---
analysis: A single detection rule on malware hashes is easily bypassed by binary rotation.
  This hunt correlates cloud identity anomalies with host behavior and file impact,
  providing context that a single-surface rule cannot achieve.
blind_spots:
- id: missing-endpoint-visibility
  question: Are there infected hosts that are not reporting process or file activity?
  requires: endpoint agent coverage
  risk: A host without an agent could be executing malware undetected even if identity
    logs show session hijacking.
  stage: execution-malware-droppers
- id: browser-forensic-gap
  question: Can we confirm the browser-level cookie theft event?
  requires: local browser history and cookie artifacts
  risk: This hunt relies on identifying the aftermath (anomalous sign-ins) rather
    than the direct theft, which may allow stealthy proxy usage to go unnoticed.
  stage: credential-access-session-theft
coverage:
- stage: initial-access-docusign-phishing
  status: covered
  steps:
  - dns-phishing-lures
- stage: credential-access-session-theft
  status: covered
  steps:
  - m365-auth-anomaly
  - agent-identity-triage
- stage: execution-malware-droppers
  status: covered
  steps:
  - malware-execution
- stage: impact-data-encryption
  status: covered
  steps:
  - ransomware-impact
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: M365 session hijacking via phishing platforms like NovaCookies bypasses
    traditional MFA. Detecting the subsequent malware execution and ransomware impact
    on the same user context provides a high-confidence signal for containing intrusions.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary has bypassed MFA by stealing M365 session tokens via DocuSign-themed
  phishing, enabling them to execute malicious droppers and deploy ransomware across
  the fleet.
labels:
- hunt
- attack.t1566.002
- attack.t1539
- attack.t1204.002
- attack.t1486
name: M365 Session Hijacking and Malware Execution
parameters:
  lookback_days:
    default: '14'
    description: Days of history to examine.
    type: number
  malware_filenames:
    default:
    - VID001.exe
    - client32.exe
    - WCInstaller_NonAdmin.exe
    - content.js
    - SECOH-QAD.exe
    description: Known filenames of malicious droppers observed in recent telemetry.
    from:
      kind: article
      observed: '2026-08-27'
      ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    type: list[string]
  malware_hashes:
    default:
    - 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
    - e7e784cae8d37f12a5af0bc9b3975c8d3e668142e9c6b0b365ed4f4e80933c47
    - c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2
    - 38d053135ddceaef0abb8296f3b0bf6114b25e10e6fa1bb8050aeecec4ba8f55
    - 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f
    - a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91
    description: SHA256 hashes of malware droppers and tools identified by Talos.
    from:
      kind: article
      observed: '2026-08-27'
      ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    type: list[hash]
  phishing_domains:
    default:
    - 95.sbx.tg
    - 38d053135d-95.sbx.tg
    - c4dd71e347-95.sbx.tg
    - 9f1f11a708-100.sbx.tg
    description: DocuSign phishing and sandbox domains observed in the campaign; docusign.net
      removed to reduce noise.
    from:
      kind: article
      observed: '2026-08-27'
      ref: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    type: list[domain]
  scope_hosts:
    default: []
    description: Optional list of hostnames to focus the hunt.
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
    gates:
    - dry-run
    - lint
    model: hb_google/gemini-3-flash-preview
rationale: Prioritize users with access to sensitive document shares and workstations
  in departments commonly receiving DocuSign notifications. Start with a 14-day lookback
  to catch the session theft beachhead.
references:
- name: "\u201CSorry, I can\u2019t help with that\u201D: How your guardrails might\
    \ become the attacker\u2019s best friend"
  url: https://blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
- name: "Talos \u2014 Sorry, I can\u2019t help with that: How your guardrails might\
    \ become the attacker\u2019s best friend"
  url: https://blog.blog.talosintelligence.com/sorry-i-cant-help-with-that-how-your-guardrails-might-become-the-attackers-best-friend/
related:
- hunt: m365-token-theft-browser-forensics
  reason: This hunt focuses on network and authentication anomalies; browser-specific
    cookie artifacts require a separate forensic hunt.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: DocuSign Phishing Lure
    observables:
    - genuine docusign notifications
    - docusign.net
    - NovaCookies phishing platform
    slug: initial-access-docusign-phishing
    tactic: initial-access
    techniques:
    - T1566.002
  - name: M365 Session Hijacking
    observables:
    - M365 session theft
    - real-time session hijacking
    - $320/month phishing kit
    slug: credential-access-session-theft
    tactic: credential-access
    techniques:
    - T1539
  - name: Malware Dropper Execution
    observables:
    - VID001.exe
    - client32.exe
    - WCInstaller_NonAdmin.exe
    - content.js
    - SECOH-QAD.exe
    - d4aa3e7010220ad1b458fac17039c274_62_Exe.exe
    - ToxicPanda banking trojan
    slug: execution-malware-droppers
    tactic: execution
    techniques:
    - T1204.002
  - name: Data Encryption for Impact
    observables:
    - ransomware encryption
    - file renaming
    - inaccessible user files
    slug: impact-data-encryption
    tactic: impact
    techniques:
    - T1486
  summary: The NovaCookies campaign uses genuine DocuSign notifications to lure users
    into Microsoft 365 session theft via a subscription-based phishing kit. Stolen
    sessions enable unauthorized access to corporate environments, leading to the
    deployment of various banking trojans and droppers like ToxicPanda or VID001.exe,
    and eventually culminating in data encryption for impact.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
tlp: clear
type: investigation
---


