$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: minidump + PCAP of a custom Nim AES-128-CTR HTTP C2; recover crypto, decrypt traffic, and reconstruct a two-part flag. Solution: carve the Nim implant from the dump, Unicorn-emulate a XOR-rolling-counter key derivation to get the real key, AES-CTR-decrypt all C2 traffic (flag part 1 in a double-base64+gzip screenshot ASCII art), then RC4-self-decrypt the uploaded rev.exe shellcode loader for flag part 2.
Permission denied (requires tier.pro)
Sign in with GitHub or Discord to continue. No email required.
$sign in$ grep --similar