Home >

Huntress CTF > Medium Challenges

Back <> Next

We saw some communication to a sketchy site… here’s an export of the network traffic. Can you track it down?

Some tools like rita or zeek might help dig through all of this data!

Here we are given ’traffic.7z’ to download and extract.

For this challenge, we used Rita. Once you get Rita installed, you just need to

gunzip ./*

The files and load them into rita dataset, then create a web report with:

./rita html_report

If we look under Beacons SNI, and take a hint from the challenge about the sketchy sitewe see something that stands out as suspicious:

traffic1

Visiting the sketchy site we can retrieve the flag!

traffic2

Back <> Next