INC-1041 · owner S. Hartono
Phishing-led intrusion with credential dumping on WS-FIN-014
A macro-enabled invoice attachment delivered a PowerShell loader to a finance workstation. The loader established C2, dumped LSASS, and moved laterally to the SQL server via admin shares.
criticalInvestigatingSLA 4h response · 2h 10m elapsedcollaborators: A. Pratama, You
Evidence panel
Pivotable entities
MITRE ATT&CK
T1566.001T1059.001T1003.001T1021.002
Attack timeline
Build the sequence of the intrusion
- 09:12
Email received
invoice_0824.docm delivered to a.pratama
- 09:15
User opened attachment
WINWORD.EXE macro execution enabled
- 09:17
PowerShell loader
powershell.exe -nop -w hidden -enc
- 09:18
DNS query
cdn-update-sync.net resolved
- 09:19
C2 connection
TLS session to 185.220.101.44:443
- 09:28
Credential dumping
rundll32 → lsass.exe handle 0x1410
- 09:35
Lateral movement
ADMIN$ write + service create on SRV-SQL-01
Linked alerts
Containment actions
- WS-FIN-014 isolated at 09:41
- C2 IP 185.220.101.44 blocked at perimeter
- svc_backup credentials rotated
Recommendations
- Block macro execution from internet-sourced documents via GPO
- Enable LSASS protection (RunAsPPL) fleet-wide
- Require MFA for all administrative SMB sessions
Case tasks
- Acquire triage package from WS-FIN-014A. Pratama
- Reset credentials for all users on the hostS. Hartono
- Scope hash across the estateYou
- Draft executive incident summaryS. Hartono
Investigation notes
Audit trail
- System · Incident created from ALT-2400 escalation1970-01-01 05:30:00Z
- S. Hartono · Assigned ownership, severity set to Critical1970-01-01 05:42:00Z
- A. Pratama · Attached memory acquisition evidence1970-01-01 06:20:00Z
- You · Linked ALT-2407 (lateral movement)1970-01-01 07:24:00Z