📦 Threat Actor Support Line

image.png

new instance empty text file

image.png

new instance empty text file with the cve exploit

image.png

with abcdefghijklmnopqrstuvwxyz1234567890

image.png

┌──(kali㉿kali)-[/mnt/…/2025-Huntress-CTF/16/4/encrypted_cve-2025-8088-sxy-poc (1)]
└─$ xxd Users/ADMINI\\~1/AppData/Local/Temp/2/tmprcj7gcsh/test.txt.tasl
00000000: 6151 3852 355e 5741 4e82 91ea 4c86       aQ8R5^WAN...L.

┌──(kali㉿kali)-[/mnt/…/2025-Huntress-CTF/16/4/encrypted_cve-2025-8088-sxy-poc (1)]
└─$ xxd Windows/TEMP/tmp625scag2/test.txt.tasl
00000000: 4290 a256 ef5d cbc9 8593 3de7 576b       B..V.]....=.Wk

┌──(kali㉿kali)-[/mnt/…/2025-Huntress-CTF/16/4/encrypted_cve-2025-8088-sxy-poc (1)]
└─$ xxd Windows/TEMP/tmpb3odq0qd/test.txt.tasl
00000000: 8762 2a7d 4d8c 88a9 e670 cf6f 3b38       .b*}M....p.o;8

┌──(kali㉿kali)-[/mnt/…/2025-Huntress-CTF/16/4/encrypted_cve-2025-8088-sxy-poc (1)]
└─$ xxd Windows/TEMP/tmpbkax0fw4/test.txt.tasl
00000000: aac5 9768 2991 d85c 321f d90c 457b       ...h)..\\2...E{

┌──(kali㉿kali)-[/mnt/…/2025-Huntress-CTF/16/4/encrypted_cve-2025-8088-sxy-poc (1)]
└─$ xxd Windows/TEMP/tmpgczo6uuh/decoy.txt.tasl
00000000: ade2 5f23 3d79 5943 ccf0 4188 b9fa f4c4  .._#=yYC..A.....
00000010: bcaf df35 05b9 2d70 7288 53d7 c23d d989  ...5..-pr.S..=..
00000020: 14a9 0922                                ..."

┌──(kali㉿kali)-[/mnt/…/2025-Huntress-CTF/16/4/encrypted_cve-2025-8088-sxy-poc (1)]
└─$ xxd Windows/TEMP/tmpma4qkmkx/test.txt.tasl
00000000: 5d79 74b9 db6c b3f5 0954 4650 ee51       ]yt..l...TFP.Q
Decryption/decoding was not the way. 

XOR with 0x42
Add random(1-255)
Mod 256

image.png

decoy.txt

exploit.py