$ cat writeup.md…
$ cat writeup.md…
HackTheBox
Task: Multi-layer obfuscated phishing document — HTML email with embedded XLSM containing VBA macros that drop an HTA with injected shellcode. Solution: Extract XLSM from data URI, reassemble three base64 fragments from image alt text/form caption/cell value, decode HTA, reconstruct Chr()-obfuscated VBA, emulate Shikata Ga Nai shellcode with Unicorn Engine to reveal Metasploit reverse_tcp C2 URL containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar