Click Here For Free Bricks
- ID:
1
- Category:
Forensics
- Value:
100
- Solves:
152
- Solved By Me:
False
- State:
visible
- Attribution:
non_gonzo
- Tags:
Wireshark, medium
- Files:
https://ctf.umasscybersec.org/files/c1da2e0787ebd99d305ba8fa3bb263e6/click-here-for-free-bricks.zip?token=eyJ1c2VyX2lkIjoyMzE3LCJ0ZWFtX2lkIjoxMTY5LCJmaWxlX2lkIjoyfQ.adnYNA.7wa7I98c4-rzZ-AeAK4RQ6fmgOw
Description
Hey! A man was caught with malware on his PC in Lego City. Luckily, we were able to get a packet capture of his device during the download. Help Lego City Police figure out the source of this malicious download.
The flag for this challenge is the name of this virus on VirusTotal under the details tab with the format UMASS{[String]_[Sha256 Hash]}. For example if your hash is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824, there will be a virus name under the details tab with a format similar to ForensicsChallenge_2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824, where "ForensicsChallenge" is an arbitrary string.
Use flagCheck to input the flag you get from the challenge to get the actual flag
Author: UMass Cybersecurity