A multi-stage malware infection was identified on host Ross, initiated via a phishing email delivering a malicious ISO file. The ISO contained a weaponized Word document that triggered a curl download of a second-stage payload disguised as a PNG. The payload was executed via rundll32.exe, leveraging a non-standard file extension to evade detection.
| Time | Event |
|---|---|
| 09:11 AM | Phishing email received from support@mail[.]westcapitalreserve[.]com |
| ~09:1X AM | ZIP attachment extracted, malicious ISO mounted |
| ~09:1X AM | WINWORD.EXE opens document.rtf from mounted ISO |
| ~09:1X AM | cmd.exe runs curl.exe → downloads stage 2 payload to c:\wnd\3291.png |
| 10:17 AM | rundll32.exe executes 3291.png via GetModuleProp export |
172.16.17.122C:\Users\LetsDefend\Downloads\perspiciatism\PERSPICIATISM\c:\wnd\3291.pngross@letsdefend[.]iosupport@mail[.]westcapitalreserve[.]comThe phishing email used a business-themed pretext (“Important Documentation”) to deliver a ZIP containing a malicious ISO. Mounting an ISO bypasses Mark-of-the-Web (MOTW) protections normally applied to email/ZIP-extracted files, allowing the embedded RTF to execute without standard security prompts. The document triggered a curl download of a second-stage payload saved with a .png extension — a masquerading technique to evade extension-based detection. This payload was a DLL executed via rundll32.exe using the non-standard export GetModuleProp, a classic LOLBin proxy-execution technique. EDR/AV did not flag the activity at any stage, indicating successful evasion through to final payload execution.
| Tactic | Technique ID | Technique Name |
|---|---|---|
| Initial Access | T1566.001 | Spearphishing Attachment |
| Defense Evasion | T1574 | Hijack Execution Flow |
| Defense Evasion | T1218.011 | System Binary Proxy Execution: Rundll32 |
| Defense Evasion | T1036.008 | Masquerade File Type |
| Command and Control | T1105 | Ingress Tool Transfer |
| Execution | T1204.002 | User Execution: Malicious File |
| Type | Value |
|---|---|
| Sender Email | support@mail[.]westcapitalreserve[.]com |
| URL | hxxps[://]yourunitedlaws[.]com/mrD/4462 |
| Filename | perspiciatism[.]zip |
| Filename | document[.]rtf |
| Filename | 3291[.]png |
| File Path | c:\wnd\3291.png |
| IP Address | 172[.]16[.]17[.]122 |
True Positive — confirmed multi-stage malware infection (phishing → ISO → malicious document → LOLBin-proxied second-stage execution). Host contained, phishing email deleted from mailbox.
https://bazaar.abuse.ch/sample/c2071407cf960fa166ac47d86f4a92b64873cd8c37a4ea416e80488c5f327c8f/
https://www.virustotal.com/gui/url/74bfeec8b2d532c2ce473b1a4e409d7d54e428c06e55b3fb9b73910a0a8d6366