Introduction

Welcome to the TeamCity Exploit Lab walkthrough. This lab is designed to simulate a real-world cyberattack, focusing on a sophisticated breach against a network utilizing TeamCity. As a blue team analyst, your goal is to conduct a comprehensive investigation, identify indicators of compromise (IOCs), and uncover the tactics, techniques, and procedures (TTPs) used by the attackers.

The scenario involves analyzing a network compromise caused by leveraging known vulnerabilities within TeamCity. Attackers exploit these vulnerabilities to gain initial access, escalate privileges, execute commands, exfiltrate data, and deploy ransomware.

As a blue team analyst, your mission is to perform a thorough investigation of the breach, uncover the full extent of the attack, and identify the tactics, techniques, and procedures (TTPs) utilized by the attackers. To support your investigation, you are provided with:

  1. Triage Images: From the compromised hosts (e.g., JB01, SQL, DC01, IT01).

  2. Splunk Logs: A centralized log repository containing event logs from all compromised systems.

Analysis

Scoping

Q1: After analyzing the compromised systems, you discovered that several files have been encrypted. What extension has been appended to these files, indicating the ransomware's activity?

By visiting F:\E\Users\Administrator\Documents\<folder_name>, we can find that the files that were encrypted with an extension of lsoc.


Q2 While reviewing the infected machines, you notice a ransom note left behind by the attacker. Can you find and provide the exact name of this file?

By visiting F:\E\Users\Default\Desktop, we can find the ransom note dropped called un-lock your files.html.


Q3 What email addresses did the attacker provide for the victim to contact?

By opening the ransom note, we can find the two emails, [email protected] and [email protected].

Now, we'll head to the Ransom…

Unlock Your Full Learning Experience with BlueYard Labs

Sign up to track your progress, unlock exclusive labs, and showcase
your achievements—begin your journey now!
Join for Free