Skip to main contentSkip to main content
Room Banner
Room Icon

Mayhem

Can you find the secrets inside the sea of mayhem?

medium

60 min

4,998

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Beneath the tempest's roar, a quiet grace,
Mayhem's beauty in a hidden place.
Within the chaos, a paradox unfolds,
A tale of beauty, in disorder it molds.

Click on the Download Task Files button at the top of this task. You will be provided with an evidence.zip file. Extract the zip file's contents and begin your analysis in order to answer the questions.

Note: Some browsers may detect the file as malicious. The zip file is safe to download with of a7d64354e4b8798cff6e063449c1e64f. In general, as a security practice, download the zip and analyze the forensic files on a dedicated lab machine, and not on your host Always handle such files in isolated, controlled, and secure environments.

Answer the questions below

What is the SID of the user that the attacker is executing everything under?

What is the Link-local IPv6 Address of the server? Enter the answer exactly as you see it.

The attacker printed a flag for us to see. What is that flag?

The attacker added a new account as a persistence mechanism. What is the username and password of that account? Format is username:password

The attacker found an important file on the server. What is the full path of that file?

What is the flag found inside the file from question 5?