Skip to content
Abdullah
securityletsdefendcase-study

SOC104 | Malware Detected

Platform: LetsDefend Date Investigated: December 01, 2020 Severity: High Verdict: True Positive ✅ Summary A malware detection fired on an endpoint on December 1, 2020 at 10:23 AM. The file hash came b

1 min read

Platform: LetsDefend Date Investigated: December 01, 2020 Severity: High Verdict: True Positive ✅

Summary

A malware detection fired on an endpoint on December 1, 2020 at 10:23 AM. The file hash came back confirmed malicious and the endpoint itself backed that up by connecting to a known malicious address immediately after execution. Both pieces of evidence pointing the same direction is what made this a clean True Positive.

Alert Details

Field Value
Event ID 36
Event Time Dec 01, 2020, 10:23 AM
Rule SOC104, Malware Detected
C2 Address http://92.63.8.47/

Note: File hash was not retrievable during this investigation. The C2 network activity and analyst note confirmation were used as the primary evidence chain.

Investigation Steps

1. Malware Analysis The file hash was confirmed malicious through analysis. While the specific hash value was not captured in the artifacts available for this writeup, the detection was verified as genuine rather than a false positive based on the file's signature and behavior.

2. C2 Check Checked network logs for outbound connections from the endpoint. Found the device reaching out to http://92.63.8.47/ after the malware was installed. The timing of that connection, right after execution, is what ties the network activity directly to this specific malware rather than unrelated background traffic. An endpoint connecting to a raw IP address over HTTP with no legitimate business reason is a strong indicator of C2 communication on its own, and the post-execution timing seals it.

The destination, 92.63.8.47, is a raw IP address rather than a domain. Malware authors sometimes use raw IPs instead of domains specifically to avoid domain-based blocklists and DNS-based detection, so that detail is worth noting as part of the threat profile.

3. Quarantine Check Verified whether the malware was quarantined or cleaned from the endpoint following detection.

Why This Matters

What makes this case solid is that two independent sources agree with each other. The hash check confirms the file itself is malicious by signature. The network log confirms the file actually executed and called out to external infrastructure. When both the static analysis and the dynamic behavior point the same direction, there is very little room for a false positive interpretation.

This maps to T1071, Application Layer Protocol, on the MITRE ATT&CK framework, since the malware used HTTP to communicate with its C2 infrastructure rather than a custom protocol, which is a common technique for blending in with normal web traffic.

Malware Installed on Endpoint
        ↓
File Hash Confirmed Malicious
        ↓
Endpoint Connects to 92.63.8.47 Post-Execution
        ↓
C2 Communication Confirmed
        ↓
True Positive, Containment Required

Playbook Answers

  • ✅ Check If Someone Requested the C2

  • ✅ Analyze Malware

  • ✅ Check if the Malware is Quarantined and Cleaned

Verdict and Closing Rationale

True Positive. The file hash was confirmed malicious and the endpoint connected to a known bad IP address immediately after execution. The post-execution timing of that outbound connection is what connects the network activity to this specific file rather than treating it as coincidental traffic. Closed as TP.

Takeaway for Future Cases

When you have both a malicious hash and a post-execution C2 callout, you do not need to pick one as your primary evidence, both together make the case much harder to dispute. The hash tells you what the file is. The network activity tells you what it did. That combination is cleaner than either one alone, especially in situations where you might be missing one of the two.

Originally published on Hashnode.