Once downloaded the files, we get a .pcap
, so itโs time to use Wireshark:
Click on Follow โ HTTP Stream:
Upon examining the HTTP streams, we can find an ncoded string in the Stream 4:
If we decode it in CyberChef it seems to be a reverse shell:
Now I follow the TCP stream and find the flag:
Once again, I decoded it in CyberChef: