data:image/s3,"s3://crabby-images/2a5ef/2a5ef6b5ee409ef07f80c259c1ee20a6ba2eb30a" alt=""
.pptm is a Microsoft Powerpoint file extension, if you’re not running windows you can use the free and open source libreoffice to view the file. I downloaded mine using sudo apt.
The first command I did was strings to see if there was any hidden text in the file.
data:image/s3,"s3://crabby-images/5f999/5f99965fef5eac12f3bb6081f347b96a11a47dd5" alt=""
data:image/s3,"s3://crabby-images/63252/63252db834e3399284f2d5e53ed4a0dfa3235116" alt=""
There is a hidden slide within the file so I opened it with libreoffice
data:image/s3,"s3://crabby-images/e819e/e819ef258d19e5af7f2973745f3bc694c9a60ba6" alt=""
The hidden slide is denoted with the grayed out bars, but sadly it is just a rabbit hole. When I initially opened the file I received a security warning about macros, so let’s look there next.
data:image/s3,"s3://crabby-images/308e2/308e2781d1985e06b54f2d8952b06ae3802ddb4b" alt=""
Another false flag. Next I decided to use binwalk to see if there were any files I could extract.
data:image/s3,"s3://crabby-images/41c3d/41c3d3a617db849a54f3c0426ce5b7ea53ff8582" alt=""
data:image/s3,"s3://crabby-images/6dce2/6dce2753a01d07352e733b1ad72eced3a587cb2d" alt=""
Another hidden file. Viewing the hidden file I found this cipher.
data:image/s3,"s3://crabby-images/c8a96/c8a9699b220a6680162847c0cde8003bee021fc3" alt=""
The spaces were making it difficult for online decoders to recognize so I quick removed them using python.
data:image/s3,"s3://crabby-images/cef0f/cef0f2a512625cfc9480d6b16d9fe0b6f10cc71a" alt=""
After that I was able to decode it using cyberchef. I could have used python, but cyberchef’s gui and auto recognition features make it much faster and efficient.
data:image/s3,"s3://crabby-images/b018e/b018ebed5d46f9c59a5a2afa013798eda540706b" alt=""
And there’s the flag!