YACIDR. Yet another challenge I don't recollect. Let's give this one a shot (the answer could be a number of things really...).
Go back to following the TCP stream from when ogfcmxaiaexofkdozkvz.php popped a reverse shell...
Checkout what webstats.txt is... because hey why not.
I saved the file as a text document I titled fu and stripped out all but the base64 itself. After ridding the document of nothing but base64 we are in the clear to decode it.
Turns out the file the attacker grabbed is a fairly well known RAT called c99 shell...
If my memory isn't completely off... the answer was just simply just the name of the .php script that was used to invoke c99... "webstats.php"
No comments:
Post a Comment