> For the complete documentation index, see [llms.txt](https://mapol.gitbook.io/home/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mapol.gitbook.io/home/blog/ctf/cryptolockerme.md).

# CryptoLockerMe

Sep 17, 2023

### Thailand Cyber Top Talent 2023 <a href="#f365" id="f365"></a>

In this publish i will do some write-up about the CTT 2023 which i have participated with my fellow borthers from the university were i studying at.

This is the only challenge that i still have in my FlareVM guest. All of the other challenge files has been deleted by my self from my VM, after the event has end. So. This publish would be only one challenge write-up!

So first the challenge will give us a zip file format. We will have `CryptoLockerMe.exe` and `flag.crypt` after we have extracted the zip file. How ever the flag file were not in the plain text, that’s for sure that the `flag.crypt` got encrypted.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*lnt2YJTcl-zHoA4XOgWDKQ.png" alt="" height="122" width="700"><figcaption><p>Suspect File.</p></figcaption></figure>

So. Let see what is the PE of `CryptoLockerMe.exe`, so we can find the right way, and tool to do analysis on it. In this process i’ll use DIE, because it just easy to use, and output is readable.

From this we will se that it use .NET which is a set of libraries and tools used with C# (as well as other programming languages) to build a wide range of applications or run them.

I think? I don’t know. I have never wrote C# before in my life.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*JjNq8UIxo85er78cUzoePw.png" alt="" height="423" width="700"><figcaption><p>.NET detected.</p></figcaption></figure>

After we know that this file use to be C#, that mean we know what tool we are going to use, to perfrom analysis on it. For me i’ll use `dnSpy` because this is the only tool that i know to perfrom analysis with any malware that are written in C#.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*B0kt-In5yW5TRLN6-sVb0g.png" alt="" height="404" width="700"><figcaption><p>dnSpy open .NET Executables file.</p></figcaption></figure>

Since, This sections. I will only talk about the decomplied code of this malware and a little bit of dnSpy.

After we open this .NET Executables file on dnSpy. In decomplied code we will see that there is three mainly suspect functions (Atleast for me.) in the same class, which is `From1_Load`, `ea`, and `da`.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*57w1V7Ax6r0zbxWX4cw9xw.png" alt="" height="448" width="700"><figcaption><p>From1_Load function.</p></figcaption></figure>

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*REVTB6YYV88WwT0GtjWCYg.png" alt="" height="290" width="700"><figcaption><p>ea function.</p></figcaption></figure>

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*4LPQQkxlCam7UHQRSoJYQQ.png" alt="" height="269" width="700"><figcaption><p>da function.</p></figcaption></figure>

From the analysis that i has been doing. I can specify that.

* `From1_Load` is use to load other function when `From is loaded`.
* `ea` is the encrypt function.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*WuBb_bm5JIhlolEDNqxCRQ.png" alt="" height="287" width="700"><figcaption><p>“ea” encrypt function identify.</p></figcaption></figure>

* `da` is the decrypt function.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*K1XiDa5JwadXjDjTS4seYA.png" alt="" height="279" width="700"><figcaption><p>“da” decrypt function identify.</p></figcaption></figure>

Since, We know that `From1_Load` will call `ea`, and `da` our mainly targeted function that we will be focusing to analysis on is `From1_Load` for sure.

In the `From1_Load` we will see that there is some condition that will check that `flag` which’s `flag.txt` is exist or not. If it not. It will not execute the block in side that statement, and go to the next state ment which’s also check. If `00000000.eky` exist or not. If it were, well, it will delete `00000000.eky` file which this file is important to us in the future analysis.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*HttvS0UrNSGm_CPXCEceyg.png" alt="" height="449" width="700"><figcaption><p>File management condition.</p></figcaption></figure>

Ok. If `flag` which’s `flag.txt` exist in side of the condition block it will use to read the data of the `00000000.eky` file and the `flag.txt` file. Then it will pass those value through the `ea` function. From now on we can assume that this is the **encryption process** of the malware. But if we go back to our directories that we have extracted from zip file. we will see that there is no `flag.txt` at all. Instead `flag.txt` turn out to be `flag.crypt` which’s mean that the flag is already encrypted.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*xtwcGOADo4pxyPEpS4sVvg.png" alt="" height="510" width="700"><figcaption><p>Flag is already encrypted.</p></figcaption></figure>

Now let come to the decryption process. Well since we know that if `flag.txt` is not right there in the directories. I use to edit the decompiled code by set those condition statement to not true (because it is the boolean checker).

Inside of the condition block. Since we know that `ea` is encryption function. So. I’ll change it to `da` which’s decryption function by passing argument to the “da” function follow by the varible that’s set inside of the `da` function, and delete the encryption statement. I’ll use `MessageBox` to show the flag, because it just easier to read.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*y7DPQKXVNtwFwJ4hpolMgg.png" alt="" height="276" width="700"><figcaption><p>Follow the varibles.</p></figcaption></figure>

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*Q9GYLrwOAY0_KMPxMSP-IA.png" alt="" height="369" width="700"><figcaption><p>Re-compiled code.</p></figcaption></figure>

**Before we are going to see the flag of this challenge. Let’s see how `00000000.eky` will be able to use in the decryption process?**

We will see the statement that will initialize the varible name `text3` with `Form1.da` which is the decryption function.

Then it will call `File.WriteAllText(text, text3)` following by the arguments that need to be pass to the parameters of function.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*HgNPDNmWXKTBX_6_RW5Ljg.png" alt="" height="352" width="700"><figcaption><p>Generate “00000000.eky”.</p></figcaption></figure>

To see more image of it, let’s jump to `WriteAllText` and see how this function work.

After we jump in to `WriteAllText` function. We can clearly see, that this function use to create `00000000.eky` following by the argument that were pass into the parameter `File.WriteAllText(text, text3)`.

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*pLaOIny0y9aThhMwqxqntw.png" alt="" height="221" width="700"><figcaption><p>WriteFile function.</p></figcaption></figure>

That mean it will write the content that’s return from decryption function to the file name `00000000.eky`, and can possibly be the key to decrypt the flag.

**Since we keep the `00000000.eky` generate process in `From1_Load` keep in mind that, `00000000.eky` will generate after we run the executable file, that we has save after we edit the decompiled code similarly, or correctly.**

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*Cjrt1o0GOoEjaKVluKsrYA.png" alt="" height="341" width="700"><figcaption><p>Possible decrypt key.</p></figcaption></figure>

After we have re-compiled and save it as executable. Now we can run and get the flag!

<figure><img src="https://miro.medium.com/v2/resize:fit:875/1*7cmlI-Aow9ssf1tDYQqIwg.png" alt="" height="446" width="700"><figcaption><p>CryptoLockerMe — Flag!</p></figcaption></figure>

<br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://mapol.gitbook.io/home/blog/ctf/cryptolockerme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
