// ThreatHuntingLabs  ·  writeup

Ursnif Malware Targeting Italy — Malware Analysis (Case Lab 4/4)

ThreatHuntingLabs EDR TelemetryKQL

Case Context

Part of a 4-lab investigation case on Threat Hunting Labs built around a single incident: a high-severity alert on a Windows workstation triggered by a signed binary loading a DLL from a user-writable path. This lab is the Malware Analysis angle — the final angle, moving from the host-and-network evidence of the other three labs to the artifact itself: static and behavioural triage of the DLL to establish how it hides and loads.

The case runs four separate investigation angles against the same incident: Threat Hunt, Incident Response, Detection Engineering, and Malware Analysis. This lab is 4 of 4 — I’ll be posting the full case now that all four are complete.

Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.

Techniques Encountered

Four MITRE ATT&CK techniques surfaced during artifact triage, spanning scripting, proxy execution, and obfuscation via packing and shared modules:

MITRE ATT&CK techniques encountered during the artifact triage

Prioritising Findings — Pyramid of Pain

Five findings came out of the artifact triage, weighted by how costly each is for the attacker to change:

Pyramid of Pain breakdown of findings from the artifact triage

What I Practiced

This closes out the 4-lab Ursnif case — Threat Hunt, Incident Response, Detection Engineering, and Malware Analysis, all against the same intrusion from four different analyst angles.