
FluBot: The Parcel-Delivery Text That Spreads Itself
A managed Android handset at Larkfield Mutual is infected by FluBot after the employee taps a smishing SMS impersonating a DHL parcel-delivery notice. The fake tracking page talks the user into installing an app and granting it Accessibility and SMS permissions; from there the trojan turns the phone into a sender, harvesting the contact list, texting the same lure onward and intercepting bank 2FA codes, while keeping a command channel the perimeter firewall never blocked. Walk the mobile telemetry and firewall logs step by step to trace the lure, the sideload, the contact theft, the SMS worm, and the hidden C2.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Brief: a parcel text that texts itself
0A managed company phone started sending text messages of its own this morning, after its owner tapped a parcel-delivery link. Before you dig into the logs, get oriented on how this kind of mobile malware works.
Find the link the victim tapped
15The whole infection began with one text message containing a web link disguised as a parcel-tracking page. Find the domain that link pointed to.
Name the app that was sideloaded
15Tapping the link led to an app download from outside the managed store. Identify the exact filename of the package that landed on the phone.
Spot where the stolen contacts went
15Once installed, the trojan read the entire contact list and reached out to its command server to send them off. Identify the command-and-control domain it contacted.
Measure how far it tried to spread
10FluBot's signature behavior is turning a victim into a sender. The handset began blasting the same lure to its own contacts. Determine how many messages it sent in that burst.
Label how the C2 stayed hidden
10The firewall never blocked the command-and-control traffic because of how the trojan disguised it. Map that evasion technique to MITRE ATT&CK.
6 tasks · 65 points total
Training Tools
Skills You'll Build
Ideal for newcomers to SOC operations. Guided investigation with clear indicators.
Prerequisites
- No prior experience required
- Familiarity with SIEM concepts
- Familiarity with Firewall concepts
Ready to investigate?
More Operations
View allThe Template That Read the Disk
The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.
Exposed .git Folder: Scanning the Web for Secrets
A public web server at Larkspur Logistics was deployed straight from a git checkout, leaving its .git directory exposed to the Internet. Following the EMERALDWHALE playbook, an attacker pulled /.git/config, stole the GitHub token baked into the clone URL, cloned the private repository, and found a hard-coded AWS key inside that handed them the cloud account. Walk the access, GitHub, and CloudTrail logs step by step to trace one misconfiguration into a full credential-theft chain.
OneNote Attachment to RAT: A Guided First Investigation
A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.