| Field | Value |
|---|---|
| Event ID | 278 |
| Date | Jul 17, 2024 12:18 PM |
| Rule | SOC302 - Suspicious Base64 Encoding/Decoding Commands Detected |
| Severity | High |
| Hostname | Wilburn |
| Internal IP | 172[.]16[.]17[.]74 |
| Category | Unauthorized Access / Credential Access |
| Technique ID | Tactic | Technique |
|---|---|---|
| T1110.001 | Credential Access | Brute Force - Password Guessing |
| T1078 | Defense Evasion / Initial Access | Valid Accounts |
| T1059.006 | Execution | Command and Scripting Interpreter - Python |
| T1027 | Defense Evasion | Obfuscated Files or Information |
| T1083 | Discovery | File and Directory Discovery |
| T1087 | Discovery | Account Discovery |
| T1552.001 | Credential Access | Unsecured Credentials - Credentials In Files |
analyst from 143[.]244[.]44[.]163 following brute force attempts across multiple usernames (letsdefend, fener, analyst)whoami, groups, hostname, uname -a, cat /etc/os-release, getent passwd, cat /etc/groupfind / -type f -name *password* and find / -type f -name *important*important file; confirmed contents with cat important/root/Documents/important → /root/Documents/decoded_file[.]txtdecoded_file[.]txt; output was a plaintext credential list containing 10 IP/username/password pairs| Type | Value | Notes |
|---|---|---|
| IP | 143[.]244[.]44[.]163 | Attacker source; VPN; flagged malicious VT + AbuseIPDB |
| Username | analyst | Compromised account used for initial access |
| File | /root/Documents/important | Base64-encoded credential store |
| File | /root/Documents/decoded_file[.]txt | Decoded plaintext credentials |
| Command | python3 -c ‘import base64; …’ | Used to decode credential file in-place |
🔬 VirusTotal — 143.244.44.163 | 🦠 AbuseIPDB — 143.244.44.163
True Positive — Active Intrusion / Credential Access
Attacker successfully brute-forced SSH access to the analyst account on Wilburn (172[.]16[.]17[.]74) from a known-malicious VPN IP. Post-login activity followed a clear intrusion pattern: host enumeration, targeted file hunting, and Base64 decoding of a credential store yielding 10 plaintext credential sets. The decoded credentials represent a significant lateral movement and downstream compromise risk.
Recommended Actions: Isolate host, disable analyst account, rotate all credentials recovered from decoded_file.txt, and block 143[.]244[.]44[.]163 at perimeter.