Open in app

Sign In

Write

Sign In

nosfera0x2
nosfera0x2

9 Followers

Home

About

Sep 14

BTLO — Paranoid

Howdy y’all! This is a write up of Blue Team Lab Online’s challenge ‘Paranoid’ It is a challenge the involves reviewing an audit log file using the tool aureport, which is part of the auditd package in Linux. To ensure its presence, run: apt install auditd The distro of Linux…

Cybersecurity

8 min read

BTLO — Paranoid
BTLO — Paranoid
Cybersecurity

8 min read


Sep 8

Reverse Engineering — Injection Series Part 3

This is a writeup of the Blue Team Labs Online challenge “Injection Series Part 3” I’m by no means an expert (far from it) but was able to navigate through the questions using these tools: cutter cyberchef and of course google Question 1) How many arguments does the sample take? …

Reverse Engineering

4 min read

Reverse Engineering — Injection Series Part 3
Reverse Engineering — Injection Series Part 3
Reverse Engineering

4 min read


Aug 17

Write-Up: Injection Series Part 4

Howdy y’all. This is a write up for Blue Team Labs Online challenge ‘Injection Series Part 4’. To complete this challenge, the tools I used were: PEstudio: Winitor Ghidra: Ghidra (ghidra-sre.org) CyberChef: CyberChef Additionally, all the questions can be answered via static analysis. Question 1) What is the process that…

Cybersecurity

4 min read

Write-Up: Injection Series Part 4
Write-Up: Injection Series Part 4
Cybersecurity

4 min read


Jun 22

Reverse Engineering — Another Injection

Overview This is a writeup of the blueteamlabs.online challenge “Reverse Engineering — Another Injection”. This is a pretty straightforward challenge. It can all be solved via static analysis, with some light decoding in Cyber Chef. What is the language the program is written? During the static portion of the malware analysis, I loaded the binary into PEStudio. From there…

Malware Analysis

2 min read

Reverse Engineering — Another Injection
Reverse Engineering — Another Injection
Malware Analysis

2 min read


Jun 20

Reverse Engineering — A Classic Injection

Overview This is a write up of the Security Blue Team Challenge “ Reverse Engineering — A Classic Injection” As always when dealing with malware, make sure you have an environment configured to properly examine/execute samples. To begin this challenge, I moved the file over to a Flare VM running in…

Malware Analysis

4 min read

Reverse Engineering — A Classic Injection
Reverse Engineering — A Classic Injection
Malware Analysis

4 min read


Jun 19

Macro Analysis — Melissa

This is a write up of the Melissa challenge from https://blueteamlabs.online/. Melissa aka W97M.Melissa.A (Symantec) or Virus:W32/Melissa (F-Secure) is a macro virus dates back to March 26, 1999. Background Created in 1999 by a programmer named David Lee Smith, the Melissa Virus prompted increased focus in the cybersecurity space due to…

Cybersecurity

3 min read

Macro Analysis — Melissa
Macro Analysis — Melissa
Cybersecurity

3 min read


Jun 16

Write-Up: Powershell Analysis — Keylogger

This is a write up of Blue Team Labs Online challenge, PowerShell Analysis — Keylogger (BTLO (blueteamlabs.online)) All you need for this challenge is a text editor. I prefer to use Visual Studio Code. At your own risk, feel free to change it from a .txt file to a .ps1…

Cybersecurity

3 min read

Write-Up: Powershell Analysis — Keylogger
Write-Up: Powershell Analysis — Keylogger
Cybersecurity

3 min read


Jun 16

Write-Up: Browser Forensics — Cryptominer

This is a write up of the Blue Team Labs Online challenge, Browser Forensics — CryptoMiner BTLO (blueteamlabs.online) While cryptominers are not always inherently malicious, they do present a risk to the integrity of systems in an organization. …

Blue Team

3 min read

Write-Up: Browser Forensics — Cryptominer
Write-Up: Browser Forensics — Cryptominer
Blue Team

3 min read

nosfera0x2

nosfera0x2

9 Followers

Anthropology Major turned Cybersec Consultant .

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams