these are my writeups for memlabs , i made some notes while studying to understand why this plugin and how does it inner working translate to do what we want and some theory stuff and document winapi in my own words and also not to just run tools and solve stuff and be a skid
Lab 0 - Never Too Late Mister
Plugins i used
consoles
Similar to cmdscan the consoles plugin finds commands that attackers typed into cmd.exe or executed via backdoors. However, instead of scanning for COMMAND_HISTORY, this plugin scans for CONSOLE_INFORMATION. The major advantage to this plugin is it not only prints the commands attackers typed, but it collects the entire screen buffer (input and output). For instance, instead of just seeing "dir", you'll see exactly what the attacker saw, including all files and directories listed by the "dir" command.
pslist
To list the processes of a system, use the pslist command. This walks the doubly-linked list pointed to by PsActiveProcessHead and shows the offset, process name, process ID, the parent process ID, number of threads, number of handles, and date/time when the process started and exited. As of 2.1 it also shows the Session ID and if the process is a Wow64 process (it uses a 32 bit address space on a 64 bit kernel).
This plugin does not detect hidden or unlinked processes (but psscan can do that).
pstree
To view the process listing in tree form, use the pstree command. This enumerates processes using the same technique as pslist, so it will also not show hidden or unlinked processes. Child process are indicated using indention and periods.
envars
To display a process's environment variables, use the envars plugin. Typically this will show the number of CPUs installed and the hardware architecture (though the kdbgscan output is a much more reliable source), the process's current directory, temporary directory, session name, computer name, user name, and various other interesting artifacts.
Notes -
In Windows, each process is represented in memory by an _EPROCESS structure, which contains all the information the kernel needs to manage that process things like its PID, parent PID, handle table, and more. One important part of this structure is the ActiveProcessLinks field, which is used to link all active processes together in a doubly linked list.
A doubly linked list means each node (process) has two pointers: Flink points to the next process in the list, and Blink points to the previous one. This allows the kernel to quickly traverse the list in either direction.
The global symbol nt!PsActiveProcessHead points to the head of this list, which is essentially the starting point for enumerating all active processes. When you do something like:
dt nt!_list_entry poi(nt!PsActiveProcessHead)
you’re inspecting the first _LIST_ENTRY structure at the head of the list. The Flink and Blink pointers show the next and previous entries in memory, which themselves are offsets inside other _EPROCESS.ActiveProcessLinks fields.
To find the start of the full _EPROCESS structure for a given list entry, you subtract the offset of ActiveProcessLinks (in your case, 0x2e8 or 744 decimal) from the Flink address. This gives you the base address of the _EPROCESS structure that contains that list entry. Once you have the base, you can access any field, for example, ImageFileName:
dt nt!_eprocess 0xffffc582`ca5c3328-0x2e8 ImageFileName
This shows the name of the process, e.g., “Registry” or “csrss.exe”.
When you iterate through the Flinks of the doubly linked list starting from nt!PsActiveProcessHead, you’re effectively walking the entire list of active processes in the system. Each Flink points to the ActiveProcessLinks of the next _EPROCESS in memory, and subtracting the offset gives you that process’s structure. This is exactly what your !list command does: it traverses all entries and prints the ImageFileName for each.
Challenge Description
My friend John is an "environmental" activist and a humanitarian. He hated the ideology of Thanos from the Avengers: Infinity War. He sucks at programming. He used too many variables while writing any program. One day, John gave me a memory dump and asked me to find out what he was doing while he took the dump. Can you figure it out for me?
Solution
First i unizpped it to check whats inside the dump
[nix-shell:~/sid/CTF/memlabs]$ tar -xf Challenge.tar.xz
(.venv)
[nix-shell:~/sid/CTF/memlabs]$ ls
Challenge.raw Challenge.tar.xz shell.nix
(.venv)
Upon initial inspection of the memory dump Challenge.raw using the Volatility 3 framework, the windows.info command was executed to determine the system's profile. The analysis successfully identified the operating system as a 32-bit Windows 7 Service Pack 1, as indicated by the NTBuildLab string "7601.24260.x86fre.win7sp1_ldr.18". Key memory structure addresses, such as the Kernel Base at 0x82604000, were resolved, and the appropriate debugging symbols were automatically downloaded and parsed. The tool also extracted a crucial timestamp, revealing the system time was set to October 23, 2018, at 08:30:51 UTC, providing an initial temporal baseline for the investigation. .
Also The cool plugin pslist helps us see what proccesses were running
The investigation shows that the user logged in under Session ID 1, with explorer.exe (PID 324) serving as their main shell. From there, they opened a command prompt (cmd.exe, PID 2096) at 08:30:18 UTC.
SO since Cmd.exe was executed , we'll try to find what commands were used in the PS shell , using the plugin cmdscan
I attempted to retrieve the user’s command-line history directly using Volatility 3’s windows.cmdscan and windows.consoles plugins, both designed to pull command history from memory. Unfortunately, both plugins failed. They returned a NotImplementedError, stating that the Windows version in the memory image (6.1.15.7601) wasn’t supported. This meant I couldn’t access the console buffer or command history using my current Volatility build
Even when a program terminates, traces of its activity can remain in memory, including references to the files it opened. To search for such remnants, I used the windows.filescan plugin, which scans memory for _FILE_OBJECT structures representing files that were recently accessed by the system. At this stage, I didn’t know exactly which file I was looking for I simply wanted to see what had been opened around the time of the user’s session. As I reviewed the output, one entry immediately stood out: a file object pointing to \Users\hello\Desktop\demon.py.txt at the virtual address 0x3d4d1dc8
switched to volatility 2 : (
At this point, I decided to switch tools and try Volatility 2, since some plugins in Volatility 3 weren’t fully supported for this image. Using the consoles plugin, I was able to extract the full command-line history from the user’s active session. The output revealed two console processes: one associated with cmd.exe (PID 2096) and another with DumpIt.exe (PID 2412).
What caught my attention immediately was the command history linked to cmd.exe. It showed a single executed command:
C:\Python27\python.exe C:\Users\hello\Desktop\demon.py.txt
This confirmed that the user had explicitly run the Python interpreter to execute a script named demon.py.txt from their desktop. The captured screen buffer even showed the program’s output:
335d366f5d6031767631707f
This hexadecimal string was likely the key output or result produced by the script ?
After confirming that the user executed demon.py.txt, I wanted to see if there were any additional clues hidden in the system’s runtime environment. Processes often store useful information in environment variables, including configuration values, keys, or even passwords used during execution. To explore this, I ran the Volatility 2 plugin envars, which lists the environment variables for every process in memory.
While reviewing the output, one particular process stood out svchost.exe (PID 716). Among its environment variables, I discovered entries referencing “Thanos”, “xor”, and “password”.
After running several Volatility plugins, I decided to look into the environment variables using the envars plugin, since processes often store clues like encryption keys, commands, or passwords in memory. When I ran:
vol2 -f Challenge.raw --profile=Win7SP1x86 envars
I came across something interesting. Under the process svchost.exe (PID 716), I noticed an environment variable named Thanos with the value xor. Right next to it, there was also a password variable. At first, I didn’t quite understand what it meant, but seeing “xor” immediately made me think that the password might be hidden using a simple XOR cipher. This clue pointed me toward a potential decryption step.
