Microsoft KC7

  Act II

  The Front Yard (DMZ)

Difficulty:

This challenge is located in the DMZ in the center of The Front Yard. It is called "The Great Elf Conflict". There is an elf from each faction nearby that can give context.

The Great Elf Conflict / Microsoft KC7

Clicking the globe takes you to the KC7 page of "The Great Elf Conflict". It is a "Cyber Detective Game" that will ask a series of questions and the user must use the KQL language to query data out of logs to find the answer. You will need to register a free account to get started. To get the Silver trophy, complete 2 of the 4 sub-objectives in your HHC badge. To get the Gold, you must answer all 4. The game is broken down into 4 sections, with each section corresponding to a sub-objective in your HHC badge.

Many questions in section 1 are to help you get used to the KQL language and the game so they are very easy.

Question 1: Just type "let’s do this" to complete question 1.

  Question 1:
 
let’s do this

Question 2: Once you've examined all the tables, type when in doubt take 10 to proceed.

  Question 2:
 
when in doubt take 10

Question 3: Now, let’s gather more intelligence on the employees. To do this, we can use the count operator to quickly calculate the number of rows in a table. This is helpful for understanding the scale of the data you’re working with. How many elves did you find?

  Question 3:
  KQL
Employees
| count 

The count of the Employee table returned "90"

Question 4: Can you find out the name of the Chief Toy Maker?

  Question 4:
  KQL
Employees
| where role == "Chief Toy Maker"

The query returned "Shinny Upatree" as the Chief Toy Maker.

Question 5: Type "operator" to continue.

  Question 5:
  KQL
operator

Question 6: How many emails did Angel Candysalt receive?

  Question 6:
  KQL
Email
| where recipient == "angel_candysalt@santaworkshopgeeseislands.org"
| count

Angel Candysalt received 31 emails.

Question 7: How many distinct recipients were seen in the email logs from twinkle_frostington@santaworkshopgeeseislands.org?

  Question 7:
  KQL
Email
| where sender == "twinkle_frostington@santaworkshopgeeseislands.org"
| distinct recipient
| count

32 distinct email recipients were found.

Question 8: How many distinct websites did Twinkle Frostington visit?

  Question 8:
  KQL
OutboundNetworkEvents
| where src_ip == "10.10.0.36"
| distinct url
| count

4 distinct websites were visited by Twinkle Frostington.

Question 9: How many distinct domains in the PassiveDns records contain the word green?

  Question 9:
  KQL
PassiveDns
| where domain contains "green"
| distinct domain
| count

10 domains in the PassiveDns log contain the word "green".

Question 10: How many distinct URLs did elves with the first name Twinkle visit?

  Question 10:
  KQL
let twinkle_ips = Employees 
| where name has "Twinkle"
| distinct ip_addr;
OutboundNetworkEvents  
| where src_ip in (twinkle_ips)  
| distinct url
| count

8 distinct URLs were visited by elves with the first name "Twinkle".

Enter the last solution "8" into the KQL 101 sub-objective in your HHC badge to complete it.

Section 2: Operation Surrender has 7 questions.

Question 1: Type surrender to get started!

  Question 1:
  KQL
surrender

Question 2: Who was the sender of the phishing email that set this plan into motion?

  Question 2:
  KQL
Email
| where subject contains "Surrender"
| distinct sender

I looked to see if any emails contained the word "surrender" in their subject line. There was a hit on the email address "surrender@northpolemail.com".

Question 3: How many elves from Team Wombley received the phishing email?

  Question 3:
  KQL
Email
| where subject contains "Surrender"
| distinct recipient
| count

I counted the distinct recipients of emails with "surrender" in the subject line. There were 22 of them.

Question 4: What was the filename of the document that Team Alabaster distributed in their phishing email?

  Question 4:
  KQL
Email
| where subject contains "Surrender"
| distinct link

This returns several different links but they all have the same filename "Team_Wombley_Surrender.doc".

Question 5: Who was the first person from Team Wombley to click the URL in the phishing email?

