Skip to content

khairulazam.net

Just my simple blog.

khairulazam.net

Just my simple blog.

  • Home
  • About Me
  • Hall of Shame
Tutorials

Generate Memory Dump from .vmss file using vmss2core

zam 31/03/2021 No Comments

Previously, I’ve encountered a problem where I’m unable to copy the .vmem file for further analysis. So, the next alternative way that we can do is to use .vmss file…

Cybersecurity

Global Community CTF: Mini Bootup by SANS – NM02

zam 20/02/2021 No Comments

Question: Let’s try connect to the domain & port given via netcat Hmm. There’s mathematic question that we need to solve. But we’re too slow on solving it.. What if…

Cybersecurity

Global Community CTF: Mini Bootup by SANS – NM01

zam 20/02/2021 No Comments

Question: Download & extract the file. You’ll see named “nm01.pcapng“ Open the pcap file using Wireshark. Usually, I sort frame with large “Length” number and view the content. On Frame…

Analysis Write-Ups

Hunting for possible attacker Cobalt-Strike infra

zam 15/10/2020 No Comments

Recently, we have an incident where suspicious traffic was observed related to external C2. Initial finding found that this IP 172.241.27.17 (172.241.24.0/21) resolved to atakaitechnologieshost; according to pDNS in Virustotal…

Cybersecurity

HackTheBox.eu – Reminiscent (Forensics 40 points)

zam 15/10/2020 No Comments

For this question, I use Volatility to solve it. You can try to use Volatility Workbench. For me, it seems like not working properly (or I’m just too noob to…

Analysis Write-Ups

Analyzing Phishing Email – Word XML File Analysis

zam 22/11/2018 No Comments

Recently I’ve observed a phishing mail as below:https://www.virustotal.com/#/file/cf027dd938f1a268f45f2ea786dc538ab47f35006fb12d0b64e0867bccf789c0/detection – clean The file seems to be clean per VT. Interestingly, on details sections, found 2 URLs under OpenXML Doc Info; section…

Analysis Write-Ups

Check bulk IP for reverse DNS (rDNS)

zam 10/06/2018 No Comments

Recently I’ve encounter list of IPs that are related to CoinHive. So I want to check for domains that tied to these IPs. We can do that by using dig…

Tutorials

Import & export installed Cygwin packages

zam 10/06/2018 1 Comment

Recently I’ve changed my workstation to new one. Previously I’ve installed bunch of Cygwin packages on my old workstation. So I thought; can I somehow migrate my installed Cygwin packages…

Analysis Write-Ups

Analyzing Oracle WebLogic attack

zam 07/06/2018 No Comments

Recently we received an alert from our WAF related to an attack towards our environment. Further review of the alert found that the attacker is using Oracle WebLogic RCE Deserialization…

Cybersecurity

Wargames 2017 – Challenge 12 : ezfile sharing

zam 19/11/2017 No Comments

Challenge 12 : ezfile sharing and the hint for this challenge: Initially, one of our teammate was fuzzing around the website and found “.git” folder. Seems related to the hint.…

Posts pagination

1 2 3 4 … 13

Ads

Recent Posts

  • From ClickFix/ClickVerify to Lumma Stealer – The Rise of Self-Pwn Techniques
  • Malcore.io Challenge – Stacy
  • Deobfuscating Malicious PowerShell Script – ClickFix PowerShell
  • Deobfuscating PHP Webshell
  • Wargames.MY 2023 CTF – Compromised

Recent Comments

  • Marnik on Extracting Quarantine Files from Windows Defender
  • Hunting for Log4j RCE (CVE-2021-44228) using RSA Netwitness | khairulazam.net on Hunting for Log4j RCE (CVE-2021-44228) using Splunk & Excel
  • Rickk on Wifi Pineapple Mark V MR3020 – Bypass verify_pineapple LED pattern
  • Joe the hash cat on Extracting password from data leaks dump files
  • Lakshminarayanan Sethumadhavan on Recover bricked TL-MR3020 via serial console

Archives

Tags

analysis apache apple bash bsd coding configure ctf cygwin debian firewall forensic hack hackthebox honeypot hunting ios linux logfile macos malware metasploit microsoft mongo mybb mysql network&hacking nginx opensource openvz openwrt pcap perl pineapple powershell pwn python ssh tplink ubuntu vmware vps windows wireshark wordpress

Categories

Analysis Write-Ups Cybersecurity Offensive Tutorials

khairulazam.net

Just my simple blog.

Copyright © All rights reserved | Blogus by Themeansar.