forensicsPromedium
Общение (Communication)
hackerlab
Task: Analyze suspicious localhost traffic from a pcap file to find a flag. Solution: Extract TCP streams, identify PE malware with XOR encryption (key 0x99), decrypt Base64-encoded C2 messages marked with $$$#...#$$$ delimiters.
$ ls tags/ techniques/
base64_decodingxor_decryptiontcp_stream_extractiondisassembly
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [misc][Pro]Трафик (Traffic)— hackerlab
- [forensics][Pro]Зашифрованный трафик (Encrypted Traffic)— hackerlab
- [forensics][Pro]Офисный Хакер (Office Hacker)— duckerz
- [forensics][Pro]exFill— grodno_new_year_2026
- [forensics][Pro]Download— SPbCTF