  Question 5:
  KQL
Employees
| join kind=inner (
    OutboundNetworkEvents
) on $left.ip_addr == $right.src_ip
| where url contains "Team_Wombley_Surrender.doc"
| project name, ip_addr, url, timestamp
| sort by timestamp asc
| take 1

This query returns the list of users that clicked the phishing document, but sorted by timestamp ascending. I also only care about the first row, so I added a "take 1" to only return the answer: "Joyelle Tinseltoe".

Question 6: What was the filename that was created after the .doc was downloaded and executed?

  Question 6:
  KQL
ProcessEvents
| where timestamp between(datetime("2024-11-27T14:11:45Z") .. datetime("2024-11-27T14:12:45Z"))
| where hostname == "Elf-Lap-W-Tinseltoe"

I checked the Process events on Joyelle Tinseltoe's laptop that occured during the timeframe in question. There were only 2: opening the phishing doc itself, and then a file named "keylogger.exe".

Question 7: To obtain your flag use the KQL below with your last answer!

  Template
  KQL
let flag = "Change This!";
let base64_encoded = base64_encode_tostring(flag);
print base64_encoded
  Question 7:
  KQL
let flag = "keylogger.exe";
let base64_encoded = base64_encode_tostring(flag);
print base64_encoded

The string "keylogger.exe" base64 encoded is "a2V5bG9nZ2VyLmV4ZQ==".

Enter "a2V5bG9nZ2VyLmV4ZQ==" in the Operation Surrender sub-objective in your HHC badge to complete section 2.

Question 1: Type snowfall to begin

  Question 1:
  KQL
snowfall

Question 2: What was the IP address associated with the password spray?

  Question 2:
  KQL
AuthenticationEvents
| where result == "Failed Login"
| summarize FailedAttempts = count() by src_ip, result
| where FailedAttempts >= 5
| sort by FailedAttempts desc

I queried for failed login attempts grouped by IP. There was 1 IP address that had 4419 failed login attempts which is about 15 times higher than the next nearest IP. The IP that was spraying passwords was "59.171.58.12".

Question 3: How many unique accounts were impacted where there was a successful login from 59.171.58.12?

  Question 3:
  KQL
AuthenticationEvents
| where result == "Successful Login" and src_ip == "59.171.58.12"
| distinct username
| count

I counted successful logins from the spraying IP address only counting the distinct usernames. It was 23 distinct accounts impacted by the spray.

Question 4: What service was used to access these accounts/devices?

  Question 4:
  KQL
AuthenticationEvents
| where result == "Successful Login" and src_ip == "59.171.58.12"
| distinct description
| project description

The description of the events all mention RDP. For example "User successfully logged onto Elf-Lap-A-Ribbonson via RDP." RDP was the service used.

Question 5: What file was exfiltrated from Alabaster’s laptop?

  Question 5
  KQL
AuthenticationEvents
| where result == "Successful Login" and src_ip == "59.171.58.12" and hostname == "Elf-Lap-A-Snowball"

This query looks for the timestamp of a successful login to Alabster's laptop from the attacker's IP. The timestamp of the login was "2024-12-11T01:39:50Z". Use this timestamp in the next query

  Question 5
  KQL
ProcessEvents
| where hostname == "Elf-Lap-A-Snowball"
| where timestamp >= datetime("2024-12-11T01:39:50Z")

The query returned a series of events. One of those events is the attacker copying a file called "Secret_Files.zip" to a network share: "copy C:\Users\alsnowball\AppData\Local\Temp\Secret_Files.zip \\wocube\share\alsnowball\Secret_Files.zip". The file exfiltrated was "Secret_Files.zip".

Question 6: What is the name of the malicious file that was run on Alabaster's laptop?

Using the last query from Question 5, there was another process command line that copied a file from a network share to Alabaster's laptop named "EncryptEverything.exe". This file is executing using a base64 encoded powershell script. The file executed was "EncryptEverything.exe".

Question 7: Submit the base64 encoded answer to question 6.

  Question 7:
  KQL
let flag = "EncryptEverything.exe";
let base64_encoded = base64_encode_tostring(flag);
print base64_encoded

The string "EncryptEverything.exe" base64 encoded is "RW5jcnlwdEV2ZXJ5dGhpbmcuZXhl". Submit this to the Operation Snowfall sub-objective in your badge to complete section 3.

