// ThreatHuntingLabs  ·  writeup

Ursnif Malware Targeting Italy — Threat Hunt (Case Lab 1/4)

ThreatHuntingLabs EDR TelemetryNetwork Logs (Zeek)KQL

Case Context

Part of a 4-lab investigation case on Threat Hunting Labs built around a single incident: a high-severity alert on a Windows workstation triggered by a signed binary loading a DLL from a user-writable path. This lab is the Threat Hunt angle — hunting through EDR and network telemetry to build the attack chain from initial proxy execution through to command-and-control, without a pre-built detection rule to lean on.

The case runs four separate investigation angles against the same incident: Threat Hunt, Incident Response, Detection Engineering, and Malware Analysis. This lab is 1 of 4 — I’ll be posting the full case once all four are complete rather than piecemeal.

Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.

Techniques Encountered

Nine MITRE ATT&CK techniques surfaced across the hunt, spanning proxy execution, scripting, registry-based staging, and layered C2:

MITRE ATT&CK techniques encountered during the hunt

Prioritising Findings — Pyramid of Pain

Fifteen findings came out of the hunt, weighted by how costly each is for the attacker to change — hash values are trivial to burn, TTPs are what actually hurt:

Pyramid of Pain breakdown of findings from the hunt

What I Practiced