Skip to main content
QakBot bb02: Trace the Loader DLL to its C2 operation cover
BeginnerSIEMFirewallXDR

QakBot bb02: Trace the Loader DLL to its C2

A purchasing coordinator opened a phishing email, downloaded a password-protected archive, and ran a shortcut on the disk image hidden inside it. A signed Windows utility quietly registered a QakBot DLL, and the workstation started beaconing to addresses nobody recognized. Trace the bb02 wave from a phishing link through an ISO and the loader DLL handoff to the single TLS command-and-control endpoint the bot settled on.

30m
6 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Triage the morning alert

0

A purchasing workstation at Haldren Fabrication tripped the SIEM this morning: an Office-adjacent process spawning a system utility, followed by encrypted traffic to addresses nobody recognizes. Before you pull threads, get oriented. This case starts in a mailbox and ends on the perimeter, and the analyst who caught it has handed it to you. Review the available surfaces and the incident window, then begin working the delivery.

2

Trace the delivery

15

The trail begins with one inbound message that slipped past sender authentication and pointed the recipient at a password-protected archive, with the password helpfully included so no scanner could open it. Establish who sent it.

SOC{name@domain.tld}Hint available
3

Catch the execution handoff

15

Downloading the archive and mounting what was inside it did not just open a document. A shortcut on the mounted drive launched a trusted Windows utility that has no business running a payload from a user profile. Identify the system binary the shortcut chain used to register and run the hidden DLL.

SOC{name.exe}Hint available
4

Recover the payload

15

The registration utility did not carry the malicious code in plain sight. It registered and executed a module that had been written to the user profile with a deliberately misleading extension. Recover the file name of that payload.

SOC{filename.ext}Hint available
5

Pin the C2 beacon

20

Once the payload ran, it tried a string of external addresses over encrypted web traffic, most of which refused it, before locking onto one and staying there. To contain the host you need the address it settled on. Identify the primary command-and-control endpoint, as an address and port.

SOC{a.b.c.d:port}Hint available
6

Classify the execution proxy

15

For the incident report, classify how the attacker ran the payload through a trusted, signed Windows binary instead of executing it directly. Map that evasive behavior to its MITRE ATT&CK technique.

SOC{Txxxx.xxx}Hint available

6 tasks · 80 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
SIEM log analysis
Firewall log analysis
XDR log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with SIEM concepts
  • Familiarity with Firewall concepts
  • Familiarity with XDR concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts