Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

Fake CAPTCHA to Infostealer: DFIR Malware Investigation Case Study

This repository presents a sanitized DFIR case study based on a malware investigation involving fake CAPTCHA social engineering, suspected Living-Off-the-Land behavior, obfuscated PowerShell execution, and follow-on infostealer delivery patterns.

The project highlights investigation methodology, evidence review, process chain analysis, IOC extraction, and defensive remediation without exposing sensitive internal data.

What this project covers

  • Fake CAPTCHA social engineering workflow
  • mshta.exe and PowerShell execution chain analysis
  • Obfuscated and deobfuscated script review
  • Suspected LOTL technique assessment
  • AMSI and event logging bypass indicators
  • IOC extraction and infrastructure review
  • Investigation conclusions and remediation steps

Safety and Privacy Note

This repository contains a sanitized portfolio version of a malware investigation case study. Sensitive identifiers, internal references, and operational details have been removed or generalized. The material is shared for educational and professional portfolio purposes only.

Files

  • PDF case study
  • IOC summary
  • Short executive summary

Key Findings

  • Suspicious fake CAPTCHA flow led to command execution behavior
  • mshta.exe and PowerShell were involved in the observed chain
  • Obfuscated scripting and repeated background execution suggested malicious intent
  • Indicators pointed to infostealer-style objectives
  • Investigation produced actionable IOCs and remediation outcomes

About

Sanitized DFIR case study of a fake CAPTCHA malware delivery chain involving mshta, obfuscated PowerShell, LOTL behavior, IOC analysis, and remediation actions.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors