
HTB: Challenge - Wanted Alive
Wanted Alive peels back a phishing .hta attachment through nested JScript, obfuscated VBScript, and two chained PowerShell downloaders to reach a flag served over HTTP.

Wanted Alive peels back a phishing .hta attachment through nested JScript, obfuscated VBScript, and two chained PowerShell downloaders to reach a flag served over HTTP.

In this lab, the RemoteMouse 3.008 exploit will be used on port 1978 for remote code execution, capturing a reverse shell with Netcat. After decoding the FileZilla password, we will log in via Remote Desktop and open a Command Prompt as an administrator. This lab focuses on exploiting service vulnerabilities and privilege escalation methods.

Reminiscent carves a malicious resume.pdf.lnk out of a Windows 7 memory dump with Volatility, then peels back two offset-read, base64-chained PowerShell stagers — the second an RC4-keyed Empire-style beacon — down to the flag.