To confirm this, I next decided to check for user credentials stored in memory. Using the hashdump plugin, I was able to extract NTLM password hashes from the memory image:
vol2 -f Challenge.raw --profile=Win7SP1x86 hashdump
The output revealed the following users and hashes:
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
hello:1000:aad3b435b51404eeaad3b435b51404ee:101da33f44e92c27835e64322d72e8b7:::
Given the earlier Thanos = xor clue, I suspected this string might be XOR-encrypted. So, I wrote a simple Python script to brute-force all possible XOR keys (0–255) and print the decrypted results:
a = "335d366f5d6031767631707f".decode("hex")
for i in range(0, 255):
b = ""
for j in a:
b += chr(ord(j) ^ i)
print(b)
Solving the hash and concatenating the xor output gave the flag : )
flag{you_are_good_but1_4m_b3tt3r}
Lab 1
kdbgscan is responsible for locating the Kernel Debugger Block (KDBG) within a memory dump. The KDBG is a core Windows kernel structure that stores critical metadata about the running operating system, including the kernel base address, OS build number,offsets to important kernel structures, and even information about active processes and loaded modules.
The way kdbgscan works is by scanning the memory dump for signatures that match the KDBG structure. Once found, it reports the addresses of the KDBG and other related kernel data. This allows Volatility to map the memory correctly and select the proper kernel symbols (PDBs) for analysis. For example, running vol -f MemoryDump_Lab1.raw windows.kdbgscan will output the kernel base, directory table base, and OS build number, all of which are essential for the other plugins to work properly.
After running pslist to see what all ran in the time the PC crashed i used PSlist
I could see System and smss.exe at the top, followed by critical processes like csrss.exe, winlogon.exe, and services.exe. Each entry showed the PID, parent PID, number of threads, handles, session IDs, and creation times. It was satisfying to watch the familiar Windows processes appear alongside some user-level programs like explorer.exe, mspaint.exe, and even DumpIt.exe, which hinted at how the memory dump was created
Also Vol3 automatically reads the KDBG structure from the memory dump and maps the kernel symbols for me.
These processes seem to be very out of place WinRAR.exe, mspaint.exe, wmpnetwk.exe
So lemme dump these and look more inside .
As a standard practise that i saw on last lab its good to see what all the computer was interacting with before it shut down . So we'll use netscan plugin : (
There's a wierd uh name under owner tag called ?J3???? ?
This might be the hacked process ig .
moving on to see if that had commmunicated with any console to run any commands to run output , ill use the console plugin .
This was very abnormal and i think one of them is a b64 flag and i see dumpit.exe which was used to make the .raw dump .
Decoding the b64 gives us
flag{th1s_1s_th3_1st_st4g3!!}
Ok now onto investigating mspaint and other sus process
After googling , i found out that u need to give the PID of the process to memdump plugin to dump the data and mspaint has 2424
Onto more investigation
Since it was a ms paint , i thought of opening it in ms paint itself to see if there's anything but nothing really came out , then i tried using gimp and changed all the extensions to png jpg and data . I also tried looking at the metadata and hex in hex editor but nothing quite was in them so it must be the image itself . After not getting anything after running steghide , binwalk , i refred the writeup and you just had to open it as a .data in gimp ... which i overcomplicated .
After opening it in gimp
After adjusting the values , i noticed a kinda text apperaing
Adjusting and playing around more gave me an image of the flag , alyssa was drawing but upside down tho
flag{G00d_BoY_good_girL}
For the third one , the process mentioned was wintrar
So lemme find that info and dump it using PID
And it unzipped to Important.rar , so findstr(ripgrep better) , i got this :
I assume the first coloumn values are offsets so id need to use them to extract later
Then i tried extracting and saw this :
C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>tar -xf Important_extracted.rar
flag3.png: Reading encrypted data is not currently supported: Illegal byte sequence
tar: Error exit delayed from previous errors.
Looks like im on the right track ?
Also it asks for a password tho , so we can check the hashes stored and see using the hashdump plugin : )
And then we can get the flag : p
Lab 2
Uhm the Challenge description says One of the clients of our company, lost the access to his system due to an unknown error. He is supposedly a very popular "environmental" activist. As a part of the investigation, he told us that his go to applications are browsers, his password managers etc. We hope that you can dig into this memory dump and find his important stuff and give it back to us.
Note: This challenge is composed of 3 flags.
Starting on some uhm keywords here , enviormental , browsers and password manager .
First things first , we have to see profile or image info using KDGB which will tell us info about the dump . This is only for vol 2.6 as vol 3 does this automatically
next as always we need to see what all was running while the , dump was taken so we'll use pslist
Sus processes that we would need to dump and investigate would be chrome.exe, keypass.exe ig
Also whats wmpnetwk.exe ?
Moving on next i like to do what was passed onto the consoles ...
WOW , hidden kbdx !!!!!
Grepping it , (findstr)
so we need a keypass sofware to unlock this and we'll need a password as well . Hopefull and luckily greping for pass gave a good info
A file called PASSWORD.PNG !!!!
lets dump and open it quickly , hopefully no gimp or offset changing rgb values .
Phew and we got the password :
The the right lower block ,
Now we have the password we can open the keypass software and get out first flag .
The workflow is to open this and see put the .kbdx and use the password we recovered and see if there's a flag
And we got the first flag : 3
But the flag contents said this is the 2nd flag ?
Reading the description again , i forgot to check the lead on enviorment variables
After checking for env using envars plugin i found a b64 on a TEMP_var
flag{w3lc0m3_T0_$T4g3_!_Of_L4B_2}
Now onto finding the 3rd flag the hint was chrome ? After googling how to get history and stuff related like downloads , there'a s plugin to extrcat chrome history : p
Also forgot to add , Win7SP1x64 !!, is how a Volatility profile identifier works . That means windoes 7 (why vol 3 dosent work smh) , Service pack 1 and X64 operation system .
Service Pack (SP) is a collection of updates, fixes etc stuff ..
After trying to get the chrome history i got into an error , apparently the plugin is broken for vol2 , so i'll just have to grep (findstr) chrome history
After going through the strings from the history dump i found a mega link
And this zip file needs a password which is the uh SHA1 of Lab 1 stage-3 : )
after doing that we get an image of the flag :) and we're dong with lab3
flag{oK_So_Now_St4g3_3_is_DoNE!!}
Lab 3
Starting off like any lab , we will do imageinfo or kdgbscan to see info about the OS
we can see that there are multiple window profiles ? so we might need to check for all the profiles ig
Moving onto to see what processes were running might give us more insight
Also we see dump it .exe running , and its used to make the memory dump . A intuitive way to think about this is that whatever was running before dumpit.exe should be our focus and here we see 2 notepad.exe 's running .
Now the workflow for any DFIR challenge is to dump the info that you see might be worth looking into , so lets do that
After running comndscan i got this
seems like no lead .
tehn i looked at the clues , which was about steghide ?? So i started searching for png , jpeg and jpg in the dump ..
And there was one actually :) jpeg
After dumping it and opening it i saw
So this image might have been steghided with a password and we'll need a password to uncover ig .
The way i thought was since steghide is a cmd line tool , the person who made the dump should run it on the commands line to steghide it . So the location or any insight could be that of getting the cmdline stdin .