# M365 Session Hijacking and Malware Execution

This hunt follows an attack lifecycle from initial cloud identity theft to endpoint ransomware impact. It begins by identifying suspicious DocuSign-related phishing activity and anomalous M365 sign-ins that suggest session hijacking using the NovaCookies platform. The hunt then pivots to the endpoint to detect the execution of specific malware droppers identified by Talos telemetry and monitors for high-frequency file operations characteristic of data encryption. By correlating cloud authentication anomalies with host-side process and file artifacts, the hunt identifies compromised users and the specific hosts where malicious code established a beachhead.

## scope-windows-workstations
<!-- Scope Windows Workstations -->
Identify active Windows hosts that are the primary targets for phishing and subsequent ransomware execution.

```sqlite target=endpoint role=scoping params=(lookback_days=lookback_days)
~~~yaml
expected: A list of targetable Windows hosts. None means no Windows systems were enrolled
  or active during the window.
reads:
- hostname
- os_name
- os_version
- last_seen
- time
silence: not_evidence_of_absence
source: hb_devices
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT hostname, os_name, os_version, last_seen FROM hb_devices WHERE platform = 'windows' AND lifecycle_state = 'active' AND time >= datetime('now', '-{{lookback_days}} days')
```

## early-stage-parallel
<!-- Early Stage Parallel -->
parallel:
- → dns-phishing-lures
- → m365-auth-anomaly
join: → agent-identity-triage

## dns-phishing-lures
<!-- DNS Phishing Lures -->
Detect resolution of DocuSign-themed phishing sites or sandbox domains named in the report.

```sqlite target=endpoint role=enrichment params=(phishing_domains=phishing_domains, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Hosts resolving malicious domains; silence means no direct connection to
  the reported lures occurred.
reads:
- device_hostname
- query_hostname
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, query_hostname, COUNT(*) AS total_lookups, MIN(time) AS first_seen FROM hb_dns_activity WHERE instr(',' || '{{phishing_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, query_hostname
```

## m365-auth-anomaly
<!-- M365 Sign-in Anomalies -->
Find successful M365 logons from unusual IP addresses per user, suggesting session hijacking.

