forensicsmedium

Общение (Communication)

hackerlab

Task: Analyze suspicious localhost traffic from a pcap file to find a flag. Solution: Extract TCP streams, identify PE malware with XOR encryption (key 0x99), decrypt Base64-encoded C2 messages marked with $$$#...#$$$ delimiters.

$ ls tags/ techniques/
base64_decodingxor_decryptiontcp_stream_extractiondisassembly

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]