Forensics - Golden Persistence
Hack the Box Cyber Apocalypse CTF 2022 - Intergalactic Chase, Golden Persistence Forensics Challenge Writeup
Last updated
Hack the Box Cyber Apocalypse CTF 2022 - Intergalactic Chase, Golden Persistence Forensics Challenge Writeup
Last updated
For this one we started with an NTUSER.DAT file. I went ahead and opened it in MiTeC Windows Registry Recovery which allows me to explore the entire file easily. From looking around briefly we can see there is a startup process being run that executes an encoded powershell script.
To view the whole command and copy it I headed over to the raw data section and searched for the name.
Once that popped up I copied the encoded text and plugged it into CyberChef.
Towards the bottom it grabs a few other files and uses their data conjoined to load the encrypted data.
I went through and found each of these files and grabbed the data from them and plugged it into the powershell script manually.
After doing this I made sure nothing would execute and then I ran it so it would print out the encrypted data in plaintext and there was the flag.
PWNED!!