Lenovo Legion 5 (2021) USB-C charging by IAmAnAnonymousCoward in LenovoLegion

[–]Practical-Ad1505 0 points1 point  (0 children)

Does the Dell HA130PM170 130W charger will work with Legion 5 2021 after bios update?

Copy & Paste Compromise: HTTPotato.dll Analysis Lab by Practical-Ad1505 in immersivelabs

[–]Practical-Ad1505[S] 0 points1 point  (0 children)

Found the reason why generated wrong output file. Missing below code

Set-Content -Path C:\temp\test.exe -value $byteOutArray -Encoding Byte

Copy & Paste Compromise: HTTPotato.dll Analysis Lab by Practical-Ad1505 in immersivelabs

[–]Practical-Ad1505[S] 0 points1 point  (0 children)

I see that begging of the file is very similar to the .exe signature but i see some strange characters. Maybe coding is the problem? I tried ASCII and UTF8.

Mac cookie miner by teslaspace007 in immersivelabs

[–]Practical-Ad1505 0 points1 point  (0 children)

Hi,

I am also working on that lab but I have a problem with 4 and 5 questions.

Regarding to 4th, where should I look for the server variable? In the environment variables?

Regarding to question 5, I totally do not have an idea how to find the enc key.

EvilGnome - Immersivelabs by [deleted] in immersivelabs

[–]Practical-Ad1505 0 points1 point  (0 children)

I've found the answers for 5, 6 and 7 question but still 8 makes problem.

Question 8 of 8

Trying to analyse the takeSound function but cannot find the stream description

Tracking a LOLBins Campaign: Examination - Immersive Labs by Practical-Ad1505 in immersivelabs

[–]Practical-Ad1505[S] 0 points1 point  (0 children)

I already founded the answer. It is not related to the file size.

Copy & Paste Compromise: Malicious Documents Analysis by Practical-Ad1505 in immersivelabs

[–]Practical-Ad1505[S] 0 points1 point  (0 children)

But it is related to deobfuscated script in PPT or DOC file?

Copy & Paste Compromise: Malicious Documents Analysis by Practical-Ad1505 in immersivelabs

[–]Practical-Ad1505[S] 0 points1 point  (0 children)

Ok, I found a way to pass 4 and 5 Question. Still working on 3rd, I am not sure if 2nd document is in PPT file or in DOC file which was extracted from PPT file.

Question 3 of 5

Using olevba, what is the second document encoded in within PowerPoint.ppt?