$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: PCAP of an APT breach using a SharPyShell (.NET in-memory) webshell over HTTP; one server looks clean but shows suspicious traffic. Solution: reconstruct the hidden .NET assembly from two ulong arrays, recover the AES-256-CBC key (hardcoded hex p) and IV (ASCII 'infinity_edgehtb') from IL, decrypt the whole C2 session, follow JuicyPotato privesc, then XOR-decode the fileless shellcode injected into explorer.exe with the key xGk89_Ew the attacker stashed in C:\\xor.k to recover the real flag (avoiding the decoy).
Permission denied (requires tier.pro)
Sign in with GitHub or Discord to continue. No email required.
$sign in$ grep --similar