[ << ALL_FEED ]

Analysis of reports.db

More in General

☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described in the previous post.

This artifact is a database (reports.db) that stores information about application activity, including files and web resources that a given process interacted with.


{"application.description":"Windows PowerShell","application.directory":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0","application.name":"powershell.exe","eventId":154,"object.directory":"\\\\10.50.1.39\\E$\\Очень важные документы\\отчет.xlsx//","object.name":"encrypted","timestamp":"2024-05-06T15:44:15.305346Z","user.name":"COMPANY\\admin","user.type":1}

{"application.description":"Windows PowerShell","application.directory":"C:\\Windows\\System32\\WindowsPowerShell\\v1.0","application.name":"powershell.exe","eventId":154,"object.directory":"http://94.158.247.19/files/upload/4c3df659-4299-4f3d-a159-5cca5215f74f///WREQ//XFwxMC40MC4xMC4zNFxFJFzQntGH0LXQvdGMINCy0LDQttC90YvQtSDQtNC+0LrRg9C80LXQvdGC0Ytc0L7RgtGH0LXRgi54bHN4JiYyOC4wMi4yMDI0IDc6NDI6MTImJjM2NzQyJiZWTTAwMSYmYWRtaW4mJkRGNDUzNjI0//","object.name":"encrypted","timestamp":"2024-05-06T15:44:15.305346Z","user.name":"COMPANY\\admin","user.type":1}

The events above, obtained after parsing the database with one of our tools, indicate that the powershell.exe process accessed a document in a network folder and a web page.

🖥 The URL reflected in the object.directory field has the following format:


ip_address/files/upload/guid///WREQ//base64_id//

🧑‍💻 After decoding from Base64, we get the following string:


\\10.40.10.34\E$\Очень важные документы\отчет.xlsx&&28.02.2024 7:42:12&&36742&&VM001&&admin&&DF453624

The exfiltration request contains the file path, modification date, file size in bytes, host name, user name, and hard drive serial number, separated by double ampersands.

Thus, reports.db is an excellent source of data in which one can find:

• evidence of this script being used for exfiltration;
• a list of exfiltrated resources;
• the account under which the malicious activity was conducted.

#detect #dfir #PowerShell #win
@ptescalator

More from oUth0R

More from oUth0R

More in General