n0St3p0nSyn@ck

n0_st3p_0n_Syn@ck

View on GitHub

OpTinselTrace-1

OpTinselTrace-1

Description:

An elf named "Elfin" has been acting rather suspiciously lately. He's been working at odd hours and seems to be bypassing some of Santa's security protocols. Santa's network of intelligence elves has told Santa that the Grinch got a little bit too tipsy on egg nog and made mention of an insider elf! Santa is very busy with his naughty and nice list, so he’s put you in charge of figuring this one out. Please audit Elfin’s workstation and email communications.

1: What is the name of the email client that Elfin is using?

Answer: eM Client

2: What is the email the threat is using?

Answer: definitelynotthegrinch@gmail.com

3: When does the threat actor reach out to Elfin?

Rapidly realizing that using the sqlite3 cli was going to take a long time I installed **db browser for sqlite**; this makes it much faster to search through the .dat files in order to find interesting information.

Answer: 2023-11-27 17:27:26

4: What is the name of Elfin’s boss?

Answer: elfuttin bigelf

5: What is the title of the email in which Elfin first mentions his access to Santas special files?

Answer: re: work

6: The threat actor changes their name, what is the new name + the date of the first email Elfin receives with it?

Answer: Wendy Elflower, 2023-11-28 10:00:21

7: What is the name of the bar that Elfin offers to meet the threat actor at?

Answer: SnowGlobe

8: When does Elfin offer to send the secret files to the actor?

Answer: 2023-11-28 16:56:13

9: What is the search string for the first suspicious google search from Elfin? (Format: string)

Answer: how to get around work security

10: What is the name of the author who wrote the article from the CIA field manual?

Answer: Joost Minnaar

11: What is the name of Santas secret file that Elfin sent to the actor?

Answer: santa-deliveries.zip

12: According to the filesystem, what is the exact CreationTime of the secret file on Elfins host?

Answer: 2023-11-28 17:01:29

13: What is the full directory name that Elfin stored the file in?

Answer: C:\users\Elfin\Appdata\Roaming\top-secret

14: Which country is Elfin trying to flee to after he exfiltrates the file?

Answer: Greece

15: What is the email address of the apology letter the user (elfin) wrote out but didn’t send?

Answer: Santa.claus@gmail.com

16: The head elf PixelPeppermint has requested any passwords of Elfins to assist in the investigation down the line. What’s the windows password of Elfin’s host?

python3 ./secretsdump.py -sam /path/to/SAM -security /path/to/SYSTEM -system /path/to/SYSTEM LOCAL -outputfile elfidence_hashes

[*] Target system bootKey: 0x1679d0a0bee2b5804325deeddb0ec9fe
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
WDAGUtilityAccount:504:aad3b435b51404eeaad3b435b51404ee:95199bba413194e567908de6220d677e:::
Elfin:1001:aad3b435b51404eeaad3b435b51404ee:529848fe56902d9595be4a608f9fbe89:::
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] Cleaning up...

529848fe56902d9595be4a608f9fbe89:Santaknowskungfu ```

Answer: Santaknowskungfu