Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
BlackLotus-Z2A-Challenge — BlackLotus-Z2A-Challenge, Nothing to see here 4 now , please move along | Kitploit
Tools/GitHubGitHub/spiralbl0ck/blacklotus-z2a-challenge
Static AnalysisReverse EngineeringMalware AnalysisCTFLearning & Education
GitHubspiralbl0ck/blacklotus-z2a-challenge

BlackLotus-Z2A-Challenge

BlackLotus-Z2A-Challenge, Nothing to see here 4 now , please move along

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
32573 years agoNot yet reviewed
Share

BlackLotus-Z2A-Challenge

BlackLotus-Z2A-Challenge, Nothing to see here 4 now , please move along

First things first Capture23

For aesthetic purposes soley, I will shamesly borrow(steal) :)) from @darthmaulware(Ryan “DM” Smith) solution the yara detection rules just to make it look proffesional. Go check his twitter he's a fking cool person! Ps. Ryan please don't get mad bc i stole that :))) and thx for support in discord :)

Please check his work also :)

https://gitlab.com/malre-rcs/zero2automated/-/blob/main/solutions/bi_weekly_challenge/BlackLotus_20230321/BlackLotus_HTTP_Downloader.ipynb

rule Blacklotus_HTTP_Downloader
{
        meta:
            description = "Rule to detect Blacklotus HTTP Downloader"
            author = "Darth Maulware"
            sha256 = "d68f668b4240f9518e4f80499d93d8c5a1eddece0771658c33ae916cc54f5a66"

        strings:
            $opcode1 = {48 89 4C 24 08 48 89 54 24 10 4C}
            $opcode2 = {89 44 24 18 4C 89 4C 24 20 48 83}
            $opcode3 = {EC 28 B9 31 62 D7 2E 90 90 E8 ??}
            $opcode4 = {?? ?? ?? 48 83 C4 28 48 8B 4C 24}
            $opcode5 = {08 48 8B 54 24 10 4C 8B 44 24 18}
            $opcode6 = {4C 8B 4C 24 20 4C 8B D1 90 90}

        condition:
            (uint16(0) == 0x5a4d and filesize < 500KB and all of them)
}

Also for aesthetical reasone i will also steal this because it looks cool :) again sorry ryan please don't get mad on me :)

        C:\\Users\\REM\\Desktop>capa.exe -f pe -r capa-rules-5.0.0 d68f668b4240f9518e4f80499d93d8c5a1eddece0771658c33ae916cc54f5a66.exe
        matching: 100%|████████| 124/124 [00:02<00:00, 46.96 functions/s, skipped 1 library functions (0%)]

        +------------------------+------------------------------------------------------------------------------------+
        | ATT&CK Tactic          | ATT&CK Technique                                                                   |
        |------------------------+------------------------------------------------------------------------------------|
        | DEFENSE EVASION        | Obfuscated Files or Information T1027                                              |
        | DISCOVERY              | Process Discovery T1057                                                            |
        | EXECUTION              | Shared Modules T1129                                                               |
        +------------------------+------------------------------------------------------------------------------------+

        +-----------------------------+-------------------------------------------------------------------------------+
        | MBC Objective               | MBC Behavior                                                                  |
        |-----------------------------+-------------------------------------------------------------------------------|
        | ANTI-BEHAVIORAL ANALYSIS    | Debugger Detection::Process Environment Block BeingDebugged [B0001.035]       |
        |                             | Debugger Detection::Process Environment Block NtGlobalFlag [B0001.036]        |
        | CRYPTOGRAPHY                | Encrypt Data::RC4 [C0027.009]                                                 |
        |                             | Generate Pseudo-random Sequence::RC4 PRGA [C0021.004]                         |
        | DATA                        | Encode Data::XOR [C0026.002]                                                  |
        | DEFENSE EVASION             | Obfuscated Files or Information::Encoding-Standard Algorithm [E1027.m02]      |
        +-----------------------------+-------------------------------------------------------------------------------+

        +------------------------------------------------------+------------------------------------------------------+
        | CAPABILITY                                           | NAMESPACE                                            |
        |------------------------------------------------------+------------------------------------------------------|
        | execute syscall instruction (35 matches)             | anti-analysis                                        |
        | check for PEB BeingDebugged flag (2 matches)         | anti-analysis/anti-debugging/debugger-detection      |
        | check for PEB NtGlobalFlag flag                      | anti-analysis/anti-debugging/debugger-detection      |
        | encode data using XOR (2 matches)                    | data-manipulation/encoding/xor                       |
        | encrypt data using RC4 PRGA (2 matches)              | data-manipulation/encryption/rc4                     |
        | get process heap flags                               | host-interaction/process                             |
        | get ntdll base address (3 matches)                   | linking/runtime-linking                              |
        | parse PE header (2 matches)                          | load-code/pe                                         |
        | resolve function by parsing PE exports (2 matches)   | load-code/pe                                         |
        +------------------------------------------------------+------------------------------------------------------+

tbh if i were you i wouldn't trust 100% capa(at least in this specific case) because here it say the sample uses rc4 when actually sample uses aes but whatever , as mentioned this is strictly for aesthetics :)

Before we start you will encounter through this report a lot of

1

Please ignore this as ida fails to properly dissasamble this in assembly this is

1

And this crashes the debugger ? why ?

because it tries to write at address 0, which in hacker folklor is know as writing at null pointer address which was something exploited widely in order to obtain CE(code execution), and this has been obviously mitigated.

And such with the current mitigation if you try to write at 0 it will crash that process in our case the malware & consequently the debugger.

Now if we open this is ida

1

I renamed every function to indicate some logic it does, let's start with first function, do_syscall() Capture23

We imediatly notice the use of syscalls, which it's a known method to make the life of an analyst harder when it comes to dynamic analysis.

For those who are not familiar with syscall's in windows here is a cool video made by oalabs(https://www.youtube.com/watch?v=Uba3SQH2jNE). Please watch it cause i did too and it helped me a lot to understand what happens in this function

If we inspect the "pseudo-code" resolved by ida we see it looks like this

Capture4

If we inspect statically solve_hash it looks like this

1

2

From a pseudo-perspective it looks like this

4

Download Tool