Pinned Loading
-
hackthebox-businessctf-2021-dfir-wri...
hackthebox-businessctf-2021-dfir-writeup 1As this was a downloadable OVA file, I figured I needed to import it into VirtualBox and spin-up the machine in order to start.
23After logging in with the provided password Noticed a PowerShell window appearing for a short time (the description mentioned something about ‘blue windows’ popping up so this is interesting).
45A quick look in the Task Manager revealed two suspicious processes with no name; however, when opening the file locations, we can find a weird svchost.exe file in a non-standard location: **C:\ProgramData\windows\svchost.exe**
9 contributions in the last year
Day of Week | April Apr | May May | June Jun | July Jul | August Aug | September Sep | October Oct | November Nov | December Dec | January Jan | February Feb | March Mar | |||||||||||||||||||||||||||||||||||||||||
Sunday Sun | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Monday Mon | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Tuesday Tue | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Wednesday Wed | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Thursday Thu | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Friday Fri | |||||||||||||||||||||||||||||||||||||||||||||||||||||
Saturday Sat |
Less
No contributions.
Low contributions.
Medium-low contributions.
Medium-high contributions.
High contributions.
More