TL;DR

A .pcapng capture shows a victim host on 192.168.1.141 downloading a Python

keylogger (updates.py) from an attacker-controlled "hotel update server" at

byte-lotus-hotel.thm:8080 (34.41.103.191). The script XOR-encrypts every

keystroke with a hardcoded key, base64-encodes it, and exfiltrates it inside an