BlackEnergy Write-up
Last updated
Last updated
:الØÙ…د لله والصلاة والسلام على رسول الله وعلى آله ÙˆØµØØ¨Ù‡ أما بعد
Instructions:
Uncompress the lab (pass: )
ZIP SHA-256: 69b66c302d7efeb4d191aee2b4cb98262554dff8
ZIP Size: 57 MB
Link:
Medium:
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw imageinfo
Answer: WinXPSP2x86
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw pslist
There are 25 operations, but only 19 are running
Answer: 19
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw pslist
Answer: 1960
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw pslist
Answer: rootkit.exe
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw malfind
Look for Flags!
Answer: svchost.exe
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw handles --pid 880 -t file
Answer: C:\WINDOWS\system32\drivers\str.sys
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw ldrmodules --pid 880
Answer: msxml3r.dll
Command: .\\volatility_2.6_win64_standalone.exe -f C:\\Users\\MalwareLab\\Desktop\\CYBERDEF-567078-20230213-171333.raw malfind
Answer: 0x980000
Blog: /
Linkedin:
Facebook:
Tryhackme: