kali@kali: ~/hackerverse-dfir — Terminal

[ EC-Council Hackerverse CTF — DFIR Writeup ]

cat README.md
Event : EC-Council Hackerverse CTF — Digital Forensics & Incident Response (DFIR) Participant: Asahel Kipkemei Level : Journeyman Issued : 3rd Oct 2026 | CPE Credits: 1 | Certificate No.: 1998 Platform : EC-Council lab (Kali Linux + Windows Forensic VM) Sections : 1) Cryptic Canvas 2) Network Forensics (Synixon) 3) Autopsy / Chrome / LSASS 4) Ransomware
display certificate.png
EC-Council Hackerverse certificate of participation
kali@kali: ~/Stego Artifacts

[1] Level 1 — Cryptic Canvas

# Challenge 1 — The Hidden Voice (Audio.wav)

file Audio.wav; exiftool Audio.wav; strings Audio.wav | head -30
Audio.wav: RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11050 Hz
# Uploaded the WAV to an online Morse audio decoder (adaptive). Output used only two symbols: # ----- = 0 and .---- = 1 → the Morse was a carrier for a binary stream.
echo "0110011001101100011000010110011101111011...01111101" | perl -lpe '$_=pack("B*",$_)'
Flag: flag{binary_audio_secrets} (6-5-7 letters, matches flag{xxxxxx_xxxxx_xxxxxxx})

# Challenge 2 — JFIF magic bytes (Cat.jpg)

Answer: FF D8 FF E0 # FF D8 = SOI, FF E0 = APP0 → "JFIF"
binwalk -e Cat.jpg
Extractor Exception: ... use '--run-as=root'
steghide extract -sf Cat.jpg
steghide: the file format of the file "Cat.jpg" is not supported.
file Cat.jpg; exiftool Cat.jpg
Cat.jpg: data Error : File format error # header corrupted → repair a COPY
cp Cat.jpg Cat_fixed.jpg && chmod u+w Cat_fixed.jpg printf '\xff\xd8\xff\xe0' | dd of=Cat_fixed.jpg bs=1 seek=0 conv=notrunc printf '\x4a\x46\x49\x46\x00' | dd of=Cat_fixed.jpg bs=1 seek=6 conv=notrunc file Cat_fixed.jpg
steghide extract -sf Cat_fixed.jpg
Enter passphrase: (now prompts → valid JPEG with embedded data) wrote extracted data to "flag.txt".
cat flag.txt | base64 -d
flag.txt : Q1RGe3N0ZWcwXzFzX2NvMGx9 Flag : CTF{steg0_1s_co0l}

# Challenges 4 & 5 — Encoded_Dump.txt (decoys + real secret)

cat Encoded_Dump.txt
Hint 1 (b64 → reversed) : ".eno tsuj si eurt ,syoced era owT" → two strings are decoys Hint 2 (b64) : Process: Base58 → ROT13 → BASE64 → XOR (Hex Key: 342120)
Challenge 4 answer: Base58 → ROT13 → Base64 → XOR (Hex Key: 342120)
python3 -c "import base58,base64,codecs;b=base58.b58decode('2A6fz3V1RQkk4RgpctzF5bPYFCaCXsLLb7Jxot4');r=codecs.decode(b.decode(),'rot13');d=base64.b64decode(r);k=bytes.fromhex('342120');print(bytes(c^k[i%3] for i,c in enumerate(d)).decode())"
pz1up1c2KJWHr1A5IJWVsHE2HJIq → cm1hc1p2XWJUe1N5VWJIfUR2UWVd → rmasZv]bT{SyUbH}DvQe] → Challenge 5 flag: FLAG{ViCtOrYaChIeVeD} # CyberChef equivalent: From Base58 → ROT13 → From Base64 → XOR (Hex 342120)
kali@kali: ~/Pcap Artifacts

