Pinned Loading
-
hackthebox-businessctf-2021-dfir-wri...
hackthebox-businessctf-2021-dfir-writeup 1As this was a downloadable OVA file, I figured I needed to import it into VirtualBox and spin-up the machine in order to start.
23After logging in with the provided password Noticed a PowerShell window appearing for a short time (the description mentioned something about ‘blue windows’ popping up so this is interesting).
45A quick look in the Task Manager revealed two suspicious processes with no name; however, when opening the file locations, we can find a weird svchost.exe file in a non-standard location: **C:\ProgramData\windows\svchost.exe**
Something went wrong, please refresh the page to try again.
If the problem persists, check the GitHub status page or contact support.
If the problem persists, check the GitHub status page or contact support.