← All Challenges
Silent Locker
Forensics
200 pts
standard
Challenge Description
An endpoint was isolated before full encryption. You must reconstruct the attack chain from mixed host artifacts and recover the key indicators.
Identify (after filtering decoys):
- Initial access vector.
- Real C2 domain used by locker client.
- Encryptor sample short hash.
- Timestamp of first malicious PowerShell spawn (UTC, exact).
Flag format: HackCTF{...}
Files
Hints
Submit Flag
Login to submit a flag.