forensicsmedium

Thief Challenge Scenario

HackTheBox

Task: analyze a PCAP and recovered malware from a host compromise where data is stolen over ICMP. Solution: recover the PyInstaller payload, reverse its AES-CBC exfil format, rebuild chunk order from ICMP id/seq, decrypt the PNG, and read the flag.

$ ls tags/ techniques/
aes_cbc_decryptionprotocol_reverse_engineeringpcap_traffic_analysispyinstaller_malware_recoveryicmp_exfil_reassembly

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]