So yea , earlier we say two things running on notepad.exe that might have been this python encryption texts ,
notepad.exe pid: 3736
Command line : "C:\Windows\system32\NOTEPAD.EXE" C:\Users\hello\Desktop\evilscript.py
************************************************************************
notepad.exe pid: 3432
Command line : "C:\Windows\system32\NOTEPAD.EXE" C:\Users\hello\Desktop\vip.txt
Dumping them
we get
C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>type vip.txt
am1gd2V4M20wXGs3b2U=
C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>type evilscript.py
import sys
import string
def xor(s):
a = ''.join(chr(ord(i)^3) for i in s)
return a
def encoder(x):
return x.encode("base64")
if __name__ == "__main__":
f = open("C:\\Users\\hello\\Desktop\\vip.txt", "w")
arr = sys.argv[1]
arr = encoder(xor(arr))
f.write(arr)
f.close()
vip.txt contained the base64 string am1gd2V4M20wXGs3b2U= and evilscript.py revealed the encoding routine: it XORs each character with the value 3 and then encodes the result with base64. Knowing this, I reversed the process by base64-decoding the vip.txt payload and XORing each byte with 3, which yielded the recovered secret: inctf{0n3_h4lf} :)
Since the description said , you need to use the first part to get the 2nd part i used the flag part 1 was a password to extract the info .
and we got the 2nd half
inctf{0n3_h4lf_1s_n0t_3n0ugh}
Lab 4
First lets run imageinfo using KDGB
Then lets see what proccess are there
Next , wel'll have to use a plugin called psxview :3
It cross-checks multiple methods (pslist, pstree, thrdproc, etc.) to find processes that might be hidden by rootkits.
C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>volatility_2.6_win64_standalone.exe -f "C:\Users\SIDDHARTH U\Downloads\MemLabs-Lab4\MemoryDump_Lab4.raw" --profile=Win7SP1x64 psxview
Volatility Foundation Volatility Framework 2.6
Offset(P) Name PID pslist psscan thrdproc pspcid csrss session deskthrd ExitTime
------------------ -------------------- ------ ------ ------ -------- ------ ----- ------- -------- --------
0x000000003e920350 conhost.exe 2636 True True True True True True True
0x000000003f1c1b30 services.exe 472 True True True True True True False
0x000000003fc62b30 dwm.exe 3000 True True True True True True True
0x000000003e930060 winlogon.exe 2728 True True True True True True True
0x000000003ec1b890 svchost.exe 220 True True True True True True True
0x000000003e8f0610 GoogleCrashHan 2272 True True True True True True False
0x000000003eaa4420 DumpIt.exe 2624 True True True True True True True
0x000000003efb9b30 svchost.exe 840 True True True True True True False
0x000000003ecaab30 spoolsv.exe 1132 True True True True True True True
0x000000003fceeb30 VBoxTray.exe 2384 True True True True True True True
0x000000003efacb30 svchost.exe 804 True True True True True True True
0x000000003eec1b30 lsm.exe 488 True True True True True True False
0x000000003eaf7b30 explorer.exe 1944 True True True True True True True
0x000000003e86e910 SearchProtocol 1696 True True True True True True True
0x000000003fcaeb30 explorer.exe 3012 True True True True True True True
0x000000003ed81b30 taskhost.exe 1804 True True True True True True True
0x000000003ef30b30 VBoxService.ex 640 True True True True True True False
0x000000003eeb5940 lsass.exe 480 True True True True True True False
0x000000003eff1060 audiodg.exe 952 True True True True True True True
0x000000003e892b30 dllhost.exe 2076 True True True True True True True
0x000000003ec45630 svchost.exe 484 True True True True True True True
0x000000003fc54b30 taskhost.exe 2976 True True True True True True True
0x000000003efc6850 svchost.exe 864 True True True True True True True
0x000000003e8f6b30 GoogleCrashHan 2284 True True True True True True False
0x000000003edf9630 taskeng.exe 1824 True True True True True True False
0x000000003ecd7b30 svchost.exe 1176 True True True True True True True
0x000000003ed452e0 svchost.exe 1276 True True True True True True True
0x000000003fd18b30 StikyNot.exe 2432 True True True True True True True
0x000000003ee6f760 wininit.exe 384 True True True True True True True
0x000000003e879890 SearchFilterHo 1688 True True True True True True True
0x000000003ebabab0 VBoxTray.exe 1592 True True True True True True True
0x000000003eabbb30 dwm.exe 1908 True True True True True True True
0x000000003ee751f0 winlogon.exe 412 True True True True True True True
0x000000003ef43a70 svchost.exe 708 True True True True True True True
0x000000003e801ab0 SearchIndexer. 1068 True True True True True True False
0x000000003ef02b30 svchost.exe 580 True True True True True True False
0x000000003ff67960 csrss.exe 376 True True True True False True True
0x000000003ee57b30 csrss.exe 328 True True True True False True True
0x000000003ff5f040 System 4 True True True True False False False
0x000000003f6af950 smss.exe 256 True True True True False False False
0x000000003eeac460 csrss.exe 2700 True True True True False True True
0x000000003edfab30 LogonUI.exe 2148 False True False False False False False 2019-06-29 07:29:59 UTC+0000
0x000000003ea94630 csrss.exe 2672 False True False False False False False 2019-06-29 07:29:59 UTC+0000
0x000000003fc5ab30 dllhost.exe 2572 False True False False False False False 2019-06-29 07:30:07 UTC+0000
Ok uhm there's a wierd proccess called StikyNot i can see .
and 2 proccess which were hidden
0x000000003ff67960 csrss.exe 376 True True True True False True True
0x000000003ee57b30 csrss.exe 328 True True True True False True True
My idea for now is to see what commands did these proccess run ?
for that cmdsline will help us
After that , we can see that , it spwaned stickey note program .
We'll dump the exe and see it later .
Moving onto to finding interesting stuff , a focus should be on identifying what kind of files are in the memory dump .
There are a lot of files now , but the user of the PC is called slim shady , so i'll search what files is under him or related to slimshady .
