> For the complete documentation index, see [llms.txt](https://adarshsr.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://adarshsr.gitbook.io/writeups/walk-through/advent-of-cyber-2024/day-21.md).

# Day 21

HELP ME...I'm REVERSE ENGINEERING!

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2FoHPB0rv4uEY6w8qlUvn1%2FScreenshot%202024-12-22%20192639.png?alt=media&amp;token=572b21d0-773a-4ed2-9857-f8dd8cec70fc" alt=""><figcaption></figcaption></figure>

Welcome to **Day 21 of Advent of Cyber 2024** 🎄

Today’s challenge dives into the fascinating world of **reverse engineering** using **ILSpy**.

**Introduction to Reverse Engineering**

Reverse engineering involves deconstructing software or binaries to understand their behavior. It’s a vital cybersecurity technique used to:

* Identify malware functionality.
* Detect security flaws in applications.
* Attribute binaries to specific threat actors.

Lets Begin:

We have an exe named  `WarevilleApp.exe`

We need to decompile this and find the answers to questions:

Open this exe in ILSpy;

First we need to find the function name that downloads and executes files in the WarevilleApp.exe:

expand the Form1 section and inspect :

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2FHlbusKvl96f3XEdrGCF7%2FScreenshot%202024-12-22%20190239.png?alt=media&amp;token=3aa75f8c-349b-41ee-98c0-52df1c9fd225" alt=""><figcaption></figcaption></figure>

Here we can find the `DownloadandExecute()` function used to download `explorer.exe` from `mayorc2.thm`

Lets run this `WarevilleApp.exe:`

When we run this a file named exlorer.exe will be downloaded, we need to decompile that to find more answers:

Open `explorer.exe` in ILSpy:

Visit the Pictures folder to check the zip file:

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2Fdir3KD8gNbhydPIUwu2f%2FScreenshot%202024-12-22%20191304.png?alt=media&amp;token=fa164928-36bf-4ff3-a6ca-006a5c35b8ba" alt=""><figcaption></figcaption></figure>

We can see the zip file named CollectedFiles.zip

and finally to find the name of the C2 server:

check the **UploadFiletoServer** function of `explorer.exe`

<figure><img src="https://1187393604-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fy6N5yjIFH53MlFGmbHMl%2Fuploads%2FirWcBqgHZwVwXyI4dhjZ%2FScreenshot%202024-12-22%20191322.png?alt=media&amp;token=d7154555-20a1-4fcc-9e2a-4c3d020df0c8" alt=""><figcaption></figcaption></figure>

We can see the server name: `anonymousc2.thm`

### Questions:

1.What is the function name that downloads and executes files in the WarevilleApp.exe?

A: **DownloadAndExecuteFile**

2.Once you execute the WarevilleApp.exe, it downloads another binary to the Downloads folder. What is the name of the binary?

A: **explorer.exe**

3.What domain name is the one from where the file is downloaded after running WarevilleApp.exe?

A: **mayorc2.thm**

4.The stage 2 binary is executed automatically and creates a zip file comprising the victim's computer data; what is the name of the zip file?

A: **CollectedFiles.zip**

5.What is the name of the C2 server where the stage 2 binary tries to upload files?

A: **anonymousc2.thm**

***Stay tuned for Day 22 and Happy Hacking*** 🎄

***Thank you!***
