security portfolio + blog

by Nicholas Coleman

Download as .zip Download as .tar.gz View on GitHub
19 April 2025

Malicious Google Authenticator Report

by Nicholas Coleman

Malicious Ads on Bing Search Leads to Malware

You work as an analyst at a Security Operation Center (SOC). Someone contacts your team to report a coworker has downloaded a suspicious file after searching for Google Authenticator. The caller provides some information similar to social media posts at:

Based on the caller’s initial information, you confirm there was an infection.  You retrieve a packet capture (pcap) of the associated traffic.  Reviewing the traffic, you find several indicators matching details from a Github page referenced in the above social media posts.  After confirming an infection happened, you begin writing an incident report.

LAN Segment Details

Indicators of Compromise

Files

Hash Filename Type Suspicion
a833f27c... pas.ps1 PowerShell Likely a payload script
9634ecaf... Teamviewer_Resource_fr.dll DLL Abused DLL
904280f2... TeamViewer.exe EXE Possibly modified/packed remote access tool
3448da03... TV.dll DLL Possibly injected
fd045fce... skqllz.ps1 PowerShell Possibly secondary script

From Malicious Ad on Bing

Task

tags: tryhackme