// soc investigation 2026-11-07
SOC300 Right-to-Left Override Detected
letsdefend Medium ✓ true positive
mitre/T1036-002mitre/T1204-002
analyst verdict TRUE POSITIVE
✓

SOC300 - Right-to-Left Override Detected

Host: Alonso | IP: 172[.]16[.]17[.]243 | User: LetsDefend
Event Time: Jul 11, 2024, 12:14 PM | Device Action: Allowed


Investigation Summary

User downloaded a malicious ZIP archive via Chrome from an attacker-controlled AWS S3 URL. The archive contained a PE binary with a Unicode Right-to-Left Override character (U+202E) injected into the filename, causing it to render as a .txt file while the OS executed it as a .exe. The user executed the file via Explorer. VirusTotal confirmed the sample as Lumma Stealer. Manual inspection on the endpoint revealed an MZ header confirming the PE binary. Active process execution was confirmed and the endpoint has been contained.


Timeline

Time (UTC)Event
2024-07-11 12:13:16Malicious ZIP downloaded via chrome.exe from AWS S3
2024-07-11 12:14:00Alert triggered — RTLO character detected in process name
2024-07-11 12:14:23Process confirmed running (PID 8004), parent explorer.exe

Process Details

FieldValue
Process2024-report[U+202E]txt.exe (renders as 2024-reporttxt.exe)
PathC:\Users\LetsDefend\Downloads\2024-report[RTLO]txt.exe
Command LineC:\Windows\Boot\PCAT\memtest.exe
PID8004
Parentexplorer.exe
UserEC2AMAZ-ILGVOIN\LetsDefend
SHA2560914e92d15507742da4feef71b1b21230138b450e334855cd980f46b394c4f71

Indicators of Compromise

TypeIndicator
URLhxxps://files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/2024-annualreport[.]zip
File2024-report[RTLO]txt.exe
Drop PathC:\Users\LetsDefend\Downloads\
Spawned BinaryC:\Windows\Boot\PCAT\memtest[.]exe
SHA2560914e92d15507742da4feef71b1b21230138b450e334855cd980f46b394c4f71
Host IP172[.]16[.]17[.]243

Malware Identification


MITRE ATT&CK

Technique IDTacticTechnique
T1036.002Defense EvasionMasquerading: Right-to-Left Override
T1204.002ExecutionUser Execution: Malicious File

Analysis Reports

🔍 VirusTotal
🔗 MITRE T1036.002


Scope

No additional hosts observed connecting to the AWS S3 source URL. Single point of infection confirmed. Endpoint isolated and contained.


Verdict: TRUE POSITIVE — MALICIOUS