```sqlite target=identity role=baseline params=(lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A rare user/IP combination that differs from historical patterns. A single
  logon from a new IP for a user is a typical hijacking signal.
prevalence:
  by: actor_user_name
  key:
  - src_endpoint_ip
  rare_below: 2
reads:
- actor_user_name
- src_endpoint_ip
- provider
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT actor_user_name, src_endpoint_ip, COUNT(*) AS logon_count, MIN(time) AS first_logon, MAX(time) AS last_logon FROM hb_auth_signin WHERE provider = 'm365' AND status_id = 1 AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY actor_user_name, src_endpoint_ip HAVING logon_count < 5 ORDER BY logon_count ASC
```

## agent-identity-triage
<!-- Triage Identity Hijack -->
```agent target=hunter
cite: required
context:
- dns-phishing-lures
- m365-auth-anomaly
max_iterations: 4
objective: Identify users who likely fell for a DocuSign phishing lure and subsequently
  had their M365 session hijacked. Cite the resolved domain and the anomalous logon
  IP.
success_criteria: A list of users with corresponding suspicious IP and DNS evidence.
tools:
- endpoint
- identity
```

## follow-on-parallel
<!-- Endpoint Follow-on Hunt -->
parallel:
- → malware-execution
- → ransomware-impact
join: → follow-on-agent

## malware-execution
<!-- Malware Execution -->
Detect the execution of the specific droppers and tools identified by Talos.

```sqlite target=endpoint role=detection-candidate params=(malware_hashes=malware_hashes, malware_filenames=malware_filenames, lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: Process executions matching the reported malware. Any match is high confidence.
reads:
- device_hostname
- process_name
- process_hash_sha256
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_hash_sha256, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{malware_hashes}}' || ',', ',' || LOWER(process_hash_sha256) || ',') > 0 OR instr(',' || '{{malware_filenames}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0)
```

## ransomware-impact
<!-- Ransomware Impact -->
Detect high-frequency file operations on user document types, characteristic of encryption.

```sqlite target=endpoint role=triage params=(lookback_days=lookback_days, scope_hosts=scope_hosts)
~~~yaml
expected: A burst of file creations, deletions, or renames on document files. Silence
  means no mass encryption events were detected on the targeted surfaces.
reads:
- device_hostname
- actor_user_name
- activity_id
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, actor_user_name, COUNT(*) AS op_count, MIN(time) AS first_op, MAX(time) AS last_op FROM hb_file_activity WHERE activity_id IN (1, 4, 5) AND (LOWER(file_path) LIKE '%.docx' OR LOWER(file_path) LIKE '%.xlsx' OR LOWER(file_path) LIKE '%.pdf') AND time >= datetime('now', '-{{lookback_days}} days') AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) GROUP BY device_hostname, actor_user_name HAVING op_count > 20
```

## follow-on-agent
<!-- Final Correlation Agent -->
```agent target=hunter
cite: required
context:
- agent-identity-triage
- malware-execution
- ransomware-impact
max_iterations: 6
objective: Determine if compromised identities from the early stage match users or
  hosts where malware and ransomware impact occurred. Issue a malicious verdict if
  the killchain is confirmed.
success_criteria: A final verdict per host citing the correlation between identity
  theft and malicious endpoint activity.
tools:
- endpoint
- identity
```

## route-decision
<!-- Route on Final Verdict -->
if~: "the follow-on-agent verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-endpoint-visibility)
else: → close-out

## isolate-host
<!-- Isolate Host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the infected host from the network and revoke all M365 session tokens for the affected user account.
```
→ analyst-review

## analyst-review
<!-- Analyst Review -->
```manual target=analyst
Review the correlated evidence: DNS lure resolution, anomalous IP sign-in, and endpoint malware execution. Confirm if the file operations align with a ransomware attack.
```
→ close-out

## close-out
<!-- Close-out -->
```manual target=analyst
Record the hosts and users examined. Note any new phishing domains discovered to update future hunt iterations.
```
→ end
