← Back to list

KrakenKeylogger Blue Team Lab

CyberDefenders: Blue team CTF Challenges | KrakenKeylogger

Ege · 2024-08-12 23:39 · 3 claps · 3.4 min read
#cybersecurity #digital-forensics #endpoint-security #lab-solution #adli-bilişim
Open on Medium ↗
Wiki topics: FT · Fine-tuning & Adaptation 🔒 · Cybersecurity

KrakenKeylogger Blue Team Lab

CyberDefenders: Blue team CTF Challenges | KrakenKeylogger

Scenario:

An employee at a large company was assigned a task with a two-day deadline. Realizing that he could not complete the task in that timeframe, he sought help from someone else. After one day, he received a notification from that person who informed him that he had managed to finish the assignment and sent it to the employee as a test. However, the person also sent a message to the employee stating that if he wanted the completed assignment, he would have to pay $160.

The helper’s demand for payment revealed that he was actually a threat actor. The company’s digital forensics team was called in to investigate and identify the attacker, determine the extent of the attack, and assess potential data breaches. The team must analyze the employee’s computer and communication logs to prevent similar attacks in the future.

S1: What is the the web messaging app the employee used to talk to the attacker?

Bu sorunun cevabını bulmamız için internet geçmişini analiz edebiliriz.

C:\Users\OMEN \AppData\Local\Microsoft\Windows\Notifications\wpndatabase.db

Bu dosyayı çıkartıp DB Browser for SQLite a veriyoruz sonra bakıyoruz. Ve bildirimlerin olduğu db ye geçiyoruz.

S2:What is the password for the protected ZIP file sent by the attacker to the employee?

Aynı uygulama içersinde gözümüze zip pass cümlesi ortaya çıkıyor.

  1. What domain did the attacker use to download the second stage of the malware?

Bulduğumuz zip’i indiriyoruz ve içersinde normal bir dosya ve templet diye bir kısa yol dosyası görüyoruz ve bunu Lecmd ile analiz edeceğimizi de biliyoruz . Lecmd.exe -f “dosya yolu” — csv . (çıktının yeri).

Bu çıktıda gözümüze bu karmaşık şeyin bir domain olduğunu anlıyoruz. Maalesef ben kendi başıma çözemedim ve bu yüzden chatgpt’ye çözdürmeye çalıştım. Uzun bir uğraş ve deneme sonucu “masherofmasters.cyou” olduğunu buldum :)

S4: What is the name of the command that the attacker injected using one of the installed LOLAPPS on the machine to achieve persistence?

LOLAPPS, kalıcı sömürüyü gerçekleştirmek için kullanılabilecek uygulamaların bir özetidir. Burda baktığımızda Greenshot.ini ‘nin şüpheli olabileceğini düşünüyoruz.

C:\Users\Forensicator\Desktop\119-KrakenKeyLogger\challenge\Users\OMEN\AppData\Roaming yoluna gidiyoruz burda greenshot.ini dosyasını analiz ediyoruz. Ve burada bir komut belirtiyor.

S5: What is the complete path of the malicious file that the attacker used to achieve persistence?

Daha da baktığımızda yolu da açıkça göstermekte.

S6- S7:

What is the name of the application the attacker utilized for data exfiltration?

What is the IP address of the attacker?

Remote Access Software

An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services, such as , , , , , , and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.VNCTeam Viewer AnyDesk ScreenConnect LogMein AmmyyAdmin.

*Remote Access Software, Technique T1219 — Enterprise | MITRE ATT&CK®*

Yani bir saldırgan, hedef sistemlere erişim sağlamak için meşru olarak kullanılan masaüstü destek ve uzaktan erişim yazılımlarını kullanabilir. Bu yazılımlar, tıpkı VNC, TeamViewer, AnyDesk, ScreenConnect, LogMeIn, AmmyyAdmin gibi yaygın olarak teknik destek için kullanılan araçlardır ve hedeflenen bir ağda genellikle güvenilir olarak kabul edilir, bu yüzden de uygulama kontrolleri tarafından engellenmeyebilir. Bu labtayken gözüm AnyDesk klasörü dikkatimi çekmişti ve içine baktığımda aradığım cevabı buldum.

— — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — — —

Adli Bilişim alanında kendini yeni geliştirmeye çalışan bir öğrenciyim eleştiri ,öneriniz ve düzeltmeniz benim için çok önemli lütfen linkedin adresimden bana ulaşınız . İyi okumalar.

Ege Serep


메타데이터
post_id
1b83162d372a
slug
krakenkeylogger-blue-team-lab-1b83162d372a
url
https://medium.com/@ege.ka/krakenkeylogger-blue-team-lab-1b83162d372a
canonical_url
https://medium.com/@ege.ka/krakenkeylogger-blue-team-lab-1b83162d372a
author_url
https://medium.com/@ege.ka
status
ok
fetched_at
2026-06-16 19:09:56