Home > Blog > MemLabs
MemLabs | Memory Forensics

these are my writeups for memlabs , i made some notes while studying to understand why this plugin and how does it inner working translate to do what we want and some theory stuff and document winapi in my own words and also not to just run tools and solve stuff and be a skid

Lab 0 - Never Too Late Mister

Plugins i used

consoles

Similar to cmdscan the consoles plugin finds commands that attackers typed into cmd.exe or executed via backdoors. However, instead of scanning for COMMAND_HISTORY, this plugin scans for CONSOLE_INFORMATION. The major advantage to this plugin is it not only prints the commands attackers typed, but it collects the entire screen buffer (input and output). For instance, instead of just seeing "dir", you'll see exactly what the attacker saw, including all files and directories listed by the "dir" command.

pslist

To list the processes of a system, use the pslist command. This walks the doubly-linked list pointed to by PsActiveProcessHead and shows the offset, process name, process ID, the parent process ID, number of threads, number of handles, and date/time when the process started and exited. As of 2.1 it also shows the Session ID and if the process is a Wow64 process (it uses a 32 bit address space on a 64 bit kernel).

This plugin does not detect hidden or unlinked processes (but psscan can do that).

pstree

To view the process listing in tree form, use the pstree command. This enumerates processes using the same technique as pslist, so it will also not show hidden or unlinked processes. Child process are indicated using indention and periods.

envars

To display a process's environment variables, use the envars plugin. Typically this will show the number of CPUs installed and the hardware architecture (though the kdbgscan output is a much more reliable source), the process's current directory, temporary directory, session name, computer name, user name, and various other interesting artifacts.

Notes -

In Windows, each process is represented in memory by an _EPROCESS structure, which contains all the information the kernel needs to manage that process things like its PID, parent PID, handle table, and more. One important part of this structure is the ActiveProcessLinks field, which is used to link all active processes together in a doubly linked list.

A doubly linked list means each node (process) has two pointers: Flink points to the next process in the list, and Blink points to the previous one. This allows the kernel to quickly traverse the list in either direction.

The global symbol nt!PsActiveProcessHead points to the head of this list, which is essentially the starting point for enumerating all active processes. When you do something like:

dt nt!_list_entry poi(nt!PsActiveProcessHead)

you’re inspecting the first _LIST_ENTRY structure at the head of the list. The Flink and Blink pointers show the next and previous entries in memory, which themselves are offsets inside other _EPROCESS.ActiveProcessLinks fields.

To find the start of the full _EPROCESS structure for a given list entry, you subtract the offset of ActiveProcessLinks (in your case, 0x2e8 or 744 decimal) from the Flink address. This gives you the base address of the _EPROCESS structure that contains that list entry. Once you have the base, you can access any field, for example, ImageFileName:

dt nt!_eprocess 0xffffc582`ca5c3328-0x2e8 ImageFileName

This shows the name of the process, e.g., “Registry” or “csrss.exe”.

When you iterate through the Flinks of the doubly linked list starting from nt!PsActiveProcessHead, you’re effectively walking the entire list of active processes in the system. Each Flink points to the ActiveProcessLinks of the next _EPROCESS in memory, and subtracting the offset gives you that process’s structure. This is exactly what your !list command does: it traverses all entries and prints the ImageFileName for each.

Challenge Description

My friend John is an "environmental" activist and a humanitarian. He hated the ideology of Thanos from the Avengers: Infinity War. He sucks at programming. He used too many variables while writing any program. One day, John gave me a memory dump and asked me to find out what he was doing while he took the dump. Can you figure it out for me?

