CTF-Writeups

The Hood - DFIR Writeup

Scope

Offline analysis of the provided Windows image at D:\ctf2\The-Hood\The Hood\C to answer 17 challenge questions about the intrusion and data theft.

Data Sources

Findings and Evidence

USB device identification (Q1-3)

Intrusion window (Q4)

Recon and exploitation (Q5-8)

Defense evasion (Q9)

Payload download and persistence (Q10, Q14-15)

C2 shell activity (Q11-13)

Exfiltration (Q16-17)

Answer Key

  1. UM2I126E
  2. Transcend
  3. OMKALALA
  4. 2024-12-10 21:59:52_2024-12-10 22:05:45
  5. TASKMGR.EXE
  6. CVE-2024-34329
  7. 7ba477a58eb546b6d3cac3a86633b531ba82fa50
  8. T1574.002
  9. svc1D3C.ps1
  10. 3.75.217.26:8080
  11. 2024-12-11 04:01:41
  12. 3.121.196.122:55099
  13. whoami
  14. 0905089bb59887880312af06c769cebd967ffa7d2f652fe397ee972ddbed3d25
  15. 2024-12-11 04:42:35
  16. Would you lose.png
  17. important.txt-Meetings.txt-reminders.txt-research.txt-Stand_Proud_You_Are_Strong.png-tasks.txt-todolist.txt

Flag (challenges3.ctf.sd:33456)

0xL4ugh{c84afabbd76133a117cea1356f1ab6db}