<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Letsdefend on harsh giri</title><link>https://quixtalia.in/tags/letsdefend/</link><description>Recent content in Letsdefend on harsh giri</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 20 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://quixtalia.in/tags/letsdefend/index.xml" rel="self" type="application/rss+xml"/><item><title>Remote Access Regret</title><link>https://quixtalia.in/p/remote-access-regret/</link><pubDate>Fri, 20 Mar 2026 00:00:00 +0000</pubDate><guid>https://quixtalia.in/p/remote-access-regret/</guid><description>&lt;ul&gt;
&lt;li&gt;scenerio&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 1" class="gallery-image" data-flex-basis="607px" data-flex-grow="253" height="470" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/1.png" srcset="https://quixtalia.in/p/remote-access-regret/1_hu_698c534a5940ecfb.png 800w, https://quixtalia.in/p/remote-access-regret/1.png 1190w" width="1190"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Image 2" class="gallery-image" data-flex-basis="577px" data-flex-grow="240" height="242" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/2.png" width="582"&gt;&lt;/p&gt;
&lt;p&gt;we get raw file&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;extract this using&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;dd if=intelvol.raw of=output.img bs=512
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo mkdir /mnt/rar_image
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo mount -o loop output.img /mnt/rar_image
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;img alt="Image 3" class="gallery-image" data-flex-basis="1073px" data-flex-grow="447" height="268" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/3.png" srcset="https://quixtalia.in/p/remote-access-regret/3_hu_6e605559b2fd8216.png 800w, https://quixtalia.in/p/remote-access-regret/3.png 1199w" width="1199"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;local AnyDesk ID&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 4" class="gallery-image" data-flex-basis="461px" data-flex-grow="192" height="599" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/4.png" srcset="https://quixtalia.in/p/remote-access-regret/4_hu_f9e285b487694eca.png 800w, https://quixtalia.in/p/remote-access-regret/4.png 1151w" width="1151"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;open this file in db browser&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 5" class="gallery-image" data-flex-basis="6289px" data-flex-grow="2620" height="39" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/5.png" srcset="https://quixtalia.in/p/remote-access-regret/5_hu_afe321e631c76e32.png 800w, https://quixtalia.in/p/remote-access-regret/5.png 1022w" width="1022"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;first website Margaret visited before encountering the scam&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;domain of the initial malicious redirect that led Margaret to the scam page&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 6" class="gallery-image" data-flex-basis="584px" data-flex-grow="243" height="509" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/6.png" srcset="https://quixtalia.in/p/remote-access-regret/6_hu_f88189fb129544fa.png 800w, https://quixtalia.in/p/remote-access-regret/6.png 1239w" width="1239"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Examining the cached HTML file, what phone number was displayed to the victim&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 7" class="gallery-image" data-flex-basis="530px" data-flex-grow="220" height="211" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/7.png" width="466"&gt;
&lt;img alt="Image 8" class="gallery-image" data-flex-basis="408px" data-flex-grow="170" height="851" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/8.png" srcset="https://quixtalia.in/p/remote-access-regret/8_hu_b8ff23ff3e0f7e3e.png 800w, https://quixtalia.in/p/remote-access-regret/8.png 1449w" width="1449"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AnyDesk ID of the remote machine&lt;/li&gt;
&lt;li&gt;alias of scammer&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 9" class="gallery-image" data-flex-basis="610px" data-flex-grow="254" height="514" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/9.png" srcset="https://quixtalia.in/p/remote-access-regret/9_hu_ab491867fe0dff85.png 800w, https://quixtalia.in/p/remote-access-regret/9.png 1308w" width="1308"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;total session duration in seconds&lt;/li&gt;
&lt;li&gt;convert hourly duration to second 4052 sec&lt;/li&gt;
&lt;li&gt;first file stolen from Margaret&amp;rsquo;s Desktop&lt;/li&gt;
&lt;li&gt;How many bytes total exfiltrated&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 10" class="gallery-image" data-flex-basis="359px" data-flex-grow="149" height="656" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/10.png" srcset="https://quixtalia.in/p/remote-access-regret/10_hu_2b8ed664fad3b6cf.png 800w, https://quixtalia.in/p/remote-access-regret/10.png 982w" width="982"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;total URLs were visited during the browsing session on the day of the incident&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="Image 11" class="gallery-image" data-flex-basis="584px" data-flex-grow="243" height="509" loading="lazy" sizes="(max-width: 767px) calc(100vw - 30px), (max-width: 1023px) 700px, (max-width: 1279px) 950px, 1232px" src="https://quixtalia.in/p/remote-access-regret/11.png" srcset="https://quixtalia.in/p/remote-access-regret/11_hu_f88189fb129544fa.png 800w, https://quixtalia.in/p/remote-access-regret/11.png 1239w" width="1239"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;it is 10&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;</description></item></channel></rss>