forensicsPromedium

Общение (Communication)

hackerlab

Task: Analyze suspicious localhost traffic from a pcap file to find a flag. Solution: Extract TCP streams, identify PE malware with XOR encryption (key 0x99), decrypt Base64-encoded C2 messages marked with $$$#...#$$$ delimiters.

$ ls tags/ techniques/
base64_decodingxor_decryptiontcp_stream_extractiondisassembly

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups