Next-Gen SIEM|Incidents
Tactic & technique Command and Control
Status
New
TP BT KN
Investigate with Charlotte AI

Investigate with Charlotte AI

Get suggestions for additional graph entities and a summary of the incident. Depending on size of graph, analyzing can take several minutes.

Charlotte AI is working

Charlotte AI is analyzing the threat graph.

0 events analyzed
Started: 18:45:12

Summary

Charlotte AI
Jan. 25, 2024 18:47:08

On 2024-01-15 00:28:41, the user llovegood on host XDR-STH-WIN10-2 launched Microsoft Edge from explorer.exe. Over the next hour, llovegood executed several suspicious files leading to multiple detections for User Execution. At 00:39:43, WinRAR.exe launched from powershell.exe and wrote the EICAR test file, triggering a detection for User Execution. Additional EICAR test file writes were detected from the same powershell.exe parent process, indicating likely malicious activity.

At 03:13:25 on 2024-01-15, user rhagrid-admin on host XDR-STH-DC01 launched Google Chrome from explorer.exe. Over the next few minutes, multiple suspicious processes were launched by explorer.exe including cmd.exe and SecurityHealthSystray.exe. At 03:16:01 EICAR test file writes were detected from these processes, triggering detections for User Execution.

Back on XDR-STH-WIN10-2, at 03:17:21 user llovegood launched WinRAR.exe to access a remote eicar_com.zip file, triggering another User Execution detection.

At 03:19:45 on XDR-STH-DC01, rhagrid-admin launched logoff.exe, likely to evade detection.

On 2024-01-17 07:14:47, llovegood on XDR-STH-WIN10-2 opened a cmd.exe shell beneath explorer.exe. The cmd.exe process executed several suspicious commands including writing EICAR test files to disk, triggering multiple Command and Scripting Interpreter detections.

A Remote Services lateral movement was detected on 2024-01-17 18:18:49 with an RDP connection from XDR-STH-WIN10-3 to XDR-STH-WIN10-1, authenticated as ddursley@morialabs.com. Credential Dumping activity followed at 18:22:04, with CredDumpTool.exe accessing LSASS memory on the destination host.

Suggested entities (4)

Timeline
Added