// soc investigation 2026-04-05
SOC302 Suspicious Base64 Encoding/Decoding Commands Detected
letsdefend Medium ✓ true positive
mitre/T1110-001mitre/T1078mitre/T1033mitre/T1027mitre/T1458-003mitre/T1048-003data-exfil
analyst verdict TRUE POSITIVE
✓

🔍 What

An attacker from 89.187.185.184 brute-forced SSH on host Clark (172.16.20.43), successfully authenticated as the analyst user after multiple failed attempts, and escalated privileges to root via sudo su. Following privilege escalation, the attacker ran user enumeration (getent passwd), base64-encoded the /etc/passwd file into /root/Documents/encoded.dat, and attempted to exfiltrate it via a curl POST to an external domain. No outbound firewall log was found to confirm whether the transfer succeeded, but the staged file was confirmed to contain /etc/passwd content.


🕐 When


📍 Where


👤 Who

External attacker operating from 89.187.185.184, flagged on AbuseIPDB for repeated brute-force activity. The compromised account was analyst, which held sudo privileges. The attacker leveraged this to escalate to root.


❓ Why

The attacker brute-forced SSH access, used the analyst account’s sudo rights to reach root, encoded /etc/passwd to obfuscate exfiltrated content, and attempted to POST the file to an external server hosted on a .ru domain. The goal was likely credential harvesting — /etc/passwd exposes which accounts exist and have shell access, enabling follow-on attacks or lateral movement.


🎯 MITRE ATT&CK

IDTacticTechnique
T1110.001Credential AccessBrute Force - Password Guessing
T1078Defense Evasion / Initial AccessValid Accounts
T1033DiscoverySystem Owner/User Discovery
T1027Defense EvasionObfuscated Files or Information
T1548.003Privilege EscalationAbuse Elevation Control Mechanism - Sudo and Sudo Caching
T1048.003ExfiltrationExfiltration Over Unencrypted Non-C2 Protocol

📋 IOCs

TypeValueContext
IP89.187.185.184Attacker source IP — brute force, AbuseIPDB flagged
Domainukr-net-files-loading-application.ruExfil destination domain
URLhttp://ukr-net-files-loading-application.ru/uploadCurl POST exfil target
File/root/Documents/encoded.datBase64-encoded /etc/passwd staged for exfiltration
Commandgetent passwdUser enumeration recon post-compromise

🔬 Analysis Reports IPAbuseDB https://www.abuseipdb.com/check/89.187.185.184?page=5 🦠 VirusTotal https://www.virustotal.com/gui/url/c78d42195e5a114d333d70812fc29d36425921fbb27d794b20327fb9fcfff08b/details