Skip to content
View zeved's full-sized avatar
😏
😏
  • Cluj Napoca, Romania

Block or report zeved

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Pinned Loading

  1. hackthebox-businessctf-2021-dfir-wri...
    1
    As this was a downloadable OVA file, I figured I needed to import it into VirtualBox and spin-up the machine in order to start.
    2
    
                  
    3
    After logging in with the provided password Noticed a PowerShell window appearing for a short time (the description mentioned something about ‘blue windows’ popping up so this is interesting).
    4
    
                  
    5
    A quick look in the Task Manager revealed two suspicious processes with no name; however, when opening the file locations, we can find a weird svchost.exe file in a non-standard location: **C:\ProgramData\windows\svchost.exe**

9 contributions in the last year

Contribution Graph
Day of Week April May June July August September October November December January February March
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Less
No contributions.
Low contributions.
Medium-low contributions.
Medium-high contributions.
High contributions.
More

Contribution activity

April 2025

zeved has no activity yet for this period.
Loading