2019-06-27 13:14:13 UTC+0000 2019-06-27 13:14:13 UTC+0000 2019-06-27 13:14:13 UTC+0000 2019-06-27 13:14:13 UTC+0000 Users\SlimShady\Desktop\Important.txt
Volatility Foundation Volatility Framework 2.6
0x000000003e839710 2 2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003e83b2d0 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\Videos\desktop.ini
0x000000003e88a8c0 1 1 -W-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\FXSAPIDebugLogFile.txt
0x000000003e88ba20 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Themes\slideshow.ini
0x000000003e89b070 15 0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\GDIPFONTCACHEV1.DAT
0x000000003e8a85b0 2 0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\Flag not here.lnk
0x000000003e8a9610 16 0 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
0x000000003e8aa6f0 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
0x000000003e8ab250 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003e8acc40 17 1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
0x000000003e8ad250 14 0 R--r-- \Device\HarddiskVolume2\Users\eminem\Desktop\galf.jpeg
0x000000003e8af4a0 17 1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
0x000000003e8b04e0 15 0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
0x000000003e8b1a50 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\desktop.ini
0x000000003e8b2a80 1 1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
0x000000003e8bbf20 4 1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PID8EC.tmp
0x000000003e8c01a0 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003e8cdb20 15 0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003e8ce500 8 1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PIDAB5.tmp
0x000000003e8ce650 1 1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003e8d19e0 16 0 R--r-- \Device\HarddiskVolume2\Users\eminem\Desktop\Screenshot1.png
0x000000003e8d1c80 2 0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\galf.lnk
0x000000003e8d7dd0 2 0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\337ed59af273c758.customDestinations-ms
0x000000003e8da350 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003e8da630 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt
0x000000003e8e5a50 8 1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PIE007.tmp
0x000000003e8e5ba0 2 0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\Screenshot1.lnk
0x000000003e8e83c0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\Links
0x000000003e8ecc80 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003e8ecdd0 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003e8f1aa0 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\Links\desktop.ini
0x000000003e8fc590 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Network Shortcuts
0x000000003e9058a0 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003e905b80 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003e912190 6 0 R--r-d \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt\DumpIt.exe
0x000000003e915070 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\Links
0x000000003e9189d0 10 0 R--r-d \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt\DumpIt.exe
0x000000003e921a30 16 0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
0x000000003e922070 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt
0x000000003e925ab0 2 2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003ea20070 1 1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TM
0x000000003ea28c10 2 1 RW-r-- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
0x000000003ea34c10 1 1 RW---- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT
0x000000003ea35ac0 1 1 RW---- \Device\HarddiskVolume2\Users\eminem\ntuser.dat.LOG1
0x000000003ea35f20 1 1 RW---- \Device\HarddiskVolume2\Users\eminem\ntuser.dat.LOG2
0x000000003ea366b0 2 1 RW-r-- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
0x000000003ea37ad0 1 1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ea38dd0 2 1 RW-r-- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
0x000000003ea41960 2 1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ea44dd0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003ea60640 1 1 RW---- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat
0x000000003ea64850 1 1 RW---- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
0x000000003ea64f20 1 1 RW---- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
0x000000003ea66dc0 2 1 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TM.blf
0x000000003ea6cf20 2 1 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TMContainer00000000000000000001.regtrans-ms
0x000000003ea6d070 2 1 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TMContainer00000000000000000002.regtrans-ms
0x000000003ea75370 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Credentials
0x000000003ea7ea70 16 0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
0x000000003ea83890 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Credentials
0x000000003eaa4d00 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
0x000000003eaa8ea0 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003eae05d0 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\Pictures\desktop.ini
0x000000003eafe3c0 14 0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000006.db
0x000000003eb04f20 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003eb219e0 8 0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\IconCache.db
0x000000003eb27070 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
0x000000003eb5ad10 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop
0x000000003eb78f20 2 0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
0x000000003eb89790 2 2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003eb8ab30 16 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
0x000000003eb8bc90 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
0x000000003eb914f0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Burn
0x000000003eb91820 16 0 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop\desktop.ini
0x000000003eb91970 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Burn
0x000000003eb94a20 16 0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003eb95070 10 0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003eb95bb0 2 0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
0x000000003eba2070 2 0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk
0x000000003eba33b0 2 0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
0x000000003eba3e60 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop
0x000000003eba4d00 16 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
0x000000003eba84b0 16 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
0x000000003eba9d10 15 0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003ebaaf20 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
0x000000003ebab1e0 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
0x000000003ebab650 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
0x000000003ebac710 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
0x000000003ebaee50 16 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
0x000000003ebafa90 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
0x000000003ebb1070 16 0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003ebb36c0 16 0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003ebb5440 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003ebb91f0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003ebb99c0 16 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
0x000000003ebbaea0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003ebbca20 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003ebbfa70 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini
0x000000003ebc0690 8 0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
0x000000003ebc1670 16 0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003ebccdd0 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
0x000000003ebcd590 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\Documents\desktop.ini
0x000000003ebd05e0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003ebd1070 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003ebd2570 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
0x000000003ebdc890 2 0 R--rwd \Device\HarddiskVolume2\Users\eminem\Music\desktop.ini
0x000000003ebe2a20 1 1 RW-rw- \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt\2PAC-20190629-072925.raw
0x000000003ebe38e0 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003ebeedc0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003ec36d80 2 2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003ec45300 2 2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003ecd4070 2 0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
0x000000003edeb470 2 1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TM
0x000000003eeb97d0 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003eebb430 2 2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003ef033f0 2 1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Network Shortcuts
0x000000003ef47f20 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003eff6f20 16 0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms
0x000000003f602590 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003f7daa90 4 1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PID92B.tmp
0x000000003f9ccf20 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003f9ce930 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003f9cea80 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003f9cebd0 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003f9ffcb0 1 1 R--rw- \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt
0x000000003fc48070 1 1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>volatility_2.6_win64_standalone.exe -f "C:\Users\SIDDHARTH U\Downloads\MemLabs-Lab4\MemoryDump_Lab4.raw" --profile=Win7SP1x64 filescan | findstr "SlimShady"
Volatility Foundation Volatility Framework 2.6
0x000000003e900e60 2 1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
0x000000003e90df20 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\desktop.ini
0x000000003ed01740 1 1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ed382c0 2 1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
0x000000003ee47750 2 1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ee49c40 2 1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TM.blf
0x000000003ee4b480 1 1 RW---- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
0x000000003ee4b5d0 1 1 RW---- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat
0x000000003ee4cb20 2 1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TMContainer00000000000000000002.regtrans-ms
0x000000003ee4cc70 1 0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\337ed59af273c758.customDestinations-ms
0x000000003ee4cf20 1 1 RW---- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
0x000000003ee8e8c0 1 1 RW---- \Device\HarddiskVolume2\Users\SlimShady\ntuser.dat.LOG1
0x000000003ee9b590 16 0 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\9b9cdc69c1c24e2b.automaticDestinations-ms
0x000000003eeb6950 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003eeb7bb0 16 0 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
0x000000003eed64e0 16 0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
0x000000003eeec530 15 0 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003eeef070 17 1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
0x000000003f631070 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003f633d50 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
0x000000003f666aa0 1 1 RW---- \Device\HarddiskVolume2\Users\SlimShady\ntuser.dat.LOG2
0x000000003f939720 2 0 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\Important.lnk
0x000000003f9ff6d0 1 1 RW---- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT
0x000000003f9ff8e0 2 1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
0x000000003fc398d0 16 0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\Desktop\Important.txt
0x000000003fc39a20 17 1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
0x000000003fc39cd0 2 1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TMContainer00000000000000000001.regtrans-ms
0x000000003fc39f20 1 1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TM
0x000000003fc3c910 2 1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TM
0x000000003fc3dbb0 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Credentials
0x000000003fc3dd00 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Credentials
0x000000003fcbd070 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
0x000000003fcc5140 13 0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\IconCache.db
0x000000003fce9640 15 0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db
0x000000003fcedca0 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
0x000000003fcee070 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
0x000000003fcee1e0 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
0x000000003fcf0a20 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
0x000000003fcf9690 16 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Desktop\desktop.ini
0x000000003fcfa070 2 0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
0x000000003fcfb240 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Burn
0x000000003fcfba20 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
0x000000003fcfc7c0 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Burn
0x000000003fcfd320 2 0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
0x000000003fcfd5c0 1 1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003fcfd920 2 0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk
0x000000003fcfdb00 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Desktop
0x000000003fcfe810 2 0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
0x000000003fcfeac0 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Desktop
0x000000003fcfef20 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
0x000000003fd00280 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
0x000000003fd0a970 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
0x000000003fd0b070 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
0x000000003fd0b480 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
0x000000003fd13850 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Documents\desktop.ini
0x000000003fd15800 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
0x000000003fd17c80 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003fd17dd0 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003fd1a340 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Pictures\desktop.ini
0x000000003fd1bd50 11 0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
0x000000003fd1c490 18 2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003fd1c5e0 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
0x000000003fd214d0 18 2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003fd22d90 18 2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003fd23d10 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini
0x000000003fd24c70 18 2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003fd252e0 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Music\desktop.ini
0x000000003fd25bc0 18 2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003fd26840 18 2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003fd276c0 2 0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
0x000000003fd32070 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003fd32740 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003fd32890 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003fd32c80 2 1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003fd3d6d0 17 1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
0x000000003fd40910 17 1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt
0x000000003ff3dca0 1 0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms
From memlabs 2 , we should also see if there are any potential images , as they prolly hide a clue .
