I share the solution of “an unusual sighting” challenge from hack the box.
Connect to the host machine using netcat.
Then it will ask us questions. All the answers can be found in the log files.
IP Address and Port of the SSH Server
100.107.36.130:2221
What time is the first successful Login
2024-02-13 11:29:50
What is the time of the unusual Login
2024-02-19 04:00:14
What is the Fingerprint of the attacker’s public key
OPkBSs6okUKraq8pYo4XwwBg55QSo210F09FCe1-yj4
What is the first command the attacker executed after logging in
whoami
What is the final command the attacker executed before logging out
./setup
After answering to all the questions you will get the flag.