DFIR Phishing Investigation — The Boogeyman Malware Case Study
CompletedFull DFIR investigation of a phishing-based malware compromise targeting an HR employee at Quick Logistics LLC. Reconstructed the attack chain from a malicious Word doc with VBA macros to C2 communication and persistence.
Investigation focus
Analysed a malicious Microsoft Word attachment containing VBA macros that downloaded and executed additional malware payloads on the victim workstation. Used memory forensics and malware analysis to reconstruct process execution, command-and-control (C2) communication, persistence mechanisms, and indicators of compromise (IOCs).
Areas covered
- Phishing email analysis
- VBA macro analysis
- Memory forensics
- Process and network analysis
- Persistence investigation
- IOC extraction
- Threat hunting methodologies
- Incident response documentation
Technologies & tools
- Volatility 3
- Olevba
- Linux CLI
- Memory Forensics
- Malware Analysis