// soc investigation 2026-04-29
SOC321 Windows Defender Evasion Attempt
letsdefend High ✓ true positive
mitre/T1110-001mitre/T1078mitre/T1059-003mitre/T1218-011mitre/T1027mitre/T1082mitre/T1049mitre/T1069lolbin
analyst verdict TRUE POSITIVE
✓

I agg### 🎯 MITRE ATT&CK

IDTacticTechnique
T1110.001Initial AccessBrute Force: Password Guessing
T1078Initial AccessValid Accounts
T1059.001ExecutionCommand and Scripting Interpreter: PowerShell
T1059.003ExecutionCommand and Scripting Interpreter: Windows Command Shell
T1218.011Defense EvasionSystem Binary Proxy Execution: Rundll32
T1027Defense EvasionObfuscated Files or Information
T1082DiscoverySystem Information Discovery
T1049DiscoverySystem Network Connections Discovery
T1069DiscoveryPermission Groups Discovery

🔎 What

Brute force from 89[.]187[.]177[.]73 (confirmed malicious via AbuseIPDB) succeeded at 07:07 AM with logon event 4624 on account LetsDefend. Attacker conducted hands-on-keyboard recon via cmd spawned from explorer[.]exe including whoami, net user, net share, and PowerShell queries for running services, Defender status, and firewall profile. Attacker ran two LOLBin PoC commands via rundll32 abusing vbscript and mshtml traversal to spawn calc[.]exe. Second variant used LoL45 junk path obfuscation to bypass AV signature matching. First variant caught by AV. No external IPs contacted, no additional payloads executed. Verdict: True Positive - Contained. Machine contained.

🕐 When

Sep 12, 2024 - 07:09 AM

📍 Where

Host Elenora at 172[.]16[.]17[.]126. Brute force from 89[.]187[.]177[.]73. Successful logon at 07:07 AM. Commands executed via cmd and PowerShell spawned from explorer[.]exe.

👤 Who

External threat actor from 89[.]187[.]177[.]73. Gained access via brute force against LetsDefend account. Activity consistent with manual recon and Defender evasion testing - no payload deployment observed.

💡 Why

Attacker enumerated users, network, shares, and security tooling post-access. Rundll32 LOLBin PoC suggests probing Defender detection thresholds. LoL45 obfuscation indicates awareness of known AV signatures for standard mshtml traversal.

📌 IOCs

TypeValueDescription
IP89[.]187[.]177[.]73Attacker IP - brute force source, confirmed malicious AbuseIPDB
IP172[.]16[.]17[.]126Host Elenora - compromised endpoint
AccountLetsDefendBrute forced account
ProcessRUNDLL32[.]EXELOLBin used for Defender evasion PoC

🔬 Analysis Reports

🔗 AbuseIPDB (89[.]187[.]177[.]73) → https://www.abuseipdb.com/check/89.187.177.73?page=5 🔗 LOLBAS - Mshtml → https://lolbas-project.github.io/lolbas/Libraries/Mshtml/