WhatsApp ยท Quick response

๐ŸŒ Open to Remote SOC Roles  ยท  AU ยท CA ยท US ยท NZ ยท UAE

Hire Me
Home About SOC Projects Portfolio Services Academy Certifications CAI Initiative BlogContact โ†’
โ† All Projects CRITICAL โ— CONTAINED
Case Study #003 โ€” NexSecure Bootcamp Project 2

USB Malware Infection & RAT Detection

Analyst: O.T. Nathaniel, AMICDFA, CBTP
Incident ID: INC-2026-0414-002
Organisation: TechNova Solutions (Simulated)
MITRE: T1091 ยท T1059.001 ยท T1547.001 ยท T1071

๐Ÿ“‹ Scenario

On April 14, 2026 at 11:42 AM, a TechNova Solutions employee inserted an unvetted USB drive into a corporate workstation. Within seconds the SOC detected: powershell.exe launching with encoded commands, outbound C2 connections, and persistent RAT installation via scheduled task.

๐Ÿงฐ Tools Used

EDR / SIEMSysmonWireshark Magnet RAM CaptureVolatilityVirusTotal Windows Event LogsAny.run Sandbox

๐Ÿ”ฌ Investigation Process

01

Alert Triage (L1) โ€” 11:43 AM

EDR alert: "Suspicious Process โ€” powershell.exe + C2 Outbound." Confirmed powershell.exe spawned by explorer.exe (unusual parent chain). C2 connection to 91.108.4.33:4444 (Telegram infrastructure) confirmed. USB insertion logged at 11:42 AM via Event ID 2003. TRUE POSITIVE โ€” escalated to L2.

02

Host Isolation (L2) โ€” 11:50 AM

TECHNOVA-WKS-047 isolated via EDR console. Memory dump acquired with Magnet RAM Capture before remediation.

03

Malware Analysis

Static/dynamic analysis of svchost32.exe: AsyncRAT variant with keylogger, screenshot, file exfiltration, reverse shell. Payload decoded from base64 PowerShell command.

04

Persistence Removal

Registry key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\SystemHost. Scheduled task removed. C2 IP blocked at firewall.

05

Threat Hunt

Searched all endpoints for svchost32.exe, file hash, registry key, C2 IP โ€” no lateral movement confirmed. WKS-047 reimaged from gold image.

๐Ÿšจ IOCs

C2 IP
91.108.4.33:4444
Malicious File
C:\Users\Public\svchost32.exe
Registry
HKCU\...\Run\SystemHost
Scheduled Task
\Windows\SystemMaintenance\HostUpdate
PowerShell
-EncodedCommand -WindowStyle Hidden
USB AutoRun
autorun.inf OPEN=malware.exe

โœ… Conclusion

Detection: Under 60 seconds from USB insertion to SIEM alert. Infection contained to single workstation. No lateral movement. Root cause: uncontrolled USB access โ€” a preventable policy failure.