Operation Cold Trail

TRACE · LINUX · difficulty 3 · ~25 min · 10 steps

One C2 address. Pivot it into the attacker's whole estate — and find where the trail ends.

Briefing

Containment is done: the miner is dead, the C2 is blocked. Now the part everyone skips. You have one address, 45.61.184.6, and a phishing document that started it. Your job is to work outward from those two artifacts and map as much of the adversary's infrastructure as the evidence honestly supports. You will use DNS, certificates, certificate transparency, document metadata and packet capture. Every technique widens the picture. None of them names a human, and the last step of this operation is recognising exactly where the road stops.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$