Redminers writeup
Challenge name: Redminers
Difficulty: Very Easy
Challenge Scenario: In the race for Vitalium on Mars, the villainous Board of Arodor resorted to desperate measures, needing funds for their mining attempts. They devised a botnet specifically crafted to mine cryptocurrency covertly. We stumbled upon a sample of Arodor’s miner’s installer on our server. Recognizing the gravity of the situation, we launched a thorough investigation. With you as its leader, you need to unravel the inner workings of the installation mechanism. The discovery served as a turning point, revealing the extent of Arodor’s desperation. However, the battle for Vitalium continued, urging us to remain vigilant and adapt our cyber defenses to counter future threats.
Link: https://app.hackthebox.com/challenges/Red%2520Miners?tab=play_challenge
Machine IP: NA
Downloaded the zip and unzipped it. Right away I saw a bunch of base64.

I decoded this and its a part of the flag.

Part 2 of flag


Part 3 of flag


Part 2 I think is this


Put it altogether and submitted the flag and it worked. I didn’t even have to read the code exactly. From reading the code though it looks like it looks for a certain username, root7654, specific host name and basically runs a ‘miner’ but kills other services that may affect it.

GG
Leave a comment