Boss of the SOC v1 dataset (botsv1-attack-only.tgz) · reconstructed from live Splunk queries against index=botsv1
Automated scan of imreallynotbatman.com
Source IP 40.80.148.42 generated 1,928 of the 10,010 HTTP-stream requests seen against the site, using a Chrome-spoofed user agent. 17,469 events from this IP contain the string "acunetix," and 19,751 events reference "joomla." The site is a Joomla install being scanned with the Acunetix web vulnerability scanner.
Malicious file upload via Joomla com_extplorer
Same source IP POSTs a multipart upload to /joomla/administrator/index.php?option=com_extplorer (the Joomla file-manager component) containing 3791.exe (raw MZ/PE header visible in the capture) and a PHP web shell, agent.php. Server response: "Upload successful."
In-memory payload staged on we8105desk
On workstation we8105desk.waynecorpinc.local (user WAYNECORPINC\bob.smith), Sysmon logs csc.exe (the C# compiler) spawning cvtres.exe, compiling code staged into %TEMP%, a living-off-the-land technique typical of a VBScript/macro dropper avoiding disk-based AV signatures. This appears to be a separate spear-phishing intrusion chain, two weeks after the web-app compromise.
Cerber ransomware C2 burst
FortiGate UTM fires 9,231 "Botnet: Cerber.Botnet" IPS signature alerts in the same second, all sourced from 192.168.250.100 (we8105desk) and sprayed across the entire 85.93.63.0/24 block. This is Cerber's known technique of contacting a wide range of decoy IPs to defeat static blocklisting of its ransom-payment C2.
Encryption reaches shared network storage
152 SMB sessions from we8105desk (192.168.250.100) to a file server at 192.168.250.20 contain ransom-note/encryption-related keywords. The ransomware reached a mapped network drive, not just the local workstation.
md5/file_hash field was populated on the 3791.exe upload event. Splunk Stream wasn't configured to compute file hashes, so the executable's hash could not be pulled from network data alone in this environment.iis and stream:http for the actual defaced homepage/image (keywords "batman", "poison"): zero hits. The 135MB attack-only package appears to have trimmed that artifact out; it would need the full 6.1GB dataset.CommandLine/Image fields) since the official Microsoft-Sysmon Splunk add-on wasn't installed. Usable, but required reading full event bodies instead of clean field tables.