2HWA—منتخب القهوة

Team Archive & Timeline

The complete chronological timeline of writeups, challenge releases, hosted CTFs, tournament records, and security research published by the team.

18

Members

41

Competitions

2

Hosted CTFs

48

Challenges

51

Writeups

Coming soon

Research

2026
[Challenge]Escape From SpongeBobSpongeBob bolted a rocket to the boatmobile and he is leaving town tonight. The launch paperwork got torn into five pieces and every neighbor is hiding one: Mr. Krabs has it in the register, Plankton photographed it, Mrs. Puff refused to sign it, and Patrick shoved his under a rock. Gary left you the whole escape plan in a single picture. Your image viewer will not open it. Start there. One file. Five pieces. Tape them together in order.
EYCC CTF 2026FinalsMISCbeginner-friendly@0xsponge
[Challenge]Infected Revenge> ☠️ **Safety Warning:** This challenge involves a real C2 server and a real BTX miner. The files related to it are actual malware — do not run anything. Everything here is meant for static review only. You can visit the C2 with normal HTTP requests; just never execute what it serves. > **Link:** [Gofile](https://gofile.io/d/J2VI5Pfk) Aurelia Systems, a mid-sized industrial-tech company, found suspicious outbound traffic during a routine audit. On 11 July 2026, an engineer in the Engineering VLAN clicked a link in what looked like an internal IT notice. It silently redirected through redacted.com to a remote server, which dropped a chain of scripts that installed a BitcoinTX miner. No alerts fired. The attached capture covers the full incident timeline. `infected.pcap` is the company network capture from the incident. It contains only internal traffic: multiple VLANs (office, engineering, data center, CCTV, guest, IoT and more), plus some VPN and DMZ traffic. Nothing external is inside the capture, except the infected device with the requests to the C2 server. - **Flag Format:** `EYCC{part1_part2_part3_part4_part5_part6}` - **Part 1 — The Key:** the XOR key used to deobfuscate the C2 server's payload - **Part 2 — The Wallet:** the BTX address used by the miner - **Part 3 — First Payment:** the txid of that BTX address's first payout - **Part 4 — The Operator:** the email that links the miner creator to the infrastructure - **Part 5 — The Phone number:** the registrant phone of the mining pool domain
EYCC CTF 2026FinalsOSINTbeginner-friendly@2FACE
[Challenge]Krusty Krab Order BoardsMr. Krabs finally put the Krusty Krab order boards online, and SpongeBob finally admitted what he really wants: the Krabby Patty secret formula. It is filed at `/verysecretrecipe`, and the fry cook account you can sign up for is not getting in there. Mr. Krabs is, though. He reads every link dropped in the complaint box himself, from his own logged-in browser. Get the formula out of the manager's session.
EYCC CTF 2026FinalsWEBbeginner-friendly@0xsponge
[Challenge]Operation: GANBAR | natega.xlsGanbar was preparing for his beggist operation yet, working on his latest piece of art; the one that will give him complete control over all people. All he needed was to wait for the right moment; inspired by the greatest threat actors who came before ganbar was finalising his perfection before he [falls in the hands of justice](https://cdn.imgchest.com/files/1b0c66e3108d.gif). Can you figure out what was his plan?
EYCC CTF 2026FinalsREVERSEbeginner-friendly@0xreizouko
[Challenge]Operation: GANBAR | TopSecret Fallines**category: Forensics / Reverse Engineering** Ragab Ganber was finally caught. After his arrest, investigators seized two laptops: a personal Windows laptop and a separate Linux machine used for his black-hat activities. Ragab believed he had been careful. He kept his personal files separate from his malicious work and developed his own tools and algorithms to protect what mattered to him. During the investigation of his Linux machine, investigators discovered malware, attack tools, and several projects he had worked on or planned to use. Among them was a custom encryption tool that appeared to carry Ragab's signature—the same signature he had used on ransomware in previous attacks. Investigators then turned to his personal Windows laptop. Among his files, they discovered a hidden folder containing what appeared to be an experiment with the same encryption algorithm. But his laziness worked against him. After testing the encryptor, Ragab used it on an important file. He thought he had protected it, but he left traces revealing where the file had been downloaded from. You are provided with a forensic image of Ragab's personal laptop and the encryption binaries recovered from his Linux machine. Connect the evidence between the two machines. Investigate the encryption logic, uncover clues about how Ragab developed it, and follow the traces he left behind on his Windows laptop. **Follow the trail he left behind. Connect the evidence. Uncover the secret Ragab thought would remain hidden forever.**
EYCC CTF 2026FinalsFORENSICSbeginner-friendly@Y0un15
[Challenge]2Face Graduation2Face, a member of **Mont5ab El2hwa**, has finally reached one of the most memorable moments of his journey. We took this photo while celebrating his graduation, but one important detail was left behind. Your mission is to identify: 1. The full name of the university. 2. The university’s official slogan. > **Flag Format:** `EYCC{AUC_I_GO_TO_SCHOOL_BY_BUS}` > Use uppercase letters only and replace all spaces with underscores.
EYCC CTF 2026QualifiersOSINTbeginner-friendly@2FACE
[Challenge]Metoubas v1Our friend Ragab Ganbar is tired from warming the bench of unemployeds' group(جروب العواطلية), at a moment of desperation he decided to start his own RaaS. Ganbar being a human first had some causes he want to fight for and a test field for his new product so he started with Gharbia for Exhausts(الغريبة للعوادم). Like LockBit and The Gentlemen our Ganbar decided to name his ransomware Metoubas(كفر الشيخ مركز مطوبس) as he takes pride in his origins. Now it's your story, can you decrypt the file and get the secret?
EYCC CTF 2026QualifiersREVERSEbeginner-friendly@0xreizouko
[Challenge]Metoubas v2Ganbar continues his adventures, this time he improved his product and decided to target Eggyard, where it's structured as a military base with military grade security(we will see about this) A malicious file was sent to Duffy Duck the security officer of the base. After discovering the incident the called you as to restore the files as they contain very important information that needs to be reported to the Colonel.
EYCC CTF 2026QualifiersREVERSEbeginner-friendly@0xreizouko
[Challenge]Tick TockAn employee's workstation was flagged after unusual outbound network activity was detected by the organization's monitoring systems. Initial Investigation revealed that a malicious executable had been executed on the host. Investigators managed to acquire a copy of the system's registry, before the machine was reimaged as part of the remediation process. Your task is to examine the provided registry hives and determine how the attacker maintained their presence on the system.
EYCC CTF 2026QualifiersFORENSICSbeginner-friendly@OG13
2025