// soc investigation 2026-06-19
SOC319 Suspicious DLL Execution Detected
letsdefend Medium ✓ true positive
mitre/T1566-001mitre/T1574-002mitre/T1218-011mitre/T1036-008mitre/T1105mitre/T1204-002
analyst verdict TRUE POSITIVE
✓

🟧 What

A multi-stage malware infection was identified on host Ross, initiated via a phishing email delivering a malicious ISO file. The ISO contained a weaponized Word document that triggered a curl download of a second-stage payload disguised as a PNG. The payload was executed via rundll32.exe, leveraging a non-standard file extension to evade detection.

🕒 When

TimeEvent
09:11 AMPhishing email received from support@mail[.]westcapitalreserve[.]com
~09:1X AMZIP attachment extracted, malicious ISO mounted
~09:1X AMWINWORD.EXE opens document.rtf from mounted ISO
~09:1X AMcmd.exe runs curl.exe → downloads stage 2 payload to c:\wnd\3291.png
10:17 AMrundll32.exe executes 3291.png via GetModuleProp export

📍 Where

👤 Who

❓ Why

The phishing email used a business-themed pretext (“Important Documentation”) to deliver a ZIP containing a malicious ISO. Mounting an ISO bypasses Mark-of-the-Web (MOTW) protections normally applied to email/ZIP-extracted files, allowing the embedded RTF to execute without standard security prompts. The document triggered a curl download of a second-stage payload saved with a .png extension — a masquerading technique to evade extension-based detection. This payload was a DLL executed via rundll32.exe using the non-standard export GetModuleProp, a classic LOLBin proxy-execution technique. EDR/AV did not flag the activity at any stage, indicating successful evasion through to final payload execution.

🗺️ MITRE ATT&CK

TacticTechnique IDTechnique Name
Initial AccessT1566.001Spearphishing Attachment
Defense EvasionT1574Hijack Execution Flow
Defense EvasionT1218.011System Binary Proxy Execution: Rundll32
Defense EvasionT1036.008Masquerade File Type
Command and ControlT1105Ingress Tool Transfer
ExecutionT1204.002User Execution: Malicious File

🧬 IOCs

TypeValue
Sender Emailsupport@mail[.]westcapitalreserve[.]com
URLhxxps[://]yourunitedlaws[.]com/mrD/4462
Filenameperspiciatism[.]zip
Filenamedocument[.]rtf
Filename3291[.]png
File Pathc:\wnd\3291.png
IP Address172[.]16[.]17[.]122

✅ Verdict / Disposition

True Positive — confirmed multi-stage malware infection (phishing → ISO → malicious document → LOLBin-proxied second-stage execution). Host contained, phishing email deleted from mailbox.

🔗 Analysis Reports

https://bazaar.abuse.ch/sample/c2071407cf960fa166ac47d86f4a92b64873cd8c37a4ea416e80488c5f327c8f/

https://www.virustotal.com/gui/url/74bfeec8b2d532c2ce473b1a4e409d7d54e428c06e55b3fb9b73910a0a8d6366