Advent of Cyber 2024 Day 21: HELP ME…I’m REVERSE ENGINEERING!

Lab link.

Questions

1. What is the function name that downloads and executes files in the WarevilleApp.exe?

2. Once you execute the WarevilleApp.exe, it downloads another binary to the Downloads folder. What is the name of the binary?

3. What domain name is the one from where the file is downloaded after running WarevilleApp.exe?

4. The stage 2 binary is executed automatically and creates a zip file comprising the victim’s computer data; what is the name of the zip file?

5. What is the name of the C2 server where the stage 2 binary tries to upload files?

Aleyna Doğan
Aleyna Doğan

I'm Aleyna Doğan, a Senior Cyber Threat Intelligence Analyst specializing in cyber threat intelligence, OSINT investigations, and digital risk monitoring. This blog is where I share hands-on cybersecurity content, including TryHackMe writeups, PortSwigger labs, and practical learning resources.

Articles: 150

Leave a Reply

Your email address will not be published. Required fields are marked *