Offline analysis of the provided Windows image at D:\ctf2\The-Hood\The Hood\C to answer 17 challenge questions about the intrusion and data theft.
D:\ctf2\The-Hood\The Hood\C\Windows\System32\winevt\Logs\Microsoft-Windows-Storsvc%4Diagnostic.evtxD:\ctf2\The-Hood\The Hood\C\Users\a1l4m\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.dbD:\ctf2\The-Hood\The Hood\C\Windows\Prefetch\D:\ctf2\The-Hood\The Hood\C\$Extend\$JD:\ctf2\The-Hood\The Hood\C\$MFTD:\ctf2\The-Hood\The Hood\C\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\965B295F92685B983726E076B583D923D:\ctf2\extracted_tools\Deep Inside.exeD:\ctf2\decoded_stage.ps1, D:\ctf2\shellcode_disasm.txtSerialNumber=UM2I126EVendorId=JetFlash, ProductId=Transcend 8GBD:\ctf2\The-Hood\The Hood\C\Windows\System32\winevt\Logs\Microsoft-Windows-Storsvc%4Diagnostic.evtxOMKALALA (F:)D:\ctf2\The-Hood\The Hood\C\Users\a1l4m\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db2024-12-10 21:59:522024-12-10 22:05:45TASKMGR.EXE-4C8500BA.pfD:\ctf2\The-Hood\The Hood\C\Windows\Prefetch\TASKMGR.EXE-4C8500BA.pfCVE-2024-343297ba477a58eb546b6d3cac3a86633b531ba82fa50T1574.002svc1D3C.ps13.75.217.26:8080tools.7z cached in CryptnetUrlCache; SHA256:
0905089bb59887880312af06c769cebd967ffa7d2f652fe397ee972ddbed3d25D:\ctf2\The-Hood\The Hood\C\Windows\System32\config\systemprofile\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\965B295F92685B983726E076B583D9232024-12-11 04:42:35D:\ctf2\The-Hood\The Hood\C\Windows\Prefetch\DEEP INSIDE.EXE-1B0D20D6.pf2024-12-11 04:01:413.121.196.122:55099whoamiD:\ctf2\decoded_stage.ps1 and D:\ctf2\shellcode_disasm.txtDeep Inside.exe plus USN evidence shows:
%TEMP% and then builds a PNG payload.Would you lose.png.Exfiltrated_data.zip followed by Would you lose.png, then zip deletion.D:\ctf2\The-Hood\The Hood\C\$Extend\$JD:\ctf2\The-Hood\The Hood\C\$MFTimportant.txt-Meetings.txt-reminders.txt-research.txt-Stand_Proud_You_Are_Strong.png-tasks.txt-todolist.txt0xL4ugh{c84afabbd76133a117cea1356f1ab6db}