> For the complete documentation index, see [llms.txt](https://kunalwalavalkar.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://kunalwalavalkar.gitbook.io/write-ups/blue-team-labs-online/the-planets-prestige.md).

# The Planet's Prestige

## What is the email service used by the malicious actor?

To find the email service used by the malicious actor we need to check the `Received` field after opening the email in a text-editor.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FKbFbUgCgIw385bISui6i%2F1.png?alt=media&amp;token=7e819808-5e36-4b91-bd96-eae700279f37" alt=""><figcaption></figcaption></figure>

### Answer

```
emkei.cz
```

## What is the Reply-To email address?

If we open the file using [Thunderbird](https://www.thunderbird.net/en-US/), we can find the `Reply-To` email address.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FZmynxWKZV7a6hTfQu2RM%2F2.png?alt=media&amp;token=4bfe7fca-4e96-40c8-8010-1e2cacff5475" alt=""><figcaption></figcaption></figure>

### Answer

```
negeja3921@pashter.com
```

## What is the filetype of the received attachment which helped to continue the investigation?

Let's open the PDF file attached to the email.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2Fc8zrPVMt68hVEIcVwnSZ%2F3.png?alt=media&amp;token=e13fe75d-f25c-49e6-9754-19fdafd3310a" alt=""><figcaption></figcaption></figure>

So the file isn't opening. Maybe it is not really a PDF.

Using the `file` utility we can check the actual format of the file.

```
$ file PuzzleToCoCanDa.pdf 
PuzzleToCoCanDa.pdf: Zip archive data, at least v2.0 to extract
```

### Answer

```
zip
```

## What is the name of the malicious actor?

Now that we know it is a ZIP file, we can rename it to `PuzzleToCoCanDa.zip` and then unzip it.

```
$ unzip PuzzleToCoCanDa.pdf
Archive:  PuzzleToCoCanDa.pdf
  inflating: PuzzleToCoCanDa/DaughtersCrown  
  inflating: PuzzleToCoCanDa/GoodJobMajor  
  inflating: PuzzleToCoCanDa/Money.xlsx  
```

We can see that the ZIP file contains a file called `GoodJobMajor`.

If we use the `exiftool` utility on that file to check the metadata we can find the name of the malicious actor.

```
$ exiftool GoodJobMajor 
ExifTool Version Number         : 12.42
File Name                       : GoodJobMajor
Directory                       : .
File Size                       : 28 kB
File Modification Date/Time     : 2021:01:26 11:14:22-05:00
File Access Date/Time           : 2023:09:28 11:06:29-04:00
File Inode Change Date/Time     : 2023:09:28 10:51:42-04:00
File Permissions                : -rw-rw-r--
File Type                       : PDF
File Type Extension             : pdf
MIME Type                       : application/pdf
PDF Version                     : 1.5
Linearized                      : No
Author                          : Pestero Negeja
Producer                        : Skia/PDF m90
Page Count                      : 1
```

### Answer

```
Pestero Negeja
```

## What is the location of the attacker in this Universe?

On opening the `Money.xlsx` file, we can see that there are two sheets: `Sheet1` and `Sheet3`.&#x20;

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FNXneTklt5AHkr12IjIkY%2F4.png?alt=media&amp;token=9ab15bf7-bce6-41b1-b209-188e13bf017d" alt=""><figcaption></figcaption></figure>

Let's covert both the sheets to text files so that we can view the content better.

If we open the `Sheet3.txt` file we can see some text that appears to be encrypted.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2Fqt59g7wHlh6MEHxPtyjh%2F5.png?alt=media&amp;token=987cb58c-421d-4534-bb0b-f79e2964b20f" alt=""><figcaption></figcaption></figure>

The `==` at the end indicates that the encryption is Base64.

We can use Cyberchef to decrypt the text.

<figure><img src="https://1586847736-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FtSZ40gLWhBDTzPEgHsVB%2Fuploads%2FyecwOTkzhcgWdI0qM596%2F6.png?alt=media&amp;token=2c449430-4a41-4465-abc6-423dbd50952e" alt=""><figcaption></figcaption></figure>

### Answer

```
The Martian Colony, Beside Interplanetary Spaceport
```

## What could be the probable C\&C domain to control the attacker’s autonomous bots?

The attacker's name is `Pestero Negeja` and the reply-to email is `negeja3921@pashter.com` so we can guess the C\&C domain used by the attacker.

### Answer

```
pashter.com
```
