0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

Event-Viewing picoCTF (Writeup)

0
Posted at

【picoCTF】[Event-Viewing] Writeup

問題概要

  • Category: Forensics

Description:

One of the employees at your company has their computer infected by malware! Turns out every time they try to switch on the computer, it shuts down right after they log in.
The story given by the employee is as follows:
They installed software using an installer they downloaded online
They ran the installed software but it seemed to do nothing
Now every time they bootup and login to their computer, a black command prompt screen quickly opens and closes and their computer shuts down instantly.
See if you can find evidence for the each of these events and retrieve the flag (split into 3 pieces) from the correct logs!
Download the Windows Log file here

日本語訳:

御社の従業員の一人のパソコンがマルウェアに感染してしまいました!どうやら、パソコンの電源を入れるたびに、ログイン直後にシャットダウンしてしまうようです。その従業員からの報告は以下の通りです:

  • オンラインでダウンロードしたインストーラーを使ってソフトウェアをインストールした
  • インストールしたソフトウェアを実行したが、何も動作していないようだった
  • 現在、パソコンを起動してログインするたびに、黒いコマンドプロンプトの画面が瞬時に開いて閉じ、すぐにシャットダウンしてしまう。

これらの事象それぞれについて証拠を見つけ、正しいログからフラグ(3つに分割されています)を回収してください!
Windowsログファイルはこちらからダウンロードしてください。


解法のプロセス(アプローチ)

1. イベントビューアーによるログの確認とアタリづけ

まずはダウンロードしたファイル(Windows_Logs.evtx)をWindows標準の「イベントビューアー」で開きます。

image.png

開いてみると、非常に多くのログが記録されていることがわかります。これを1つずつ探すのは非効率なので、見たい内容を端的に絞り込む必要があります。
ここで役に立つのがイベントIDです。

問題文のシナリオから、以下の3つのアクションが今回のキーになります。

  1. ソフトウェアのインストール(イベントID: 1033)
  2. 自動実行のためのレジストリ変更(イベントID: 4657)
  3. システムのシャットダウン(イベントID: 1074)

2. ログのフィルタリングと証拠の収集

画面右側の「操作」ペインから「現在のログをフィルター」をクリックすると、以下のような画面が表示されます。

image.png

「<すべてのイベント ID>」と書かれた箇所に先ほど挙げたIDを入力し、ログを絞り込んでいきます。

Part 1: インストールの痕跡(ID: 1033)

image.png
ログの詳細タブを確認すると、不自然な文字列 cGljb0NURntFdjNudF92aTN3djNyXw== が見つかります。

Part 2: レジストリ変更の痕跡(ID: 4657)

image.png
同様に確認すると、2つ目の文字列 MXNfYV9wcjN0dHlfdXMzZnVsXw== が隠されています。

Part 3: シャットダウンの痕跡(ID: 1074)

image.png
ここにも、3つ目の文字列 dDAwbF84MWJhM2ZlOX0= が残されていました。

末尾の == や = といったパディング(余白埋め)の特徴から、これらの文字列が Base64 でエンコードされていることがわかります。

3. Base64のデコード

集めた3つの文字列を順番通りに結合させます。
結合した文字列:cGljb0NURntFdjNudF92aTN3djNyXw==MXNfYV9wcjN0dHlfdXMzZnVsXw==dDAwbF84MWJhM2ZlOX0=

便利なデータ変換ツールである CyberChef を開き、デコードしてみましょう。

  1. Input: 結合した文字列を入力します。
  2. Recipe: From Base64 をダブルクリックして適用します。

image.png

無事にエンコードが解け、隠されていたフラグが出現しました!

Flag:
picoCTF{Ev3nt_vi3wv3r_1s_a_pr3tty_us3ful_t00l_81ba3fe9}


お疲れさまでした!

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?