Part of a 2-lab Flash Hunt case on Threat Hunting Labs: NightShade C2 Multi-Stage Infection. This lab is the Malware Analysis angle (2 of 2) — moving from the host-and-network hunt in the first lab to the scripts and payload themselves.
Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.
Static and behavioural triage of the installer chain’s script artifacts: a VBScript stager launching a PowerShell dropper, which in turn stages an obfuscated JavaScript payload run under a legitimate portable JS runtime. The runner registers with its command-and-control server and waits for tasking, all while writing nothing further to disk in executable form.
This angle’s Lessons panel technique-tag list wasn’t captured during the investigation, so no MITRE screenshot is included here. Broadly, the analysis centred on the VBScript-to-PowerShell staging chain and the obfuscated JavaScript runner — the same underlying artifacts the Threat Hunt angle ([[nightshade-c2-multi-stage-infection-threat-hunt]] — case-level techniques listed there) mapped end-to-end from telemetry.
This angle’s debrief recorded zero Pyramid of Pain findings — the panel wasn’t populated for this angle, similar to the Detection Engineering angle on the Ursnif case.
Earned a Distinction (100% score) on this Flash Hunt case.
Verify: https://www.threathuntinglabs.com/badges/eb22ce0d-fca8-4dc0-8d71-20394cef79ff
This closes out the 2-lab NightShade case — Threat Hunt and Malware Analysis, both against the same multi-stage installer chain.