Tips & Tricks For Forensics Challenges by 0xdf_ | Hacking Workshop

Tips & Tricks For Forensics Challenges by 0xdf_ | Hacking Workshop

Source: YouTube · Hack The Box · published May 26, 2022 · 38:12

Malware Analysis
No ratings yet Log in to rate
Transcript Available
Description

This video features a walkthrough of two forensic CTF challenges: extracting a Zip file hidden within ICMP packets using Wireshark and Python to find a flag in a Firefox profile, and analyzing a malicious Word document macro to decode a PowerShell payload 3:22.

Key Takeaways:
• Wireshark's Protocol Hierarchy tool is used to identify anomalies, such as excessive ICMP traffic, where inspecting packet payloads reveals "PK" magic bytes indicating a hidden Zip file 5:06.
• The presenter uses Python with the Scapy library to filter ICMP echo requests, extract data from specific byte offsets, and reconstruct the Zip file to disk 14:10.
• The extracted Zip contains a Firefox profile, and the tool firepwd.py is utilized to decrypt saved credentials and uncover the challenge flag 21:48.
• Using olevba on a malicious .docm file reveals an auto-open macro that constructs a shell command by decoding hex strings, which the presenter translates into Python for easier decoding 23:42.

David advises examining all parts of malicious code, such as scheduled tasks, rather than just the immediate payloads to locate hidden flags 34:00.

Sources:

  • 3:22 Introduction to "Oldest Trick in the Book" challenge
  • 5:06 Analyzing ICMP traffic and magic bytes
  • 14:10 Using Python and Scapy to extract data
  • 21:48 Using firepwd.py to get the flag
  • 23:42 Analyzing the malicious Word document macro
  • [34

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

and we are back so uh i think i did a little bit of an intro er before uh yes we have with us david xerxdf uh one of the best people to work with in hack the box eternal knowledge in everything from sis admin to id to hacking to blue teaming to anything and the most amazing part is that he actually has also life i think this will be my question how you can manage be know all these things be so calm i cannot and also being always so helpful uh with anyone actually that is very nice because david is in the committee that they release boxes or not and they give also constructive feedback let's give it up to an amazing a hacker and co-worker hello david how are you uh you are muted we cannot hear you can you hear me now amazing it's not been watching the talks today it seems like everyone come…