Solution

First i unizpped it to check whats inside the dump

[nix-shell:~/sid/CTF/memlabs]$ tar -xf Challenge.tar.xz
(.venv) 
[nix-shell:~/sid/CTF/memlabs]$ ls
Challenge.raw  Challenge.tar.xz  shell.nix
(.venv)

Upon initial inspection of the memory dump Challenge.raw using the Volatility 3 framework, the windows.info command was executed to determine the system's profile. The analysis successfully identified the operating system as a 32-bit Windows 7 Service Pack 1, as indicated by the NTBuildLab string "7601.24260.x86fre.win7sp1_ldr.18". Key memory structure addresses, such as the Kernel Base at 0x82604000, were resolved, and the appropriate debugging symbols were automatically downloaded and parsed. The tool also extracted a crucial timestamp, revealing the system time was set to October 23, 2018, at 08:30:51 UTC, providing an initial temporal baseline for the investigation. .

screenshot-1759772865

Also The cool plugin pslist helps us see what proccesses were running

screenshot-1759772947

The investigation shows that the user logged in under Session ID 1, with explorer.exe (PID 324) serving as their main shell. From there, they opened a command prompt (cmd.exe, PID 2096) at 08:30:18 UTC.

SO since Cmd.exe was executed , we'll try to find what commands were used in the PS shell , using the plugin cmdscan

I attempted to retrieve the user’s command-line history directly using Volatility 3’s windows.cmdscan and windows.consoles plugins, both designed to pull command history from memory. Unfortunately, both plugins failed. They returned a NotImplementedError, stating that the Windows version in the memory image (6.1.15.7601) wasn’t supported. This meant I couldn’t access the console buffer or command history using my current Volatility build

Even when a program terminates, traces of its activity can remain in memory, including references to the files it opened. To search for such remnants, I used the windows.filescan plugin, which scans memory for _FILE_OBJECT structures representing files that were recently accessed by the system. At this stage, I didn’t know exactly which file I was looking for I simply wanted to see what had been opened around the time of the user’s session. As I reviewed the output, one entry immediately stood out: a file object pointing to \Users\hello\Desktop\demon.py.txt at the virtual address 0x3d4d1dc8

switched to volatility 2 : (

At this point, I decided to switch tools and try Volatility 2, since some plugins in Volatility 3 weren’t fully supported for this image. Using the consoles plugin, I was able to extract the full command-line history from the user’s active session. The output revealed two console processes: one associated with cmd.exe (PID 2096) and another with DumpIt.exe (PID 2412).

What caught my attention immediately was the command history linked to cmd.exe. It showed a single executed command:

C:\Python27\python.exe C:\Users\hello\Desktop\demon.py.txt

This confirmed that the user had explicitly run the Python interpreter to execute a script named demon.py.txt from their desktop. The captured screen buffer even showed the program’s output:

335d366f5d6031767631707f

This hexadecimal string was likely the key output or result produced by the script ?

screenshot-1759775791

After confirming that the user executed demon.py.txt, I wanted to see if there were any additional clues hidden in the system’s runtime environment. Processes often store useful information in environment variables, including configuration values, keys, or even passwords used during execution. To explore this, I ran the Volatility 2 plugin envars, which lists the environment variables for every process in memory.

While reviewing the output, one particular process stood out svchost.exe (PID 716). Among its environment variables, I discovered entries referencing “Thanos”, “xor”, and “password”.

After running several Volatility plugins, I decided to look into the environment variables using the envars plugin, since processes often store clues like encryption keys, commands, or passwords in memory. When I ran:

vol2 -f Challenge.raw --profile=Win7SP1x86 envars

I came across something interesting. Under the process svchost.exe (PID 716), I noticed an environment variable named Thanos with the value xor. Right next to it, there was also a password variable. At first, I didn’t quite understand what it meant, but seeing “xor” immediately made me think that the password might be hidden using a simple XOR cipher. This clue pointed me toward a potential decryption step.

To confirm this, I next decided to check for user credentials stored in memory. Using the hashdump plugin, I was able to extract NTLM password hashes from the memory image:

vol2 -f Challenge.raw --profile=Win7SP1x86 hashdump

The output revealed the following users and hashes:

Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
hello:1000:aad3b435b51404eeaad3b435b51404ee:101da33f44e92c27835e64322d72e8b7:::

Given the earlier Thanos = xor clue, I suspected this string might be XOR-encrypted. So, I wrote a simple Python script to brute-force all possible XOR keys (0–255) and print the decrypted results:

a = "335d366f5d6031767631707f".decode("hex")

for i in range(0, 255):
    b = ""
    for j in a:
        b += chr(ord(j) ^ i)
    print(b)

Solving the hash and concatenating the xor output gave the flag : )

flag{you_are_good_but1_4m_b3tt3r}


Lab 1

kdbgscan is responsible for locating the Kernel Debugger Block (KDBG) within a memory dump. The KDBG is a core Windows kernel structure that stores critical metadata about the running operating system, including the kernel base address, OS build number,offsets to important kernel structures, and even information about active processes and loaded modules.

