Open cardosec

Case 78F466 · Malware & intel · L3 Applied

Unpacking the Office stager

Practise as: Incident drill · Interview

Live alertIR hands you the -enc blob from a WINWORD.EXE-spawned powershell.exe plus the macro doc, and asks: what does this payload do, and what are its IOCs?

Interview questionYou have an encoded PowerShell command from a malicious Office doc. How do you analyse it and what do you extract?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Base64 decodes to UTF-16LE text, often with more layers (gzip, XOR, string concat); peel statically in CyberChef, never run it
  2. Classify it: download cradle (WebClient/IWR + IEX), in-memory loader of .NET or shellcode, or an AMSI-tampering prefix
  3. Extract IOCs: C2 URLs and domains, user-agent, URI paths, drop paths and stage-2 hashes; fetch stage 2 only from isolated infra
  4. Fingerprint the framework: shellcode stubs and config traits can tie it to Cobalt Strike, Empire etc.; config parsers pull settings
  5. Cross-check with 4104 script blocks, AMSI and Sysmon 3/22 telemetry; turn findings into behavioral detections, not blob hashes

If the interviewer pushes back

  • The decoded script reflectively loads a .NET assembly. How do you recover and analyse it from memory?
  • Script Block Logging (4104) shows nothing for this execution. What does that tell you about the stager?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.