Ok so it's a joker image !
Also when i tried to dump the important.txt , it showed an exmpty file ? Even tho the offset was correct and all .
This lead me to exploring and goggling , and after some time i stumbled upon how to recvover deleated files .
After seaching it in the delated dump files we get the flag :)
flag inctf{1_is_n0t_EQu4l_7o_2_bUt_th1s_d0s3nt_m4ke_s3ns3}
Explaining the MFT table : p
Master File Table
01/07/2021
[This document applies only to version 3 of NTFS volumes.]
The master file table (MFT) stores the information required to retrieve files from an NTFS partition.
A file may have one or more MFT records, and can contain one or more attributes. In NTFS, a file reference is the MFT segment reference of the base file record. For more information, see MFT_SEGMENT_REFERENCE.
The MFT contains file record segments; the first 16 of these are reserved for special files, such as the following:
0: MFT ($Mft)
5: root directory (\)
6: volume cluster allocation file ($Bitmap)
8: bad-cluster file ($BadClus)
Each file record segment starts with a file record segment header. For more information, see FILE_RECORD_SEGMENT_HEADER. Each file record segment is followed by one or more attributes. Each attribute starts with an attribute record header. For more information, see ATTRIBUTE_RECORD_HEADER. The attribute record includes the attribute type (such as $DATA or $BITMAP), an optional name, and the attribute value. The user data stream is an attribute, as are all streams. The attribute list is terminated with 0xFFFFFFFF ($END).
The following are some example attributes.
The $Mft file contains an unnamed $DATA attribute that is the sequence of MFT record segments, in order.
The $Mft file contains an unnamed $BITMAP attribute that indicates which MFT records are in use.
The $Bitmap file contains an unnamed $DATA attribute that indicates which clusters are in use.
The $BadClus file contains a $DATA attribute named $BAD that contains an entry that corresponds to each bad cluster.
When there is no more space for storing attributes in the file record segment, additional file record segments are allocated and inserted in the first (or base) file record segment in an attribute called the attribute list. The attribute list indicates where each attribute associated with the file can be found. This includes all attributes in the base file record, except for the attribute list itself. For more information, see ATTRIBUTE_LIST_ENTRY.
Structures related to the MFT include the following:
ATTRIBUTE_LIST_ENTRY
ATTRIBUTE_RECORD_HEADER
FILE_NAME
FILE_RECORD_SEGMENT_HEADER
MFT_SEGMENT_REFERENCE
MULTI_SECTOR_HEADER
STANDARD_INFORMATION
The plugin that interests us for retrieving entries from the MFT table is "MFTParser".
Use mftparser output, filescan, pslist or vads to find processes that might have opened the file, and check pagefile or memory-mapped files for content. Timestamps can tell you which process was active when the file was created or deleted and guide you to memory region .
ach MFT entry is typically 1 KB in size and contains metadata about a file rather than the file data itself, though very small files may be stored directly within the entry.
Even after a file is deleted, the MFT entry is often left intact with a “deleted” flag. The space for its clusters may eventually be overwritten, but the metadata remains until reused
Lab 5
First rituals should be running pslist and kDBG scan
WIntrar !!, flahsbacks to first lab , we'll see if some zip file is there and try to dump it .
Okie so lets see what command was it used to spwan it from (not pstree but cmdline)
we're onto something here .
nvm it's actually the 2nd part and the password is the first part flag . (Hint: You’ll get the stage 2 flag only when you have the stage 1 flag.) opps
I tried to see deleated files , and then nothing happened ..
Now lets move onto hidden files and see if filescan can get us something .
Ok after locking in and reading the clues again , it's related to a network as the attacker is outside , so i started looking for plugins that could uncover this
Nothing much here tho .
AFter exploring more and reading a writeup for this , i came across a plugin which does
iehistory
This plugin recovers fragments of IE history index.dat cache files. It can find basic accessed links (via FTP or HTTP), redirected links ( - REDR), and deleted entries ( - LEAK). It applies to any process which loads and uses the wininet.dll library, not just Internet Explorer. Typically that includes Windows Explorer and even malware samples.
Decoding that gives the first flag :))
flag{!!w3LL_d0n3_St4g3–1_0f_L4B_5_D0n3!!} and entering that to the zipped wintrar file gives us the 2nd flag in an image
Lab 6
Lets check the profile info
This came from a 64-bit Windows 7 SP1 machine .
cmd.exe (PID 880) - suggests manual command-line activity.
chrome.exe instances (PIDs 2124, 2132, 2168, 2340, etc.) - multiple browser tabs
firefox.exe cluster (PIDs 2080–3316) - another browser session, possibly used concurrently
WinRAR.exe (PID 3716) - indicates file compression/extraction activity like before
Lets dump wintrar , it should be a direct indication of something
Yes and now let's dump it
AFter trying to unrar it , well it needs a password :((
C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>volatility_2.6_win64_standalone.exe --plugins=plugins/ -f "C:\Users\SIDDHARTH U\Downloads\MemLabs-Lab6\MemoryDump_Lab6.raw" --profile=Win7SP1x64 consoles
Volatility Foundation Volatility Framework 2.6
**************************************************
ConsoleProcess: conhost.exe Pid: 916
Console: 0xff086200 CommandHistorySize: 50
HistoryBufferCount: 2 HistoryBufferMax: 4
OriginalTitle: %SystemRoot%\system32\cmd.exe
Title: C:\Windows\system32\cmd.exe
AttachedProcess: cmd.exe Pid: 880 Handle: 0x60
----
CommandHistory: 0x1fedc0 Application: whoami.exe Flags:
CommandCount: 0 LastAdded: -1 LastDisplayed: -1
FirstCommand: 0 CommandCountMax: 50
ProcessHandle: 0x0
----
CommandHistory: 0x1feab0 Application: cmd.exe Flags: Allocated, Reset
CommandCount: 2 LastAdded: 1 LastDisplayed: 1
FirstCommand: 0 CommandCountMax: 50
ProcessHandle: 0x60
Cmd #0 at 0x1fd530: whoami
Cmd #1 at 0x1fdde0: env
----
Screen 0x1e0f80 X:80 Y:300
Dump:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
C:\Users\Jaffa>whoami
virus-pc\jaffa
C:\Users\Jaffa>env
'env' is not recognized as an internal or external command,
operable program or batch file.
C:\Users\Jaffa>
**************************************************
ConsoleProcess: conhost.exe Pid: 4092
Console: 0xff086200 CommandHistorySize: 50
HistoryBufferCount: 1 HistoryBufferMax: 4
OriginalTitle: C:\Users\Jaffa\Desktop\DumpIt.exe
Title: C:\Users\Jaffa\Desktop\DumpIt.exe
AttachedProcess: DumpIt.exe Pid: 4084 Handle: 0x60
----
CommandHistory: 0x30eab0 Application: DumpIt.exe Flags: Allocated
CommandCount: 0 LastAdded: -1 LastDisplayed: -1
FirstCommand: 0 CommandCountMax: 50
ProcessHandle: 0x60
----
Screen 0x2f0f80 X:80 Y:300
Dump:
DumpIt - v1.3.2.20110401 - One click memory memory dumper
Copyright (c) 2007 - 2011, Matthieu Suiche <http://www.msuiche.net>
Copyright (c) 2010 - 2011, MoonSols <http://www.moonsols.com>
Address space size: 1610547200 bytes ( 1535 Mb)
Free space size: 9889345536 bytes ( 9431 Mb)
* Destination = \??\C:\Users\Jaffa\Desktop\VIRUS-PC-20190819-144155.raw
--> Are you sure you want to continue? [y/n] y
+ Processing...
