Erick Cisneros
ContactResume
Directory
Overview
Experience
Investigations & Tooling
The Trophy Case
Education
Contact Me
Direct Inquiries
Back to Security Investigations & Tooling
CTF-WRITEUP-EF01

EmberForge // Source Leak

CHALLENGE: EmberForge // Source Leak

PLATFORM: LOG(N) Pacific Cyber Range (Skool)

ANALYST: Erick Cisneros Ruballos

DATE COMPLETED: 2026-04-04

DATA SOURCE: EmberForgeX_CL (Sysmon + Windows Security events)

A threat actor compromised the emberforge.local domain through a phishing-delivered ISO file, achieving full domain compromise in a single attack session. The attacker exfiltrated the entire C:\GameDev source code repository (42.3 GB) to MEGA cloud storage.

Incident ResponseCTF WriteupDigital ForensicsSysmon AnalysisNTDS Extraction
See Full Report on GitHub
Case Brief

Executive Summary

A threat actor compromised the emberforge.local domain through a phishing-delivered ISO file, achieving full domain compromise in a single attack session. The attacker exfiltrated the entire C:\GameDev source code repository (42.3 GB) to MEGA cloud storage using the credential jwilson.vhr@proton.me.

Domain credentials were stolen via NTDS.dit extraction from a VSS shadow copy on the Domain Controller. The attacker established persistent remote access via AnyDesk and created a backdoor domain admin account (svc_backup). Security and System event logs on the DC were subsequently cleared to impede forensic investigation — however, Sysmon telemetry survived the clearing and provides near-complete reconstruction of the attack chain.

HOST 1 (WORKSTATION)EC2AMAZ-B9GHHO6Lisa Martin's workstation (Windows 10)
HOST 2 (SERVER)EC2AMAZ-16V3AU4Internal file/app server (Windows Server)
HOST 3 (DC)EC2AMAZ-EEU3IA2Domain Controller (Windows Server)
Intrusion Progression

Attack Timeline

PHASE 1

Initial Access (EC2AMAZ-B9GHHO6)

Lisa Martin opened 'EmberForge_Review.iso' which bypassed Mark-of-the-Web. rundll32.exe executed 'review.dll', injecting into notepad.exe.

PHASE 2

C2 Establishment & UAC Bypass

update.exe established C2 to cdn.cloud-endpoint.net. Privileges escalated via fodhelper UAC Bypass, writing to registry. Persistence created as 'WindowsUpdate' scheduled task.

PHASE 3

Credential Dumping & Discovery

update.exe dumped LSASS using direct syscalls to 'lsass.dmp'. Elevated process ran net user /domain and nltest /dclist. Added firewall rule for SMB.

PHASE 4

Lateral Movement to Server

Tools staged via workstation SMB share. Failed NTLM pass-the-hash. Attacker pivoted to Impacket smbexec and certutil.exe to stage tools on EC2AMAZ-16V3AU4.

PHASE 5

Exfiltration (EC2AMAZ-16V3AU4)

Compress-Archive on C:\GameDev. rclone.exe configured with plaintext MEGA credentials line-by-line, and source code exfiltrated.

PHASE 6

Lateral Movement to DC

Impacket atexec run on DC (EC2AMAZ-EEU3IA2). Pivoted to smbexec for NTDS.dit extraction via VSS shadow copy.

PHASE 7

Backdoor & Persistence

Created backdoor account 'svc_backup' in Domain Admins. Installed AnyDesk silently with config modified for unattended access ('password').

PHASE 8

Anti-Forensics (EC2AMAZ-EEU3IA2)

Executed 'wevtutil cl Security' and 'wevtutil cl System' via smbexec on the DC to wipe event logs. Sysmon telemetry survived.

Threat Intelligence

Evidence Inventory & IOCs

Network Indicators
C2 Domaincdn.cloud-endpoint.net
Staging Domainsync.cloud-endpoint.net:8080
C2 IP104.21.30.237, 172.67.174.46
Attacker Emailjwilson.vhr@proton.me
Filesystem & Payloads
ISO DeliveryEmberForge_Review.iso
Malicious DLLD:\review.dll
C2 ImplantC:\Users\Public\update.exe
LSASS DumpC:\Windows\System32\lsass.dmp
NTDS.dit copyC:\Windows\Temp\nyMdRNSp.tmp
Methodology Insight

Sentinel Ingestion vs. Event Time

Do not rely on TimeGenerated for forensic attack sequencing. Actual event times are embedded in the Sysmon/Windows XML in Raw_s:

<TimeCreated SystemTime='2026-01-30T23:19:21.XXXXXXX'/>

This distinction was critical for DC Arrival analysis: the atexec whoami at 23:19:21 preceded the smbexec vssadmin operations at 23:34:55 — a 15-minute gap invisible from ingestion timestamps alone.

Strategic Recommendations

  • 1Rotate all domain credentials immediately — NTDS.dit was exfiltrated; all password hashes are compromised.
  • 2Disable and delete the svc_backup domain admin account.
  • 3Revoke MEGA access for jwilson.vhr@proton.me and report to MEGA abuse team.
  • 4Remove AnyDesk service from EC2AMAZ-B9GHHO6 and invalidate all AnyDesk IDs.
  • 5Delete WindowsUpdate scheduled task and remove update.exe from Public folder.
  • 6Block C2 domains/IPs: cdn.cloud-endpoint.net, sync.cloud-endpoint.net, 104.21.30.237, 172.67.174.46.
  • 7Reset KRBTGT account twice (24-hour gap) to invalidate any forged Kerberos tickets.
© 2026 Erick Cisneros Ruballos
LinkedIn•GitHub•Direct Email