<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Huntress - 2025 on Eddak Inc.</title><link>/docs/huntress/</link><description>Recent content in Huntress - 2025 on Eddak Inc.</description><generator>Hugo</generator><language>en</language><copyright>Copyright (c) 2020-2024 Thulite</copyright><lastBuildDate>Thu, 09 Oct 2025 16:04:48 +0200</lastBuildDate><atom:link href="/docs/huntress/index.xml" rel="self" type="application/rss+xml"/><item><title>Bussing Around</title><link>/docs/huntress/bussing-around/</link><pubDate>Thu, 09 Oct 2025 16:04:48 +0200</pubDate><guid>/docs/huntress/bussing-around/</guid><description>&lt;h2 id="challenge-information"&gt;Challenge Information&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Challenge Name:&lt;/strong&gt; Bussing Around&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Category:&lt;/strong&gt; Forensics&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Challenge Description:&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;One of the engineers noticed that an HMI was going haywire.&lt;/li&gt;
&lt;li&gt;He took a packet capture of some of the traffic but he can&amp;rsquo;t make any sense of it&amp;hellip; it just looks like gibberish!&lt;/li&gt;
&lt;li&gt;For some reason, some of the traffic seems to be coming from someone&amp;rsquo;s computer. Can you help us figure out what&amp;rsquo;s going on?&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;File(s) Provided:&lt;/strong&gt; Modbus traffic capture&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="approach--solution"&gt;Approach &amp;amp; Solution&lt;/h2&gt;
&lt;h3 id="approach"&gt;Approach&lt;/h3&gt;
&lt;p&gt;The only communication on the capture are between two entities: &lt;code&gt;172.20.10.6&lt;/code&gt; &amp;amp; &lt;code&gt;172.20.10.2&lt;/code&gt;
The .6 entity initiates the communication with .2.&lt;/p&gt;</description></item><item><title>SANDY</title><link>/docs/huntress/sandy/</link><pubDate>Wed, 08 Oct 2025 16:04:48 +0200</pubDate><guid>/docs/huntress/sandy/</guid><description>&lt;h2 id="challenge-information"&gt;Challenge Information&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Challenge Name:&lt;/strong&gt; SANDY&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Category:&lt;/strong&gt; Malware&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Challenge Description:&lt;/strong&gt; My friend Sandy is really into cryptocurrencies! She&amp;rsquo;s been trying to get me into it too, so she showed me a lot of Chrome extensions I could add to manage my wallets. Once I got everything sent up, she gave me this cool program! She says it adds better protection so my wallets can&amp;rsquo;t get messed with by hackers. Sandy wouldn&amp;rsquo;t lie to me, would she&amp;hellip;? Sandy is the best!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;File(s) Provided:&lt;/strong&gt; Windows Executable (malware)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="approach--solution"&gt;Approach &amp;amp; Solution&lt;/h2&gt;
&lt;h3 id="approach"&gt;Approach&lt;/h3&gt;
&lt;p&gt;The file we are analyzing is an UPX packed exe file.&lt;/p&gt;</description></item><item><title>Beyblade</title><link>/docs/huntress/beyblade/</link><pubDate>Tue, 07 Oct 2025 16:04:48 +0200</pubDate><guid>/docs/huntress/beyblade/</guid><description>&lt;h2 id="challenge-information"&gt;Challenge Information&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Challenge Name:&lt;/strong&gt; Beyblade&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Category:&lt;/strong&gt; Forensics&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Challenge Description:&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Sheesh! Some threat actor sure did &lt;em&gt;let it rip&lt;/em&gt; on this host! We&amp;rsquo;ve been able to uncover a file that may help with incident response.&lt;/li&gt;
&lt;li&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;The password to the ZIP archive is &lt;code&gt;beyblade&lt;/code&gt;.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;ol start="2"&gt;
&lt;li&gt;This challenge has the flag MD5 hash value separated into chunks. You must uncover all of the different pieces and put them together with the &lt;code&gt;flag{&lt;/code&gt; and &lt;code&gt;}&lt;/code&gt; suffix to submit.&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;File(s) Provided:&lt;/strong&gt; Windows Registry&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hint(s):&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;Flag divided into several pieces.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="approach--solution"&gt;Approach &amp;amp; Solution&lt;/h2&gt;
&lt;h3 id="approach"&gt;Approach&lt;/h3&gt;
&lt;h5 id="file-detection"&gt;&lt;strong&gt;File detection&lt;/strong&gt;:&lt;/h5&gt;
&lt;ul&gt;
&lt;li&gt;DIE:&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;

&lt;img
 src="/images/CTF/huntress/bey_ev_1_hu_9567bd4efb6a85af.webp"
 width="780"
 height="538"
 decoding="async"
 fetchpriority="auto"
 loading="lazy"
 alt=""
 id="h-rh-i-0"
&gt;&lt;/p&gt;</description></item></channel></rss>