Question 1: Type stay frosty to begin

  Question 1:
  KQL
stay frosty

Question 2: What was the timestamp of first phishing email about the breached credentials received by Noel Boetie?

  Question 2:
  KQL
Email
| where recipient == "noel_boetie@santaworkshopgeeseislands.org"
| where subject contains "credentials"
| take 1

This query returns the first email that fits the criteria of having a recipient of noel_boetie@santaworkshopgeeseislands.org and the subject line containing the word "credentials". The timestamp of this is "2024-12-12T14:48:55Z".

Question 3: When did Noel Boetie click the link to the first file?

  Question 3:
  KQL
Employees
| join kind=inner (
    OutboundNetworkEvents
) on $left.ip_addr == $right.src_ip
| where name == "Noel Boetie"
| project name, ip_addr, url, timestamp
| sort by timestamp asc

The outbound event by user Noel Boetie that connected to the was "2024-12-12T15:13:55Z". This was found by joining the Employee table and the OutboundNetworkEvents table by Noel's IP address.

Question 4: What was the IP for the domain where the file was hosted?

  Question 4:
  KQL
PassiveDns 
| where domain == "holidaybargainhunt.io"
| distinct ip

The DNS entry for the malicious file domain "holidaybargainhunt.io" was 182.56.23.122.

Question 5: Let’s take a closer look at the authentication events. I wonder if any connection events from 182.56.23.122. If so what hostname was accessed?

  Question 5:
  KQL
AuthenticationEvents
| where src_ip == "182.56.23.122"

Looking at login events from the attacker's IP address shows there was a successful login to WebApp-ElvesWorkshop from the attacker's IP via RDP. The hostname was "WebApp-ElvesWorkshop".

Question 6: What was the script that was run to obtain credentials?

  Question 6:
  KQL
ProcessEvents
| where hostname == "WebApp-ElvesWorkshop"

The query returned some process command lines that were executed. Powershell script "Invoke-Mimikatz.ps1" was run to dump loginpasswords.

Question 7: What is the timestamp where Noel executed the file?

  Question 7:
  KQL
ProcessEvents
| where hostname == "Elf-Lap-A-Boetie"
| where timestamp between (datetime("2024-12-12T15:13:55Z") .. datetime("2024-12-12T15:14:55Z"))

From question 3, we know Noel clicked the link at timestamp 2024-12-12T15:13:55Z. The echo.exe program was executed within one minute of the clicked email. It was executed at timestamp 2024-12-12T15:14:38Z.

Question 8: What domain was the holidaycandy.hta file downloaded from?

  Question 8:
  KQL
OutboundNetworkEvents
| where url contains "holidaycandy.hta"

The url file "holidaycandy.hta" was http://compromisedchristmastoys.com/holidaycandy.hta. So the domain was "compromisedchristmastoys.com".

Question 9: What was the first file that was created after extraction?

  Question 9:
  KQL
ProcessEvents
| where hostname == "Elf-Lap-A-Boetie" and process_commandline contains "frosty.zip"

The above query shows that frosty.zip was extracted at 2024-12-24T17:19:45Z. Look at File Creation events after 2024-12-24T17:19:45Z.

  Question 9:
  KQL
ProcessEvents
| where hostname == "Elf-Lap-A-Boetie"
| where timestamp >= datetime("2024-12-24T17:19:45Z")

The next file created was "sqlwriter.exe".

Question 10: What is the name of the property assigned to the new registry key?

From the query in question 9, there is a process event that sets a property on a registry key.

  Question 10:
  Command Line
New-Item -Path "HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" -Name "MS SQL Writer" -Force | New-ItemProperty -Name "frosty" -Value "C:\Windows\Tasks\sqlwriter.exe" -PropertyType String -Force

The property name was "frosty".

Question 11: Submit base64 encoded answer from question 10.

  Question 11:
  KQL
let finalflag = "frosty";
let base64_encoded = base64_encode_tostring(finalflag);
print base64_encoded

The "frosty" base64 encoded is "ZnJvc3R5".

Submit "ZnJvc3R5" to the Echoes in the Frost sub-objective for this objective to complete it and get the Gold trophy!

 Snowball ShowdownWhere to next?Santa Vision 

Holiday Hack Challenge 2024 Report - Cody Travis <cody@chillaspect.com>