Jaffa tried running envars before dumpit.exe so that's a lead for us
From pervious lab refrence , lets try runnning envars for all the sus proccess we saw earlier .
Volatility Foundation Volatility Framework 2.6
Pid Process Block Variable Value
-------- -------------------- ------------------ ------------------------------ -----
2124 chrome.exe 0x00000000003453f0 ALLUSERSPROFILE C:\ProgramData
2124 chrome.exe 0x00000000003453f0 APPDATA C:\Users\Jaffa\AppData\Roaming
2124 chrome.exe 0x00000000003453f0 CHROME_CRASHPAD_PIPE_NAME \\.\pipe\crashpad_2124_HYPTHIKRKHINVSMY
2124 chrome.exe 0x00000000003453f0 CHROME_RESTART Google Chrome|Whoa! Google Chrome has crashed. Relaunch now?|LEFT_TO_RIGHT
2124 chrome.exe 0x00000000003453f0 CommonProgramFiles C:\Program Files\Common Files
2124 chrome.exe 0x00000000003453f0 CommonProgramFiles(x86) C:\Program Files (x86)\Common Files
2124 chrome.exe 0x00000000003453f0 CommonProgramW6432 C:\Program Files\Common Files
2124 chrome.exe 0x00000000003453f0 COMPUTERNAME VIRUS-PC
2124 chrome.exe 0x00000000003453f0 ComSpec C:\Windows\system32\cmd.exe
2124 chrome.exe 0x00000000003453f0 FP_NO_HOST_CHECK NO
2124 chrome.exe 0x00000000003453f0 HOMEDRIVE C:
2124 chrome.exe 0x00000000003453f0 HOMEPATH \Users\Jaffa
2124 chrome.exe 0x00000000003453f0 LOCALAPPDATA C:\Users\Jaffa\AppData\Local
2124 chrome.exe 0x00000000003453f0 LOGONSERVER \\VIRUS-PC
2124 chrome.exe 0x00000000003453f0 NUMBER_OF_PROCESSORS 1
2124 chrome.exe 0x00000000003453f0 OS Windows_NT
2124 chrome.exe 0x00000000003453f0 Path C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
2124 chrome.exe 0x00000000003453f0 PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
2124 chrome.exe 0x00000000003453f0 PROCESSOR_ARCHITECTURE AMD64
2124 chrome.exe 0x00000000003453f0 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
2124 chrome.exe 0x00000000003453f0 PROCESSOR_LEVEL 6
2124 chrome.exe 0x00000000003453f0 PROCESSOR_REVISION 9e0a
2124 chrome.exe 0x00000000003453f0 ProgramData C:\ProgramData
2124 chrome.exe 0x00000000003453f0 ProgramFiles C:\Program Files
2124 chrome.exe 0x00000000003453f0 ProgramFiles(x86) C:\Program Files (x86)
2124 chrome.exe 0x00000000003453f0 ProgramW6432 C:\Program Files
2124 chrome.exe 0x00000000003453f0 PSModulePath C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
2124 chrome.exe 0x00000000003453f0 PUBLIC C:\Users\Public
2124 chrome.exe 0x00000000003453f0 RAR password easypeasyvirus
2124 chrome.exe 0x00000000003453f0 SESSIONNAME Console
2124 chrome.exe 0x00000000003453f0 SystemDrive C:
2124 chrome.exe 0x00000000003453f0 SystemRoot C:\Windows
2124 chrome.exe 0x00000000003453f0 TEMP C:\Users\Jaffa\AppData\Local\Temp
2124 chrome.exe 0x00000000003453f0 TMP C:\Users\Jaffa\AppData\Local\Temp
2124 chrome.exe 0x00000000003453f0 USERDOMAIN VIRUS-PC
2124 chrome.exe 0x00000000003453f0 USERNAME Jaffa
2124 chrome.exe 0x00000000003453f0 USERPROFILE C:\Users\Jaffa
2124 chrome.exe 0x00000000003453f0 windir C:\Windows
2124 chrome.exe 0x00000000003453f0 windows_tracing_flags 3
2124 chrome.exe 0x00000000003453f0 windows_tracing_logfile C:\BVTBin\Tests\installpackage\csilogfile.log
2132 chrome.exe 0x0000000000561320 ALLUSERSPROFILE C:\ProgramData
2132 chrome.exe 0x0000000000561320 APPDATA C:\Users\Jaffa\AppData\Roaming
2132 chrome.exe 0x0000000000561320 CommonProgramFiles C:\Program Files\Common Files
2132 chrome.exe 0x0000000000561320 CommonProgramFiles(x86) C:\Program Files (x86)\Common Files
2132 chrome.exe 0x0000000000561320 CommonProgramW6432 C:\Program Files\Common Files
2132 chrome.exe 0x0000000000561320 COMPUTERNAME VIRUS-PC
2132 chrome.exe 0x0000000000561320 ComSpec C:\Windows\system32\cmd.exe
2132 chrome.exe 0x0000000000561320 FP_NO_HOST_CHECK NO
2132 chrome.exe 0x0000000000561320 HOMEDRIVE C:
2132 chrome.exe 0x0000000000561320 HOMEPATH \Users\Jaffa
2132 chrome.exe 0x0000000000561320 LOCALAPPDATA C:\Users\Jaffa\AppData\Local
2132 chrome.exe 0x0000000000561320 LOGONSERVER \\VIRUS-PC
2132 chrome.exe 0x0000000000561320 NUMBER_OF_PROCESSORS 1
2132 chrome.exe 0x0000000000561320 OS Windows_NT
2132 chrome.exe 0x0000000000561320 Path C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
2132 chrome.exe 0x0000000000561320 PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
2132 chrome.exe 0x0000000000561320 PROCESSOR_ARCHITECTURE AMD64
2132 chrome.exe 0x0000000000561320 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
2132 chrome.exe 0x0000000000561320 PROCESSOR_LEVEL 6
2132 chrome.exe 0x0000000000561320 PROCESSOR_REVISION 9e0a
2132 chrome.exe 0x0000000000561320 ProgramData C:\ProgramData
2132 chrome.exe 0x0000000000561320 ProgramFiles C:\Program Files
2132 chrome.exe 0x0000000000561320 ProgramFiles(x86) C:\Program Files (x86)
2132 chrome.exe 0x0000000000561320 ProgramW6432 C:\Program Files
2132 chrome.exe 0x0000000000561320 PSModulePath C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
2132 chrome.exe 0x0000000000561320 PUBLIC C:\Users\Public
2132 chrome.exe 0x0000000000561320 RAR password easypeasyvirus
2132 chrome.exe 0x0000000000561320 SESSIONNAME Console
2132 chrome.exe 0x0000000000561320 SystemDrive C:
2132 chrome.exe 0x0000000000561320 SystemRoot C:\Windows
2132 chrome.exe 0x0000000000561320 TEMP C:\Users\Jaffa\AppData\Local\Temp
2132 chrome.exe 0x0000000000561320 TMP C:\Users\Jaffa\AppData\Local\Temp
2132 chrome.exe 0x0000000000561320 USERDOMAIN VIRUS-PC
2132 chrome.exe 0x0000000000561320 USERNAME Jaffa
2132 chrome.exe 0x0000000000561320 USERPROFILE C:\Users\Jaffa
2132 chrome.exe 0x0000000000561320 windir C:\Windows
2132 chrome.exe 0x0000000000561320 windows_tracing_flags 3
