
HTB: Challenge - Wanted Alive
Wanted Alive peels back a phishing .hta attachment through nested JScript, obfuscated VBScript, and two chained PowerShell downloaders to reach a flag served over HTTP.

Wanted Alive peels back a phishing .hta attachment through nested JScript, obfuscated VBScript, and two chained PowerShell downloaders to reach a flag served over HTTP.

Reminiscent carves a malicious resume.pdf.lnk out of a Windows 7 memory dump with Volatility, then peels back two offset-read, base64-chained PowerShell stagers — the second an RC4-keyed Empire-style beacon — down to the flag.