$ cat writeup.md…
$ cat writeup.md…
HackTheBox
Despite having an updated antivirus, my computer was compromised after running a game. Investigate the game and uncover the two-part flag.
$ cat /etc/rate-limit
Rate limit reached (20 reads/hour per IP). Showing preview only — full content returns at the next hour roll-over.
Despite having an updated antivirus, my computer was compromised after running a game. Investigate the game and uncover the two-part flag.
Downloaded the challenge zip (password: hackthebox). Inside: a Godot Engine game with two files:
Platformer 2D.exe — PE32+ x86-64 Godot Engine binary (44MB)Platformer 2D.pck — Godot PCK resource file (2.4MB), encrypted (AES-256-CFB, Godot 4.1.1, 126 files)The PCK file had encryption flag set (flags=0x1). Studied the Godot 4.1.1 source code (file_access_pack.cpp and file_access_encrypted.cpp) to understand the exact encryption format:
FileAccessEncrypted format (no magic): 16 bytes MD5 hash + 8 bytes length + 16 bytes IV + AES-256-CFB encrypted dataThe AES-256 key was found in the EXE's .data section using strings and radare2 analysis:
f2f44f0aaa282c6b66065b1ca437abae05e20a55a0f6b2fd85f5b90576f0c88fFound malicious code in player.gd (7530 bytes). The script was heavily obfuscated with dozens of intermediate variables containing integer arrays that represent character codes, which are then joined and base64-decoded.
Key decoded values:
http://g4m3l0ad3r-network.htb (C2 server domain)p47l0ad_binary (download path)REDACTED} (flag part 2, used as input to MD5 hash)The malware behavior:
http://g4m3l0ad3r-network.htb/enum/p47l0ad_binary with a specific Cookie headernew_level_mod.exe and executes it via PowerShell with MD5 hash of loap as argument...
$ grep --similar