2132 chrome.exe 0x0000000000561320 windows_tracing_logfile C:\BVTBin\Tests\installpackage\csilogfile.log
2168 chrome.exe 0x0000000000421320 ALLUSERSPROFILE C:\ProgramData
2168 chrome.exe 0x0000000000421320 APPDATA C:\Users\Jaffa\AppData\Roaming
2168 chrome.exe 0x0000000000421320 CHROME_CRASHPAD_PIPE_NAME \\.\pipe\crashpad_2124_HYPTHIKRKHINVSMY
2168 chrome.exe 0x0000000000421320 CommonProgramFiles C:\Program Files\Common Files
2168 chrome.exe 0x0000000000421320 CommonProgramFiles(x86) C:\Program Files (x86)\Common Files
2168 chrome.exe 0x0000000000421320 CommonProgramW6432 C:\Program Files\Common Files
2168 chrome.exe 0x0000000000421320 COMPUTERNAME VIRUS-PC
2168 chrome.exe 0x0000000000421320 ComSpec C:\Windows\system32\cmd.exe
2168 chrome.exe 0x0000000000421320 FP_NO_HOST_CHECK NO
2168 chrome.exe 0x0000000000421320 HOMEDRIVE C:
2168 chrome.exe 0x0000000000421320 HOMEPATH \Users\Jaffa
2168 chrome.exe 0x0000000000421320 LOCALAPPDATA C:\Users\Jaffa\AppData\Local
2168 chrome.exe 0x0000000000421320 LOGONSERVER \\VIRUS-PC
2168 chrome.exe 0x0000000000421320 NUMBER_OF_PROCESSORS 1
2168 chrome.exe 0x0000000000421320 OS Windows_NT
2168 chrome.exe 0x0000000000421320 Path C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
2168 chrome.exe 0x0000000000421320 PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
2168 chrome.exe 0x0000000000421320 PROCESSOR_ARCHITECTURE AMD64
2168 chrome.exe 0x0000000000421320 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
2168 chrome.exe 0x0000000000421320 PROCESSOR_LEVEL 6
2168 chrome.exe 0x0000000000421320 PROCESSOR_REVISION 9e0a
2168 chrome.exe 0x0000000000421320 ProgramData C:\ProgramData
2168 chrome.exe 0x0000000000421320 ProgramFiles C:\Program Files
2168 chrome.exe 0x0000000000421320 ProgramFiles(x86) C:\Program Files (x86)
2168 chrome.exe 0x0000000000421320 ProgramW6432 C:\Program Files
2168 chrome.exe 0x0000000000421320 PSModulePath C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
2168 chrome.exe 0x0000000000421320 PUBLIC C:\Users\Public
2168 chrome.exe 0x0000000000421320 RAR password easypeasyvirus
2168 chrome.exe 0x0000000000421320 SESSIONNAME Console
2168 chrome.exe 0x0000000000421320 SystemDrive C:
2168 chrome.exe 0x0000000000421320 SystemRoot C:\Windows
2168 chrome.exe 0x0000000000421320 TEMP C:\Users\Jaffa\AppData\Local\Temp
2168 chrome.exe 0x0000000000421320 TMP C:\Users\Jaffa\AppData\Local\Temp
2168 chrome.exe 0x0000000000421320 USERDOMAIN VIRUS-PC
2168 chrome.exe 0x0000000000421320 USERNAME Jaffa
2168 chrome.exe 0x0000000000421320 USERPROFILE C:\Users\Jaffa
2168 chrome.exe 0x0000000000421320 windir C:\Windows
2168 chrome.exe 0x0000000000421320 windows_tracing_flags 3
2168 chrome.exe 0x0000000000421320 windows_tracing_logfile C:\BVTBin\Tests\installpackage\csilogfile.log
2340 chrome.exe 0x0000000000551320 ALLUSERSPROFILE C:\ProgramData
2340 chrome.exe 0x0000000000551320 APPDATA C:\Users\Jaffa\AppData\Roaming
2340 chrome.exe 0x0000000000551320 CHROME_CRASHPAD_PIPE_NAME \\.\pipe\crashpad_2124_HYPTHIKRKHINVSMY
2340 chrome.exe 0x0000000000551320 CommonProgramFiles C:\Program Files\Common Files
2340 chrome.exe 0x0000000000551320 CommonProgramFiles(x86) C:\Program Files (x86)\Common Files
2340 chrome.exe 0x0000000000551320 CommonProgramW6432 C:\Program Files\Common Files
2340 chrome.exe 0x0000000000551320 COMPUTERNAME VIRUS-PC
2340 chrome.exe 0x0000000000551320 ComSpec C:\Windows\system32\cmd.exe
2340 chrome.exe 0x0000000000551320 FP_NO_HOST_CHECK NO
2340 chrome.exe 0x0000000000551320 HOMEDRIVE C:
2340 chrome.exe 0x0000000000551320 HOMEPATH \Users\Jaffa
2340 chrome.exe 0x0000000000551320 LOCALAPPDATA C:\Users\Jaffa\AppData\Local
2340 chrome.exe 0x0000000000551320 LOGONSERVER \\VIRUS-PC
2340 chrome.exe 0x0000000000551320 NUMBER_OF_PROCESSORS 1
2340 chrome.exe 0x0000000000551320 OS Windows_NT
2340 chrome.exe 0x0000000000551320 Path C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
2340 chrome.exe 0x0000000000551320 PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
2340 chrome.exe 0x0000000000551320 PROCESSOR_ARCHITECTURE AMD64
2340 chrome.exe 0x0000000000551320 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
2340 chrome.exe 0x0000000000551320 PROCESSOR_LEVEL 6
2340 chrome.exe 0x0000000000551320 PROCESSOR_REVISION 9e0a
2340 chrome.exe 0x0000000000551320 ProgramData C:\ProgramData
2340 chrome.exe 0x0000000000551320 ProgramFiles C:\Program Files
2340 chrome.exe 0x0000000000551320 ProgramFiles(x86) C:\Program Files (x86)
2340 chrome.exe 0x0000000000551320 ProgramW6432 C:\Program Files
2340 chrome.exe 0x0000000000551320 PSModulePath C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
2340 chrome.exe 0x0000000000551320 PUBLIC C:\Users\Public
2340 chrome.exe 0x0000000000551320 RAR password easypeasyvirus
2340 chrome.exe 0x0000000000551320 SESSIONNAME Console
2340 chrome.exe 0x0000000000551320 SystemDrive C:
2340 chrome.exe 0x0000000000551320 SystemRoot C:\Windows
2340 chrome.exe 0x0000000000551320 TEMP C:\Users\Jaffa\AppData\Local\Temp
2340 chrome.exe 0x0000000000551320 TMP C:\Users\Jaffa\AppData\Local\Temp
2340 chrome.exe 0x0000000000551320 USERDOMAIN VIRUS-PC
2340 chrome.exe 0x0000000000551320 USERNAME Jaffa
2340 chrome.exe 0x0000000000551320 USERPROFILE C:\Users\Jaffa
2340 chrome.exe 0x0000000000551320 windir C:\Windows
2340 chrome.exe 0x0000000000551320 windows_tracing_flags 3
2340 chrome.exe 0x0000000000551320 windows_tracing_logfile C:\BVTBin\Tests\installpackage\csilogfile.log
2080 firefox.exe 0x00000000005f1320 ALLUSERSPROFILE C:\ProgramData
2080 firefox.exe 0x00000000005f1320 APPDATA C:\Users\Jaffa\AppData\Roaming
2080 firefox.exe 0x00000000005f1320 CommonProgramFiles C:\Program Files\Common Files
