<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Network Analysis on bubka hacks stuff</title><link>https://hexpysya.github.io/tags/network-analysis/</link><description>Recent content in Network Analysis on bubka hacks stuff</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 16 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hexpysya.github.io/tags/network-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>CDEF-EtherRAT</title><link>https://hexpysya.github.io/investigations/cdef-etherrat/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-etherrat/</guid><description>An attacker breached Maromalix&amp;rsquo;s public-facing web application by exploiting CVE-2025-55182 (Next.js Deserialization RCE). They deployed a multi-stage implant dubbed EtherRAT, which utilizes a blockchain-based C2 mechanism via Ethereum smart contracts to dynamically resolve infrastructure. The attacker exfiltrated sensitive data, established multiple persistence mechanisms, and ultimately patched the vulnerability to lock out other actors.</description></item><item><title>CDEF-Lockdown</title><link>https://hexpysya.github.io/investigations/cdef-lockdown/</link><pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-lockdown/</guid><description>An attacker performed SYN port scanning against an IIS server, enumerated open SMB shares, uploaded a webshell to the Documents share, triggered a reverse shell on port 4443, and established persistence via AgentTesla dropped into the Startup folder, which exfiltrated data via SMTP to cp8nl.hyperhost.ua.</description></item><item><title>CDEF-HawkEye</title><link>https://hexpysya.github.io/investigations/cdef-hawkeye/</link><pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-hawkeye/</guid><description>A victim host downloaded a HawkEye Keylogger dropper via HTTP, which established persistence, periodically checked the external IP via bot.whatismyipaddress.com, and exfiltrated harvested credentials every 10 minutes over SMTP.</description></item><item><title>HTB-Liberty</title><link>https://hexpysya.github.io/investigations/htb-liberty/</link><pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-liberty/</guid><description>Password spraying led to domain account compromise, followed by NetNTLM hash theft via a malicious .url file, RDP access, data exfiltration to a C2 server, and PSWA backdoor installation for persistence.</description></item><item><title>CDEF-BlueSky Ransomware</title><link>https://hexpysya.github.io/investigations/cdef-bluesky-ransomware/</link><pubDate>Tue, 10 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/cdef-bluesky-ransomware/</guid><description>An attacker performed a port scan, exploited a Microsoft SQL Server via the sa account, enabled xp_cmdshell to drop and execute a base64-encoded payload, then deployed a multi-stage PowerShell toolkit to disable AV, dump NTLM hashes, perform lateral movement via SMB, and stage the BlueSky ransomware payload.</description></item><item><title>HTB-Telly</title><link>https://hexpysya.github.io/investigations/htb-telly/</link><pubDate>Fri, 06 Mar 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-telly/</guid><description>An attacker exploited CVE-2026-24061, an authentication bypass in GNU inetutils telnetd, to obtain an unauthenticated root shell, established persistence via linper.sh across multiple cron and systemd locations, and exfiltrated a credit card database before deleting it from the victim server.</description></item><item><title>HTB-SneakyKeys</title><link>https://hexpysya.github.io/investigations/htb-sneakykeys/</link><pubDate>Tue, 03 Feb 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-sneakykeys/</guid><description/></item><item><title>HTB-Packet_Puzzle</title><link>https://hexpysya.github.io/investigations/htb-packet-_puzzle/</link><pubDate>Sat, 31 Jan 2026 00:00:00 +0000</pubDate><guid>https://hexpysya.github.io/investigations/htb-packet-_puzzle/</guid><description>Analyzed network traffic showing exploitation of CVE-2024-4577 (PHP-CGI argument injection) against a Windows server running PHP 8.1.25. Attacker achieved RCE, established reverse shell on port 4545, then escalated privileges using GodPotato to spawn a SYSTEM-level shell on port 5555.</description></item></channel></rss>