Draft executive incident summaryS. Hartono

Investigation notes

    Audit trail

    • System · Incident created from ALT-2400 escalation1970-01-01 05:30:00Z
    • S. Hartono · Assigned ownership, severity set to Critical1970-01-01 05:42:00Z
    • A. Pratama · Attached memory acquisition evidence1970-01-01 06:20:00Z
    • You · Linked ALT-2407 (lateral movement)1970-01-01 07:24:00Z