<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Event Viewer on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/event-viewer/</link><description>Recent content in Event Viewer on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Wed, 25 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/event-viewer/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB-Liberty</title><link>https://hexpysya.github.io/investigations/htb-liberty/</link><pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-liberty/</guid><description>Password spraying led to domain account compromise, followed by NetNTLM hash theft via a malicious .url file, RDP access, data exfiltration to a C2 server, and PSWA backdoor installation for persistence.</description></item><item><title>HTB-WorkFromHome</title><link>https://hexpysya.github.io/investigations/htb-workfromhome/</link><pubDate>Mon, 16 Feb 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-workfromhome/</guid><description>A victim clicked a phishing link impersonating a corporate login page, leading to credential theft. The attacker used stolen credentials to gain RDP access, then escalated privileges via SeManageVolumeExploit, deployed malicious DLLs using certutil, and established persistence through a hidden VBS script in the Startup folder.</description></item><item><title>HTB-EasyMoney</title><link>https://hexpysya.github.io/investigations/htb-easymoney/</link><pubDate>Thu, 05 Feb 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-easymoney/</guid><description>Administrator executed a malicious shortcut that triggered a hidden PowerShell command, downloading and executing payload and gaining a shell access. The attacker enumerated installed software, identified a vulnerable Yandex Browser (CVE-2024-6473), and exploited DLL hijacking by planting a malicious library that acts as a dropper. This dropper deployed a Sliver C2 implant establishing persistence via a scheduled task and maintaining communication</description></item><item><title>HTB-GhostTrace</title><link>https://hexpysya.github.io/investigations/htb-ghosttrace/</link><pubDate>Sat, 31 Jan 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-ghosttrace/</guid><description>Analyzed Windows Event Logs revealing a complete AD compromise chain: phishing email with macro-enabled document → credential dumping with Mimikatz → lateral movement via PsExec → DCSync attack → domain admin compromise → persistence via scheduled task, service, and registry run key.</description></item></channel></rss>