EmberForge // Source Leak
CHALLENGE: EmberForge // Source Leak
PLATFORM: LOG(N) Pacific Cyber Range (Skool)
ANALYST: Erick Cisneros Ruballos
DATE COMPLETED: 2026-04-04
DATA SOURCE: EmberForgeX_CL (Sysmon + Windows Security events)
A threat actor compromised the emberforge.local domain through a phishing-delivered ISO file, achieving full domain compromise in a single attack session. The attacker exfiltrated the entire C:\GameDev source code repository (42.3 GB) to MEGA cloud storage.
Executive Summary
A threat actor compromised the emberforge.local domain through a phishing-delivered ISO file, achieving full domain compromise in a single attack session. The attacker exfiltrated the entire C:\GameDev source code repository (42.3 GB) to MEGA cloud storage using the credential jwilson.vhr@proton.me.
Domain credentials were stolen via NTDS.dit extraction from a VSS shadow copy on the Domain Controller. The attacker established persistent remote access via AnyDesk and created a backdoor domain admin account (svc_backup). Security and System event logs on the DC were subsequently cleared to impede forensic investigation — however, Sysmon telemetry survived the clearing and provides near-complete reconstruction of the attack chain.
Attack Timeline
Initial Access (EC2AMAZ-B9GHHO6)
Lisa Martin opened 'EmberForge_Review.iso' which bypassed Mark-of-the-Web. rundll32.exe executed 'review.dll', injecting into notepad.exe.
C2 Establishment & UAC Bypass
update.exe established C2 to cdn.cloud-endpoint.net. Privileges escalated via fodhelper UAC Bypass, writing to registry. Persistence created as 'WindowsUpdate' scheduled task.
Credential Dumping & Discovery
update.exe dumped LSASS using direct syscalls to 'lsass.dmp'. Elevated process ran net user /domain and nltest /dclist. Added firewall rule for SMB.
Lateral Movement to Server
Tools staged via workstation SMB share. Failed NTLM pass-the-hash. Attacker pivoted to Impacket smbexec and certutil.exe to stage tools on EC2AMAZ-16V3AU4.
Exfiltration (EC2AMAZ-16V3AU4)
Compress-Archive on C:\GameDev. rclone.exe configured with plaintext MEGA credentials line-by-line, and source code exfiltrated.
Lateral Movement to DC
Impacket atexec run on DC (EC2AMAZ-EEU3IA2). Pivoted to smbexec for NTDS.dit extraction via VSS shadow copy.
Backdoor & Persistence
Created backdoor account 'svc_backup' in Domain Admins. Installed AnyDesk silently with config modified for unattended access ('password').
Anti-Forensics (EC2AMAZ-EEU3IA2)
Executed 'wevtutil cl Security' and 'wevtutil cl System' via smbexec on the DC to wipe event logs. Sysmon telemetry survived.
Evidence Inventory & IOCs
| C2 Domain | cdn.cloud-endpoint.net |
| Staging Domain | sync.cloud-endpoint.net:8080 |
| C2 IP | 104.21.30.237, 172.67.174.46 |
| Attacker Email | jwilson.vhr@proton.me |
| ISO Delivery | EmberForge_Review.iso |
| Malicious DLL | D:\review.dll |
| C2 Implant | C:\Users\Public\update.exe |
| LSASS Dump | C:\Windows\System32\lsass.dmp |
| NTDS.dit copy | C:\Windows\Temp\nyMdRNSp.tmp |
Sentinel Ingestion vs. Event Time
Do not rely on TimeGenerated for forensic attack sequencing. Actual event times are embedded in the Sysmon/Windows XML in Raw_s:
<TimeCreated SystemTime='2026-01-30T23:19:21.XXXXXXX'/>This distinction was critical for DC Arrival analysis: the atexec whoami at 23:19:21 preceded the smbexec vssadmin operations at 23:34:55 — a 15-minute gap invisible from ingestion timestamps alone.
Strategic Recommendations
- 1Rotate all domain credentials immediately — NTDS.dit was exfiltrated; all password hashes are compromised.
- 2Disable and delete the svc_backup domain admin account.
- 3Revoke MEGA access for jwilson.vhr@proton.me and report to MEGA abuse team.
- 4Remove AnyDesk service from EC2AMAZ-B9GHHO6 and invalidate all AnyDesk IDs.
- 5Delete WindowsUpdate scheduled task and remove update.exe from Public folder.
- 6Block C2 domains/IPs: cdn.cloud-endpoint.net, sync.cloud-endpoint.net, 104.21.30.237, 172.67.174.46.
- 7Reset KRBTGT account twice (24-hour gap) to invalidate any forged Kerberos tickets.