↓ Skip to main content
  1. Writeups/
  2. CyberDefenders/

Silent Breach

Description
#

The IMF is hit by a cyber attack compromising sensitive data. Luther sends Ethan to retrieve crucial information from a compromised server. Despite warnings, Ethan downloads the intel, which later becomes unreadable. To recover it, he creates a forensic image and asks Benji for help in decoding the files.

Check the challenge here.

References
#

Solution
#

The challenge archive contains ethanPC.ad1. AD1 is AccessData’s forensic image format. It is a logical image, so it contains selected files and folders from the original system rather than a complete physical disk image. FTK Imager can open it and preserve the directory structure and file metadata while we examine the evidence.


Q1: What is the MD5 hash of the potentially malicious EXE file the user downloaded?

I opened the image in FTK Imager, navigated to the user’s Downloads folder, and found IMF-Info.pdf.exe. I right-clicked the file and selected Export File Hash List.

Flag: 336a7cf476ebc7548c93507339196abb


Q2: What is the URL from which the file was downloaded?

Windows stores download information in an alternate data stream called Zone.Identifier. In FTK Imager, I expanded the executable in the evidence tree and opened its Zone.Identifier stream. The HostUrl entry contains the URL used to download the file.

Zone.Identifier in FTK Imager

Flag: http://192.168.16.128:8000/IMF-Info.pdf.exe


Q3: What application did the user use to download this file?

While exploring AppData, I found data for both Chrome and Edge. Browser history is stored in a SQLite database named History, usually under User Data\Default\History. I opened the databases with SQLite Viewer Web App and checked the download records. The matching record was in Edge’s database, which identifies the application used to download the executable.

Edge download history in SQLite Viewer

Flag: Microsoft Edge


Q4: By examining Windows Mail artifacts, we found an email address mentioning three IP addresses of servers that are at risk or compromised. What are the IP addresses?

Following the reference above, I found the Windows Mail database at AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\HxStore.hxd. The file contains serialized mail records. The @body marker identifies the beginning of an email body, so it is a useful anchor when searching the raw file.

I extracted printable strings and displayed the lines following each @body marker:

strings -a -n 5 HxStore.hxd | grep -A 200 '@body'

The relevant part of the output contains the three server addresses:

<SNIP>
Pve id
VseverU
	bpromis
. You ca
	@nito
status thr
c hubs:o
0PraQ
PClusth
IP: 145.67.29.88 (at risk
?on)Z
London O
	B Hub
212.33.10.112 (partial breach detected
Berlin Vault
192.168.16.128
@progG
Please <b>DO NOT download or execute any

Flag: 145.67.29.88, 212.33.10.112, 192.168.16.128


Q5: By examining the malicious executable, we found that it uses an obfuscated PowerShell script to decrypt specific files. What predefined password does the script use for encryption?

I extracted the printable strings from the executable and searched them for powershell in VSCode:

strings -a -n 5 IMF-Info.pdf.exe > strings.txt

Obfuscated PowerShell command

The script contains three obfuscated strings. The value assigned to $FHG7xpKlVqaDNgu1c2Utw is the reversed Base64 representation of the value assigned to $wy7qIGPnm36HpvjrL2TMUaRbz. Reversing the string first and then decoding it from Base64 reveals the predefined password.

I used CyberChef with the Reverse operation followed by From Base64 to decode it.

Decoded password in CyberChef

Flag: Imf!nfo#2025Sec$


Q6: After identifying how the script works, decrypt the files and submit the secret string.

After decoding the script, I adapted it to decrypt both .enc files:

$password = "Imf!nfo#2025Sec$"
$salt = [Byte[]](0x01,0x02,0x03,0x04,0x05,0x06,0x07,0x08)
$iterations = 10000
$keySize = 32
$ivSize = 16

$deriveBytes = New-Object System.Security.Cryptography.Rfc2898DeriveBytes($password, $salt, $iterations)
$key = $deriveBytes.GetBytes($keySize)
$iv = $deriveBytes.GetBytes($ivSize)

$inputFiles = @(
    "C:\Users\docker\Desktop\CTF\silent_breach\IMF-Mission.enc",
    "C:\Users\docker\Desktop\CTF\silent_breach\IMF-Secret.enc"
)

foreach ($inputFile in $inputFiles) {
    $outputFile = $inputFile -replace '\.enc$', '.pdf'

    $aes = [System.Security.Cryptography.Aes]::Create()
    $aes.Key = $key
    $aes.IV = $iv
    $aes.Mode = [System.Security.Cryptography.CipherMode]::CBC
    $aes.Padding = [System.Security.Cryptography.PaddingMode]::PKCS7

    $decryptor = $aes.CreateDecryptor()

    $encBytes = [System.IO.File]::ReadAllBytes($inputFile)

    $outStream = New-Object System.IO.FileStream($outputFile, [System.IO.FileMode]::Create)
    $cryptoStream = New-Object System.Security.Cryptography.CryptoStream($outStream, $decryptor, [System.Security.Cryptography.CryptoStreamMode]::Write)

    $cryptoStream.Write($encBytes, 0, $encBytes.Length)
    $cryptoStream.FlushFinalBlock()

    $cryptoStream.Close()
    $outStream.Close()

    Remove-Item $inputFile -Force
}

The script derives a 32-byte AES key and a 16-byte IV from the password and salt using PBKDF2 with 10,000 iterations. It then decrypts the files with AES-CBC and PKCS7 padding, writing the results as PDFs. The flag is in IMF-Mission.pdf.

Flag: CyberDefenders{N3v3r_eX3cuTe_F!l3$_dOwnL0ded_fr0m_M@lic10u5_$erV3r}


Note

I used AI to check spelling and enhance phrasing of this writeup. I also used it to get information about browser History file location.

Vlad Șteopoaie
Author
Vlad Șteopoaie
A.K.A. h3pha