← All Challenges
Invoice Ghost
Forensics
100 pts
standard
Challenge Description
The finance department processed a suspicious vendor payment after an email thread changed bank details. You are asked to investigate whether mailbox compromise happened and identify the fraud indicators.
Recover (ignore decoys):
- The actual attacker-created mailbox rule name.
- The first malicious external login IP tied to rule creation.
- The spoofed sender domain used in the successful fraud thread.
- The fraudulent payment amount.
- The mail folder used to hide forwarded messages.
Flag format: HackCTF{ipaddress_domain_amount_folder-name}
Files
Hints
Submit Flag
Login to submit a flag.