top of page

Archived Leads

Past Leads that have been archived at their completion

/Reach Tags/                   /Wiseguy/               /ThursdayWar/          /TwitterHandle/                  /Numeral?/

Datanode #2 - Wiseguy

A few people got a PM from Sec3OP36516, with the wiseguy emblem and some hidden text:
1) Take the text code link in the image:
Quote:
=YkMtUDNtMENtkDNtYDNtAjMtQDNtUENtUDNtYkMtEEMtQEMtYkMtYkMtEEMtQEMtgzNtQzNtAzNtAzNtUkMtUkNtUzNtYjNtYkNtUkNtYkNtQzNtEjNtYkMtgzMtYkMtEzMtEzMtYkMtIzMtEzMtAzMtIzMtYkMtUjNtcjNtEjNtIzNtYkNtQzNtMzNtYkMtUjNtIzNtYkNtQzNtMzNtUjNtMkNtkjNtYjNtcjNtYkNtMkNtIjNtYkMtQzNtUjNtUkNtUkMtMzNtczNtYkNtQjNtUkNtkjNtczNtUkMtUjNtIzNtYkNtMjNtUkMtIjNtYkNtMkNtIjNtUkMtQjNtYkNtIzNtAzNtQzNtUkNtkjNtYkNtAzNtkzNtEjNtczNtYkMtYkMtE0MtMzNtAzNtQzNtQzNtgjNtYkMtYkMtEEMtQEMtYkMtYkMtEEMtQEMtE0MtUDNtQDNtYENtUENtAjMtEDNtQTNtEDNtQDNtAjMtcDNtUENtkDNtQENtYENtMDNtUENtkDNtYkMtYkMtEEMtQEMtYkMtYkMtEEMtQEMtYkMtQDNtUDNtkDNtYDNtkDNtMTNtMTNtEDNtMENtMDNtYkMtYkMtUDNtMENtkDNtYDNtAjMtQTNtITNtEDNtQTNtMTNtYkM

2) Run it through a text reverse.
3) Enter the result in a Hex editor.
4) The result:
Quote:
/START FILE//CLASSIFIED/..//..//INCOMING DATA NODE:..//..//htps://waypointprod.blob.core.windows.net/blogfilestore/storage/2012/11/8/atonofun.pptx..//../END FILE/

You will then download the .pptx, however it isn't a slideshow, it is a zip file. Open appropriately, then you will get a long .txt file called "recoverd7" which MrToasty XD is apparently working to crack now.

Toasty:
Hooray, got a fairly wicked MP4 file now! Pretty sure we've got spectrogram and flashing images to work with.

http://www.youtube.com/watch?v=SQ8lrmOZ_F0&feature=youtu.be

 

 

Link to broken specrograph:

http://i.imgur.com/qKAln.jpg

 

The two images put together gives the first and eighth symbol in the wiseguy code:

http://imgur.com/WGyYr



The Video had the following other information:

http://imgur.com/a/teaJ8#3



The first is a modified version of the 'recipe' image for unlocking the datanode, just with colors a little different and 'a' substituted for 'ml' that we knew already.

WPX, RAZ4, M0A confirms a missing tag we had in the Reach code.

bottom of page