Host: Alonso | IP: 172[.]16[.]17[.]243 | User: LetsDefend
Event Time: Jul 11, 2024, 12:14 PM | Device Action: Allowed
User downloaded a malicious ZIP archive via Chrome from an attacker-controlled AWS S3 URL. The archive contained a PE binary with a Unicode Right-to-Left Override character (U+202E) injected into the filename, causing it to render as a .txt file while the OS executed it as a .exe. The user executed the file via Explorer. VirusTotal confirmed the sample as Lumma Stealer. Manual inspection on the endpoint revealed an MZ header confirming the PE binary. Active process execution was confirmed and the endpoint has been contained.
| Time (UTC) | Event |
|---|---|
| 2024-07-11 12:13:16 | Malicious ZIP downloaded via chrome.exe from AWS S3 |
| 2024-07-11 12:14:00 | Alert triggered — RTLO character detected in process name |
| 2024-07-11 12:14:23 | Process confirmed running (PID 8004), parent explorer.exe |
| Field | Value |
|---|---|
| Process | 2024-report[U+202E]txt.exe (renders as 2024-reporttxt.exe) |
| Path | C:\Users\LetsDefend\Downloads\2024-report[RTLO]txt.exe |
| Command Line | C:\Windows\Boot\PCAT\memtest.exe |
| PID | 8004 |
| Parent | explorer.exe |
| User | EC2AMAZ-ILGVOIN\LetsDefend |
| SHA256 | 0914e92d15507742da4feef71b1b21230138b450e334855cd980f46b394c4f71 |
| Type | Indicator |
|---|---|
| URL | hxxps://files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/2024-annualreport[.]zip |
| File | 2024-report[RTLO]txt.exe |
| Drop Path | C:\Users\LetsDefend\Downloads\ |
| Spawned Binary | C:\Windows\Boot\PCAT\memtest[.]exe |
| SHA256 | 0914e92d15507742da4feef71b1b21230138b450e334855cd980f46b394c4f71 |
| Host IP | 172[.]16[.]17[.]243 |
U+202E injected immediately before extension to reverse display rendering via Unicode bidirectional algorithm| Technique ID | Tactic | Technique |
|---|---|---|
| T1036.002 | Defense Evasion | Masquerading: Right-to-Left Override |
| T1204.002 | Execution | User Execution: Malicious File |
🔍 VirusTotal
🔗 MITRE T1036.002
No additional hosts observed connecting to the AWS S3 source URL. Single point of infection confirmed. Endpoint isolated and contained.
Verdict: TRUE POSITIVE — MALICIOUS