2080 firefox.exe 0x00000000005f1320 CommonProgramFiles(x86) C:\Program Files (x86)\Common Files
2080 firefox.exe 0x00000000005f1320 CommonProgramW6432 C:\Program Files\Common Files
2080 firefox.exe 0x00000000005f1320 COMPUTERNAME VIRUS-PC
2080 firefox.exe 0x00000000005f1320 ComSpec C:\Windows\system32\cmd.exe
2080 firefox.exe 0x00000000005f1320 FP_NO_HOST_CHECK NO
2080 firefox.exe 0x00000000005f1320 HOMEDRIVE C:
2080 firefox.exe 0x00000000005f1320 HOMEPATH \Users\Jaffa
2080 firefox.exe 0x00000000005f1320 LOCALAPPDATA C:\Users\Jaffa\AppData\Local
2080 firefox.exe 0x00000000005f1320 LOGONSERVER \\VIRUS-PC
2080 firefox.exe 0x00000000005f1320 NUMBER_OF_PROCESSORS 1
2080 firefox.exe 0x00000000005f1320 OS Windows_NT
2080 firefox.exe 0x00000000005f1320 Path C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
2080 firefox.exe 0x00000000005f1320 PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
2080 firefox.exe 0x00000000005f1320 PROCESSOR_ARCHITECTURE AMD64
2080 firefox.exe 0x00000000005f1320 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
2080 firefox.exe 0x00000000005f1320 PROCESSOR_LEVEL 6
2080 firefox.exe 0x00000000005f1320 PROCESSOR_REVISION 9e0a
2080 firefox.exe 0x00000000005f1320 ProgramData C:\ProgramData
2080 firefox.exe 0x00000000005f1320 ProgramFiles C:\Program Files
2080 firefox.exe 0x00000000005f1320 ProgramFiles(x86) C:\Program Files (x86)
2080 firefox.exe 0x00000000005f1320 ProgramW6432 C:\Program Files
2080 firefox.exe 0x00000000005f1320 PSModulePath C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
2080 firefox.exe 0x00000000005f1320 PUBLIC C:\Users\Public
2080 firefox.exe 0x00000000005f1320 RAR password easypeasyvirus
2080 firefox.exe 0x00000000005f1320 SESSIONNAME Console
2080 firefox.exe 0x00000000005f1320 SystemDrive C:
2080 firefox.exe 0x00000000005f1320 SystemRoot C:\Windows
2080 firefox.exe 0x00000000005f1320 TEMP C:\Users\Jaffa\AppData\Local\Temp
2080 firefox.exe 0x00000000005f1320 TMP C:\Users\Jaffa\AppData\Local\Temp
2080 firefox.exe 0x00000000005f1320 USERDOMAIN VIRUS-PC
2080 firefox.exe 0x00000000005f1320 USERNAME Jaffa
2080 firefox.exe 0x00000000005f1320 USERPROFILE C:\Users\Jaffa
2080 firefox.exe 0x00000000005f1320 windir C:\Windows
2080 firefox.exe 0x00000000005f1320 windows_tracing_flags 3
2080 firefox.exe 0x00000000005f1320 windows_tracing_logfile C:\BVTBin\Tests\installpackage\csilogfile.log
3716 WinRAR.exe 0x00000000002a1320 ALLUSERSPROFILE C:\ProgramData
3716 WinRAR.exe 0x00000000002a1320 APPDATA C:\Users\Jaffa\AppData\Roaming
3716 WinRAR.exe 0x00000000002a1320 CommonProgramFiles C:\Program Files\Common Files
3716 WinRAR.exe 0x00000000002a1320 CommonProgramFiles(x86) C:\Program Files (x86)\Common Files
3716 WinRAR.exe 0x00000000002a1320 CommonProgramW6432 C:\Program Files\Common Files
3716 WinRAR.exe 0x00000000002a1320 COMPUTERNAME VIRUS-PC
3716 WinRAR.exe 0x00000000002a1320 ComSpec C:\Windows\system32\cmd.exe
3716 WinRAR.exe 0x00000000002a1320 FP_NO_HOST_CHECK NO
3716 WinRAR.exe 0x00000000002a1320 HOMEDRIVE C:
3716 WinRAR.exe 0x00000000002a1320 HOMEPATH \Users\Jaffa
3716 WinRAR.exe 0x00000000002a1320 LOCALAPPDATA C:\Users\Jaffa\AppData\Local
3716 WinRAR.exe 0x00000000002a1320 LOGONSERVER \\VIRUS-PC
3716 WinRAR.exe 0x00000000002a1320 NUMBER_OF_PROCESSORS 1
3716 WinRAR.exe 0x00000000002a1320 OS Windows_NT
3716 WinRAR.exe 0x00000000002a1320 Path C:\Program Files\WinRAR;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
3716 WinRAR.exe 0x00000000002a1320 PATHEXT .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
3716 WinRAR.exe 0x00000000002a1320 PROCESSOR_ARCHITECTURE AMD64
3716 WinRAR.exe 0x00000000002a1320 PROCESSOR_IDENTIFIER Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
3716 WinRAR.exe 0x00000000002a1320 PROCESSOR_LEVEL 6
3716 WinRAR.exe 0x00000000002a1320 PROCESSOR_REVISION 9e0a
3716 WinRAR.exe 0x00000000002a1320 ProgramData C:\ProgramData
3716 WinRAR.exe 0x00000000002a1320 ProgramFiles C:\Program Files
3716 WinRAR.exe 0x00000000002a1320 ProgramFiles(x86) C:\Program Files (x86)
3716 WinRAR.exe 0x00000000002a1320 ProgramW6432 C:\Program Files
3716 WinRAR.exe 0x00000000002a1320 PSModulePath C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
3716 WinRAR.exe 0x00000000002a1320 PUBLIC C:\Users\Public
3716 WinRAR.exe 0x00000000002a1320 RAR password easypeasyvirus
3716 WinRAR.exe 0x00000000002a1320 SESSIONNAME Console
3716 WinRAR.exe 0x00000000002a1320 SystemDrive C:
3716 WinRAR.exe 0x00000000002a1320 SystemRoot C:\Windows
3716 WinRAR.exe 0x00000000002a1320 TEMP C:\Users\Jaffa\AppData\Local\Temp
3716 WinRAR.exe 0x00000000002a1320 TMP C:\Users\Jaffa\AppData\Local\Temp
3716 WinRAR.exe 0x00000000002a1320 USERDOMAIN VIRUS-PC
3716 WinRAR.exe 0x00000000002a1320 USERNAME Jaffa
3716 WinRAR.exe 0x00000000002a1320 USERPROFILE C:\Users\Jaffa
3716 WinRAR.exe 0x00000000002a1320 windir C:\Windows
3716 WinRAR.exe 0x00000000002a1320 windows_tracing_flags 3
3716 WinRAR.exe 0x00000000002a1320 windows_tracing_logfile C:\BVTBin\Tests\installpackage\csilogfile.log
oh we actually got the rar password and it wasnt the flag of the 2nd one ..
Now let's extrcat it
and we get a 2nd'part of the flag?
Since the clues mentioned , a link to and we saw some chrome and firefox running mhmm lets try to see history .
I found a amazing volatilyt plugin repo which helped
AFter spending a lot of time and clicking a lot of dead ends , i spotted a pastebin link which lead to
mhm
And it had a mega link which needed a mhmm ,
This needs a password and i spend a lot of time looking for what to do next as there wasnt anything explicit mentioned ..