// soc investigation 2026-06-15
SOC302 Suspicious Base64 Encoding/Decoding Commands Detected
letsdefend High ✓ true positive
mitre/T1110-001mitre/T1078mitre/T1059-006mitre/T1027mitre/T1083mitre/T1087mitre/T1552-001
analyst verdict TRUE POSITIVE
✓

Alert Metadata

FieldValue
Event ID278
DateJul 17, 2024 12:18 PM
RuleSOC302 - Suspicious Base64 Encoding/Decoding Commands Detected
SeverityHigh
HostnameWilburn
Internal IP172[.]16[.]17[.]74
CategoryUnauthorized Access / Credential Access

MITRE ATT&CK

Technique IDTacticTechnique
T1110.001Credential AccessBrute Force - Password Guessing
T1078Defense Evasion / Initial AccessValid Accounts
T1059.006ExecutionCommand and Scripting Interpreter - Python
T1027Defense EvasionObfuscated Files or Information
T1083DiscoveryFile and Directory Discovery
T1087DiscoveryAccount Discovery
T1552.001Credential AccessUnsecured Credentials - Credentials In Files

Timeline


IOCs

TypeValueNotes
IP143[.]244[.]44[.]163Attacker source; VPN; flagged malicious VT + AbuseIPDB
UsernameanalystCompromised account used for initial access
File/root/Documents/importantBase64-encoded credential store
File/root/Documents/decoded_file[.]txtDecoded plaintext credentials
Commandpython3 -c ‘import base64; …’Used to decode credential file in-place

Analysis Reports

🔬 VirusTotal — 143.244.44.163 | 🦠 AbuseIPDB — 143.244.44.163


Disposition

True Positive — Active Intrusion / Credential Access

Attacker successfully brute-forced SSH access to the analyst account on Wilburn (172[.]16[.]17[.]74) from a known-malicious VPN IP. Post-login activity followed a clear intrusion pattern: host enumeration, targeted file hunting, and Base64 decoding of a credential store yielding 10 plaintext credential sets. The decoded credentials represent a significant lateral movement and downstream compromise risk.

Recommended Actions: Isolate host, disable analyst account, rotate all credentials recovered from decoded_file.txt, and block 143[.]244[.]44[.]163 at perimeter.