<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>DFIR on Harsh Upadhyay</title>
    <link>https://harshupadhyay.com/tags/dfir/</link>
    <description>Recent content in DFIR on Harsh Upadhyay</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 24 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://harshupadhyay.com/tags/dfir/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ValleyRAT Behind a Fake &#34;Income Tax&#34; Notice: Anatomy of a Phishing Campaign</title>
      <link>https://harshupadhyay.com/posts/valleyrat-fake-tax-notice-india/</link>
      <pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://harshupadhyay.com/posts/valleyrat-fake-tax-notice-india/</guid>
      <description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;TL;DR&lt;/strong&gt; — A phishing campaign is impersonating the &lt;strong&gt;Government of India / Income Tax Department&lt;/strong&gt; (&amp;ldquo;कर दंड सूचना – भारत सरकार&amp;rdquo; / &lt;em&gt;Tax Penalty Notice&lt;/em&gt;) to deliver &lt;strong&gt;ValleyRAT&lt;/strong&gt;. Victims receive emails from free webmail providers (Proton Mail, Yahoo, etc.), click through to a freshly‑registered lure domain, and download &lt;code&gt;Tax-Number70863.zip&lt;/code&gt;. The ZIP contains an &lt;strong&gt;ISO image&lt;/strong&gt; (&lt;code&gt;Tax-Number70863.iso&lt;/code&gt;) — a classic &lt;strong&gt;Mark‑of‑the‑Web bypass&lt;/strong&gt; — which, when mounted, presents a single executable disguised with a &lt;strong&gt;fake Google Chrome icon&lt;/strong&gt; to mislead the user into running it. The payload establishes persistence via a Run key &lt;strong&gt;and&lt;/strong&gt; COM hijacking, injects into &lt;code&gt;ngen.exe&lt;/code&gt;, drops a kernel driver, steals browser credentials, and beacons to a raw‑IP C2 on &lt;code&gt;103.59.103[.]30:8888&lt;/code&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
