sameer fakhoury
  • Home
  • CTF Writeups
  • Course Summaries
  • Cyber Reports
  • Articles
  • Event Notes
  • About Me
CovertByte

CovertByte

Level
hard
Type
Forensics

In the wild world of covert data transmission, people have discovered numerous ways to exfiltrate and send data using a variety of methods.

image
  1. Open the PCAP file (wire.pcapng) in Wireshark or any packet analyzer; observe many DNS requests in a short time.
  2. Notice many DNS queries have obfuscated subdomains under ransomcloud-xg48f7yx5a.com.
  3. image
  4. Extract subdomains from the PCAP using:
    1. strings wire.pcapng | grep -oP '.+?(?=.ransomcloud-xg48f7yx5a\.com)' | tr -d ' ' > file.txt
    2. Extract printable strings, isolate subdomains before the main domain, remove spaces, and save to file.txt.
  5. Upload file.txt to
    CyberChefCyberChef
    • Decode the file contents twice with Base64 decoding.
    • Convert the decoded output from hex to binary.
    • Checking the results, we can see that there is a JFIF header, which may indicate the picture is corrupted due to incorrect magic bytes.
    • Save the binary output as a .jpg file; observe it appears corrupted.
    • image
      image
  6. Upload the corrupted JPEG file to
    Jens Duttke HexEd.it - Browser-based Online and Offline Hex EditingJens Duttke HexEd.it - Browser-based Online and Offline Hex Editing
  7. I'm going to search on Google for the header bytes of a JPEG file:
    JPG Signature Format: Documentation & Recovery ExampleJPG Signature Format: Documentation & Recovery Example
  8. image
  9. Replace the first 16 bytes (JPEG header) with, This fixes the JPEG magic header.
  10. FF D8 FF E0 00 10 4A 46 49 46 00 01 01 01 00 48
    image
  11. Save the changes and download the repaired JPEG.
  12. Open the repaired JPEG image.
  13. Read the displayed flag
  14. image
  15. Flag: CTF{Cr4ck_the_C0d3_And_5ee_The_Truth_B3hind_T1m3_4nD_Sp4c3_999}

©sameer fakhoury

GitHubLinkedIn
...
1pqTWdOakFnTTJFZ09EWWdOR0lnWmpNZ01tUWdPVFlnWXpNZ056SWdPRE1nWlRF
Z05qVWdZbVFnWXpBZ01UZ2dPV1FnTlRZZ1lXRWdZalVnTnpjZ01XRWdNR01nTVR
BZ05qZ2dNRFVnTURjZ1l6QWdaRFFnTldNZ1ptWWdNREFnWm1NZ016WWdZV1lnWX
pNZ1ltWWdaamdnWWpRZ1pqZ2daVFVnTURJZ09UUWdObVVnTW1JZ01Ua2dPR0VnW
VdVZ01qVWdZbUVnWWpnZ1lqY2dZamtnTnpZZ1pUWWdNVGtnTnpNZ01UUWdOakFn
TmpVZ1lqUWdOallnTmpjZ01EVWdPREFnTUdRZ09EUWdOVFFnWVRRZ01EVWdaalV
nWldZZ01EZ2dZV01nTkRZZ056a2dOMkVnWkRBZ1lqRWdZVEVnWldVZ00ySWdabV
lnTURBZ09EVWdaR1lnWmpFZ056Y2daakFnTXpZZ05qWWdObVVnTWpVZ04yTWdaa
k1nTTJVZ1pUQWdZV01nWXpFZ09EWWdaRGdnTkRjZ09EZ2dNR0lnTVRrZ05qTWdZ
bUVnT1dVZ01qY2dabVlnWkRrPQ==