Created: 28/02/2024 15:36 Last Updated: 28/02/2024 09:07
Category: Threat Intel Tags: BloodHound, Github, Mimikatz, OSINT, T1496, T1071, T1078
You, as a soc analyst, have been tasked by a client whose network was compromised and brought offline to investigate the incident and determine the attacker's identity.
Incident responders and digital forensic investigators are currently on the scene and have conducted a preliminary investigation. Their findings show that the attack originated from a single user account, probably, an insider.
Investigate the incident, find the insider, and uncover the attack actions.
Tools - Google Maps - Google Image search - sherlock
Q1: File -> Github.txt: What is the API key the insider added to his GitHub repositories?
We're provided with these 3 files, 1 text file, 1 jpeg file and 1 png file
The content of text file is a URL
It is a github repo of the EMarseille99 user
Most of the repo were forked but there is one project that this user had created which is Project-Build---Custom-Login-Page

Nothing special about fsociety.js, its just a logo from the infamous Mr Robot series

But on the other hand, There is an API key paremeter was set at the first line of Login Page.js

aJFRaLHjMXvYZgLPwiJkroYLGRkNBW
Q2: File -> Github.txt: What is the plaintext password the insider added to his GitHub repositories?
Scroll to line 46~59, I found user credentials.
Decode the password with cyberchef

PicassoBaguette99
Q3: File -> Github.txt: What cryptocurrency mining tool did the insider use?
I couldn't find anything about the mining tool on the Project-Build---Custom-Login-Page repo so I went to search for other repos, Most of them are cybersecurity tools that widely used but there is one repo that says something about Crypto which is xmrig
After reading the README.md, It is confirmed that this is the crypto mining tool that we're searching for

xmrig
Q4: What university did the insider go to?
I used the email to search on google and found Linkedin profile that belongs to this user
And in the Linkedin there is an education section that list the university this user went to

Sorbonne
Q5: What gaming website the insider had an account on?
Its time to use sherlock to hunt down the social media accounts but all of them couldn't be answered
So I went to other tool like Namechk
And there it is! This username exists on Steam

steam
Q6: What is the link to the insider Instagram profile?
Just searching by username, The first link should be it

https://www.instagram.com/emarseille99/
Q7: Where did the insider go on the holiday? (Country only)
On the Instagram, This picture was posted with a holiday caption so This might be the place so I used Google Lens to search where it is
And the result is Marina Bay Sands in Singapore

Singapore
Q8: Where is the insider family live? (City only)
On her Instragram, there are 2 pictures that the insider mentioned her family
I assumed that the second image is easier to search online so I used that
The result says it's Burj Khalifa, It might be the highest tower that appeared on the image and It is located in Dubai

Dubai
Q9: File -> office.jpg: You have been provided with a picture of the building in which the company has an office. Which city is the company located in?
Here is the image and I uploaded it for the Google Image Search to find the answer for me
And it says Birmingham New Street, on the office.jpg also showed the Grand Central and Odeon cinema
So both building confirmed the search result.

Birmingham
Q10: File -> Webcam.png: With the intel, you have provided, our ground surveillance unit is now overlooking the person of interest suspected address. They saw them leaving their apartment and followed them to the airport. Their plane took off and has landed in another country. Our intelligence team spotted the target with this IP camera. Which state is this camera in?
This is Webcam.jpg, by taking a look you can see it's from a webcam according to filename and this picture was taken from EarthCam platform
Before I go to EarthCam to find this camera, I searched on Google Image first and found that this place is a University of Notre Dame
And There It is, same view confirmed now we need to know the state of this university
Indiana it is

Indiana
