ISSUE #005
Cover story
On a Friday morning, one of our MDR analysts caught a hidden PowerShell window quietly erasing its own tracks on an insurance company’s remote endpoint.
Analytics
EE. UU.
Insurance
LoTL
Contenido
On a Friday morning, one of our MDR analysts caught a hidden PowerShell window running on a remote endpoint at an insurance company. Something inside it was already being erased.
A trail gone cold
Inside the window sat an obfuscated PowerShell script. Once our analyst opened it up, its purpose became clear: it was closing everything out, deleting a file named n.vbs through a randomly named .msi installer, and removing other script files along the way. By the time our analyst went looking for what those files had actually done, they were already gone.
Too clean to be routine
Cleanup scripts like this aren’t unusual on their own. IT admins run them all the time: configure an endpoint, then clear out the files left behind. What didn’t fit was the name. Admin scripts don’t typically generate random file names, and they don’t typically delete the very evidence of what they just did.
The tool doing the connecting was ScreenConnect, a remote access platform IT teams lean on constantly, and one this particular customer didn’t use at all. A cleanup script with unfamiliar naming, running through a tool nobody on this account should have been touching, was enough to move from suspicious to something worth acting on immediately.
Isolate first, explain later
Rather than wait for more proof, our analyst seized the initiative and isolated the endpoint. There was no guarantee yet that this was a compromise, but waiting on certainty would have meant waiting on an attacker who was already working to cover their exit.
Our analyst:
- Identified the hidden PowerShell window and opened the obfuscated script running inside it.
- Traced the anti-forensics activity to a randomly named installer deleting its own tracks.
- Confirmed the endpoint did not typically run ScreenConnect.
- Isolated the endpoint as a precaution and escalated to the customer by email and phone.
What a quiet Friday could have cost
Had the activity gone unnoticed, the attacker could have used ScreenConnect to maintain persistence and moved laterally toward higher-value systems, like the main controller or a file server. Because this was a remote worker’s device connecting in through VPN, a compromised credential there could have opened a path into the wider infrastructure, including other endpoints on that same VPN. Policyholder records, claims data, and financial systems could potentially have been reached from there. Because MDR caught this early, though, the actual intent behind the intrusion, whether ransomware, data theft, or simple persistence, was never confirmed.
Because of MDR, that didn’t happen.
Reconstrucción
Desde la primera señal hasta el traspaso completo
A hidden window
A hidden PowerShell window appears on a remote endpoint, running an obfuscated script.
Underhand behavior
The script turns out to be a cleanup routine, deleting a file through a randomly named installer as it goes.
The wrong disguise
The naming pattern doesn’t look like a routine IT cleanup, and ScreenConnect doesn’t belong on this network.
Isolation then escalation
Our analyst seizes the initiative, isolates the endpoint, and escalates to the customer.
Customer confirms
The customer confirms it: this was an attempted compromise, stopped by our swift identification and isolation of the threat.