Challenge Link: https://www.root-me.org/en/Challenges/Forensic/Ugly-Duckling
Seems like it is executing a malicious code....
Googled about the 'enc' parameter of powershell and found this: https://artofpwn.com/offensive-and-defensive-powershell-ii.html. So it is in base64 encoding. Decoding...
The binary file downloads an executable and runs it. Tried to run the file in powershell but my antivirus program blocked it. So I just downloaded the exe manually and then run it. Finally, the flag shows up.
Thanks man!
ReplyDeleteI like your blog (:
Hello brother, for me https://ducktoolkit.com/ worked perfectly, and i did not execute it, i just put it in virustotal.com the flag is there in the behavior section ;)
ReplyDelete