Case 78F466 · Malware & intel · L3 Applied
Unpacking the Office stager
Practise as: Incident drill · Interview
Live alertIR hands you the -enc blob from a WINWORD.EXE-spawned powershell.exe plus the macro doc, and asks: what does this payload do, and what are its IOCs?
Interview questionYou have an encoded PowerShell command from a malicious Office doc. How do you analyse it and what do you extract?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Base64 decodes to UTF-16LE text, often with more layers (gzip, XOR, string concat); peel statically in CyberChef, never run it
- Classify it: download cradle (WebClient/IWR + IEX), in-memory loader of .NET or shellcode, or an AMSI-tampering prefix
- Extract IOCs: C2 URLs and domains, user-agent, URI paths, drop paths and stage-2 hashes; fetch stage 2 only from isolated infra
- Fingerprint the framework: shellcode stubs and config traits can tie it to Cobalt Strike, Empire etc.; config parsers pull settings
- Cross-check with 4104 script blocks, AMSI and Sysmon 3/22 telemetry; turn findings into behavioral detections, not blob hashes
If the interviewer pushes back
- The decoded script reflectively loads a .NET assembly. How do you recover and analyse it from memory?
- Script Block Logging (4104) shows nothing for this execution. What does that tell you about the stager?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.