HTB: Fries
Fries is a hard difficulty HTB challenge that starts with a given credential set. After initial enumeration, I am able to use this to login to a Gitea instance, where I find exposed PostgreSQL data...
Fries is a hard difficulty HTB challenge that starts with a given credential set. After initial enumeration, I am able to use this to login to a Gitea instance, where I find exposed PostgreSQL data...
This write up covers my analysis for this month’s Zero2Automated bi-monthly malware challenge, which was posted in the discord. The list of sample files can be found here. After a quick look up of...
Lovely Malware is an insane difficulty malware RE sherlock, which includes a PE file, pcap file, and an encrypted .txt.naso file. I’ll start with covering what I did to decrypt config data and reso...
Writeup for the hard level forensic challenge “Acknowledge the corn” found here Challenge description: One of our clients currently active in the banking sector, was recently targeted by a known A...
Writeup for the hard level forensic challenge “Windows Infinity Edge” found here Challenge description: A motivated APT group has breached our company and utilized custom tooling. We’ve identified...
This writeup takes a look at a recently uploaded sample of Redosdru, a RAT that’s been around for a while. I’ll cover config extraction and a quick look at some of it’s features. Initial Analysis ...
In this post, I will be going deeper on the sample used in my previous BTLO challenge writeup. The challenge sample Cerberus RAT 1.03.5 Beta 2009 surfaced around the same time that early Spy-Net RA...
This writeup will walk through a dynamic malware analysis lab of Pandemic on blueteamlabs. Scenario text: The second wave of the pandemic started. Cybercriminals also started their second wave of ...