[2] Network Forensics — Synixon ChatOps breach

# synixon_breach_capture.pcapng, exported as plain-text dissections. Attacker: 10.10.1.2 → Victim: 10.10.1.111
tshark -r synixon_breach_capture.pcapng -Y http.request -T fields -e frame.number -e ip.src -e http.request.method -e http.host -e http.request.uri
tshark -r synixon_breach_capture.pcapng -Y websocket -T fields -e frame.number -e ip.src -e text
tshark -r synixon_breach_capture.pcapng -q -z follow,tcp,ascii,N # reverse-shell stream
#QuestionAnswerEvidence (frame)
1Attacker signup email[fill in from POST body]POST / (236, 303) — form body not in export
2Supervisor email reset via WebSocket[fill in from WS text]WebSocket frames 422–476, 570–573 (port 5000)
3LFI debug pagedebug-view.php1164 /syni_dev/debug-view.php, 1168 ?file=history.php
4Log file read via LFIlegacy_dev_keys.log1186 ?file=../../../../../../../opt/syni_dev/legacy_dev_keys.log (1176 read /etc/passwd)
5New admin account email[fill in from POST / WS]Check POSTs 1312, 1631, 1901+ and WS 1259–1286
6New web service port176451321 onward, 10.10.1.2 → 10.10.1.111:17645
7Hidden admin login pageadmin_login_ERHG23W2.php1597 GET, 1631 POST, 1635 dashboard
8Legacy feedback service port50001826 GET /legacy-feedback on :5000
9Reverse-shell callback10.10.1.2:89982249–2251 (victim connects out to attacker :8998)
10Root flagflag{A1EL2L8P}2299 / 2307 — cat /home/flag.txt
Shell session replayed: whoami (typo "whomai" → /usr/bin/whoami → root) → find / -name flag.txt (first typo'd as /usr/bind/find) → /home/flag.txt → cat. Note: rows 1, 2 and 5 live in HTTP/WebSocket bodies that the text export collapsed; pull them with the tshark commands above.
kali@kali: ~/chrome_cracker

[3] Autopsy — Chrome + LSASS (chaincrypto.com)

# Guidance taken from the chat.deepseek.com session. Tools on the Windows Forensic VM: Autopsy 4.21.0, FTK Imager, x32dbg/x64dbg, Wireshark, Sysinternals.
unzip chrome_cracker.zip # right-click → Extract All on the VM Desktop
lsass.DMP | Chrome profile (User Data / Default)
# Autopsy: New Case → Add Data Source → Logical Files → select the extracted chrome_cracker folder → ingest.
#QuestionMethod / answer
1Tool used to extract MasterKey from lsass.DMPSuggested by DeepSeek: pypykatz (DPAPI masterkey parsing from minidump) — mimikatz is the alternative. Confirm against your submitted answer.
2File holding Base64 encrypted_keyLocal State (JSON in Chrome User Data)
3Attacker's Windows usernameAutopsy file tree → C:\Users\<username>\AppData\Local\Google\Chrome\User Data\ — the folder name. [record value]
4First 10 chars of MasterKeypypykatz lsa minidump lsass.DMP (dpapi section) → masterkey hex, first 10 chars. [record value]
5First 10 chars of Final Secret KeyBase64-decode encrypted_key (strip "DPAPI" prefix), decrypt with the MasterKey → AES key. [record value]
6Username / password for chaincrypto.comOpen Login Data (SQLite, logins table) → decrypt password blob with AES-GCM using the Final Secret Key. [record value]
Challenges 3 and 4 (username → MasterKey) are the pivot: the username locates the profile, and the MasterKey unlocks challenges 5 and 6. Values for rows 3–6 were not part of the chat, so they are left for you to fill in from your lab output.
kali@kali: ~/ransomware

[4] Ransomware challenge

NOT SOLVED. I was unable to solve the final question on the ransomware challenge. No flag or answer was recovered for it, and none is claimed in this writeup.
kali@kali: ~/hackerverse-dfir — summary
cat tools_used.txt
Kali: file, exiftool, strings, xxd, dd, printf, binwalk, steghide, perl, python3 (base58), tshark, Wireshark Online/other: Morse audio decoder, CyberChef Windows VM: Autopsy 4.21.0, pypykatz (suggested), SQLite viewer Lessons: broken magic bytes defeat stego tools — repair a copy first; "unsupported format" is itself a clue; always follow TCP streams for reverse shells.
exit