Guild icon
Project Sekai
🔒 CrewCTF 2023 / ✅-forensics-attaaaaack10
Avatar
Attaaaaack10 - 1000 points
Category: Forensics Description: Q10. we think that the malware uses persistence technique can you detect it ? example : crew{Schedule_Task} Author : 0xSh3rl0ck Files: No files. Tags: No tags.
Sutx pinned a message to this channel. 07/08/2023 2:36 AM
Avatar
@Guesslemonger wants to collaborate 🤝
02:37
@Surg wants to collaborate 🤝
02:39
@Violin wants to collaborate 🤝
Avatar
i assume 12 and 13 are easier than 10 and 11 from solve, but not certain
Avatar
Guesslemonger 07/08/2023 2:56 AM
can someone confirm if task has underscore in its name? or spaces to be replaced by underscore
Avatar
let me ask
03:00
ok
03:00
Avatar
Guesslemonger 07/08/2023 3:09 AM
umm ok
Avatar
idk what this means lol
Avatar
Guesslemonger 07/08/2023 3:14 AM
so scheduled task is wrong? because i don't see it setting any task
03:15
it just clones to different files and edits autosart registry
Avatar
its prob not a scheduled task from what he meant
Avatar
Guesslemonger 07/08/2023 3:15 AM
ok he removed scheduled task from chall description
03:15
it is autorun then
Avatar
yeah
03:16
idk what is required
03:16
keys are listed here
03:19
or is it technique name lmao
Avatar
maybe yeah
03:20
its 2 words with space maybe
03:20
then replace w _
03:22
Avatar
Guesslemonger 07/08/2023 3:23 AM
no idea
Avatar
so its the persistent technique name?
Avatar
Guesslemonger 07/08/2023 3:23 AM
what is he showing? answer is correct but format is wrong?
Avatar
no i think format is Abc_Def as mentioned, he prob just saying we trying wrong format
Avatar
Guesslemonger 07/08/2023 3:24 AM
ask him in any case
03:24
if it is just format issue
03:24
if he sent screenshot, answer should be correct
03:24
but wrong format
03:28
Avatar
Guesslemonger 07/08/2023 3:28 AM
umm so what is required exactly?
Avatar
technique name right
03:29
i asked if its technique name he said yes here?
Avatar
Guesslemonger 07/08/2023 3:29 AM
like mitre technique id or something?
Avatar
not id, string name
Avatar
Guesslemonger 07/08/2023 3:31 AM
TA0003 Windows Service T1543.003 Stop service Start service Registry Run Keys / Startup Folder T1547.001 Persist via Run registry key Winlogon Helper DLL T1547.004 Persist via Winlogon Helper DLL registry key
03:31
these are persistence techniques being used
03:31
how do i phrase 2 words
Avatar
Word1_Word2
Avatar
Guesslemonger 07/08/2023 3:31 AM
am not sure if it is a technique name
03:32
you can phrase it differently
Avatar
you can create a ticket and ask
Avatar
Guesslemonger 07/08/2023 3:32 AM
bleh
Avatar
seems no ticket
03:32
dm admin maybe
03:33
you tried all above not working?
Avatar
Guesslemonger 07/08/2023 3:34 AM
yeah not working
Avatar
ok ill ask
03:37
💀
03:37
03:37
i need to sleep, dm admin if any issue
03:37
will wake up in 1 hour
Avatar
Guesslemonger 07/08/2023 3:43 AM
bruh
04:51
💀
Avatar
Guesslemonger 07/08/2023 5:10 AM
what movement of malware!? these are well documented in various blogs
05:10
malware copies itself and then adds keys in RUN
05:11
also he told me to use modmail, so I gave up lol
Avatar
no idea
05:19
crazyman blooded
05:19
you can just dm modmail
05:20
example : crew{Scheduled_tasks} (first letter of the first word is uppercase and the first letter of other is lowercase)
Avatar
@Legoclones wants to collaborate 🤝
Avatar
Guesslemonger 07/08/2023 5:32 AM
05:32
does this for persistence
Avatar
seens they maxxed the series lol
Avatar
Guesslemonger 07/08/2023 6:12 AM
i left, modmail is too annoying, sent a message now
Avatar
idk what to ask lol
06:15
your questions are answered (edited)
Avatar
Guesslemonger 07/08/2023 6:21 AM
fuck that, wasting time, for attack 11, idk wtf is format
Avatar
whats your question to ask
06:21
i can ask
Avatar
Avatar
sahuang
example : crew{Scheduled_tasks} (first letter of the first word is uppercase and the first letter of other is lowercase)
i think this is format (edited)
Avatar
Guesslemonger 07/08/2023 6:22 AM
for 11
06:22
this is the key
06:23
idk format
Avatar
what key and value
06:24
didnt see it
06:24
06:24
lol
Avatar
flag format should be the least of worries
06:25
why case sensitive too
Avatar
@Guesslemonger which flag you had s at the end
Avatar
Guesslemonger 07/08/2023 6:26 AM
don't even remember, i have multiple hits
Avatar
should note down the attempts
Avatar
Guesslemonger 07/08/2023 6:28 AM
bruh
Avatar
Avatar
Guesslemonger
used /ctf solve
✅ Challenge solved.
Avatar
Guesslemonger 07/08/2023 6:28 AM
this is such shit
Avatar
whats the change lol
Avatar
Guesslemonger 07/08/2023 6:28 AM
Registry_key (edited)
06:28
😐
Avatar
whats ur prev try
06:28
keys?
Avatar
Guesslemonger 07/08/2023 6:28 AM
yes
Avatar
lmao
Avatar
Guesslemonger 07/08/2023 6:29 AM
it's literally given in attack 11, key name
😂 1
Exported 103 message(s)