Skip to main content
QakBot bb02: Trace the Loader DLL to its C2 operation cover
BeginnerSIEMFirewallXDR

QakBot bb02: Trace the Loader DLL to its C2

A purchasing coordinator opened a phishing email, downloaded a password-protected archive, and ran a shortcut on the disk image hidden inside it. A signed Windows utility quietly registered a QakBot DLL, and the workstation started beaconing to addresses nobody recognized. Trace the bb02 wave from a phishing link through an ISO and the loader DLL handoff to the single TLS command-and-control endpoint the bot settled on.

30m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Triage the morning alert

0

A purchasing workstation at Haldren Fabrication tripped the SIEM this morning: an Office-adjacent process spawning a system utility, followed by encrypted traffic to addresses nobody recognizes. Before you pull threads, get oriented. This case starts in a mailbox and ends on the perimeter, and the analyst who caught it has handed it to you. Review the available surfaces and the incident window, then begin working the delivery.

2

Trace the delivery

15

The trail begins with one inbound message that slipped past sender authentication and pointed the recipient at a password-protected archive, with the password helpfully included so no scanner could open it. Establish who sent it.

SOC{name@domain.tld}Hint available
3

Catch the execution handoff

15

Downloading the archive and mounting what was inside it did not just open a document. A shortcut on the mounted drive launched a trusted Windows utility that has no business running a payload from a user profile. Identify the system binary the shortcut chain used to register and run the hidden DLL.

SOC{name.exe}Hint available
4

Recover the payload

15

The registration utility did not carry the malicious code in plain sight. It registered and executed a module that had been written to the user profile with a deliberately misleading extension. Recover the file name of that payload.

SOC{filename.ext}Hint available
5

Pin the C2 beacon

20

Once the payload ran, it tried a string of external addresses over encrypted web traffic, most of which refused it, before locking onto one and staying there. To contain the host you need the address it settled on. Identify the primary command-and-control endpoint, as an address and port.

SOC{a.b.c.d:port}Hint available
6

Classify the execution proxy

15

For the incident report, classify how the attacker ran the payload through a trusted, signed Windows binary instead of executing it directly. Map that evasive behavior to its MITRE ATT&CK technique.

SOC{Txxxx.xxx}Hint available

6 tasks · 80 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
Firewall log analysis
XDR log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with SIEM concepts
  • Familiarity with Firewall concepts
  • Familiarity with XDR concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMEmail

Bumblebee Returns: The Voicemail VBA Macro

An accounts-payable clerk opened a voicemail-notification email, followed a OneDrive link, and a Word macro quietly pulled a loader onto the host. Follow the chain from a sender-spoofed phishing message through a VBA macro, PowerShell, and signed-binary proxy execution to the Bumblebee loader's TLS command-and-control.

30m25 pts
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerSIEMFirewall

FluBot: The Parcel-Delivery Text That Spreads Itself

A managed Android handset at Larkfield Mutual is infected by FluBot after the employee taps a smishing SMS impersonating a DHL parcel-delivery notice. The fake tracking page talks the user into installing an app and granting it Accessibility and SMS permissions; from there the trojan turns the phone into a sender, harvesting the contact list, texting the same lure onward and intercepting bank 2FA codes, while keeping a command channel the perimeter firewall never blocked. Walk the mobile telemetry and firewall logs step by step to trace the lure, the sideload, the contact theft, the SMS worm, and the hidden C2.

15m25 pts