forensicsmedium
Thief Challenge Scenario
HackTheBox
Task: analyze a PCAP and recovered malware from a host compromise where data is stolen over ICMP. Solution: recover the PyInstaller payload, reverse its AES-CBC exfil format, rebuild chunk order from ICMP id/seq, decrypt the PNG, and read the flag.
$ ls tags/ techniques/
aes_cbc_decryptionprotocol_reverse_engineeringpcap_traffic_analysispyinstaller_malware_recoveryicmp_exfil_reassembly
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub to get started.
$ssh [email protected]