The way kdbgscan works is by scanning the memory dump for signatures that match the KDBG structure. Once found, it reports the addresses of the KDBG and other related kernel data. This allows Volatility to map the memory correctly and select the proper kernel symbols (PDBs) for analysis. For example, running vol -f MemoryDump_Lab1.raw windows.kdbgscan will output the kernel base, directory table base, and OS build number, all of which are essential for the other plugins to work properly.

image

After running pslist to see what all ran in the time the PC crashed i used PSlist

image

I could see System and smss.exe at the top, followed by critical processes like csrss.exe, winlogon.exe, and services.exe. Each entry showed the PID, parent PID, number of threads, handles, session IDs, and creation times. It was satisfying to watch the familiar Windows processes appear alongside some user-level programs like explorer.exe, mspaint.exe, and even DumpIt.exe, which hinted at how the memory dump was created

Also Vol3 automatically reads the KDBG structure from the memory dump and maps the kernel symbols for me.

These processes seem to be very out of place WinRAR.exe, mspaint.exe, wmpnetwk.exe

So lemme dump these and look more inside .

As a standard practise that i saw on last lab its good to see what all the computer was interacting with before it shut down . So we'll use netscan plugin : (

image

There's a wierd uh name under owner tag called ?J3???? ?

This might be the hacked process ig .

moving on to see if that had commmunicated with any console to run any commands to run output , ill use the console plugin .

image

This was very abnormal and i think one of them is a b64 flag and i see dumpit.exe which was used to make the .raw dump .

Decoding the b64 gives us

flag{th1s_1s_th3_1st_st4g3!!}

Ok now onto investigating mspaint and other sus process

After googling , i found out that u need to give the PID of the process to memdump plugin to dump the data and mspaint has 2424

image

Onto more investigation

Since it was a ms paint , i thought of opening it in ms paint itself to see if there's anything but nothing really came out , then i tried using gimp and changed all the extensions to png jpg and data . I also tried looking at the metadata and hex in hex editor but nothing quite was in them so it must be the image itself . After not getting anything after running steghide , binwalk , i refred the writeup and you just had to open it as a .data in gimp ... which i overcomplicated .

After opening it in gimp

image

After adjusting the values , i noticed a kinda text apperaing

image

Adjusting and playing around more gave me an image of the flag , alyssa was drawing but upside down tho

image
flag{G00d_BoY_good_girL}

For the third one , the process mentioned was wintrar

So lemme find that info and dump it using PID

image

And it unzipped to Important.rar , so findstr(ripgrep better) , i got this :

image

I assume the first coloumn values are offsets so id need to use them to extract later

image

Then i tried extracting and saw this :

C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>tar -xf Important_extracted.rar
flag3.png: Reading encrypted data is not currently supported: Illegal byte sequence
tar: Error exit delayed from previous errors.

Looks like im on the right track ?

Also it asks for a password tho , so we can check the hashes stored and see using the hashdump plugin : )

image

And then we can get the flag : p

image

Lab 2

Uhm the Challenge description says One of the clients of our company, lost the access to his system due to an unknown error. He is supposedly a very popular "environmental" activist. As a part of the investigation, he told us that his go to applications are browsers, his password managers etc. We hope that you can dig into this memory dump and find his important stuff and give it back to us.

Note: This challenge is composed of 3 flags.

Starting on some uhm keywords here , enviormental , browsers and password manager .

First things first , we have to see profile or image info using KDGB which will tell us info about the dump . This is only for vol 2.6 as vol 3 does this automatically

image

next as always we need to see what all was running while the , dump was taken so we'll use pslist

image

Sus processes that we would need to dump and investigate would be chrome.exe, keypass.exe ig

Also whats wmpnetwk.exe ?

Moving on next i like to do what was passed onto the consoles ...

image

WOW , hidden kbdx !!!!!

Grepping it , (findstr)

image

so we need a keypass sofware to unlock this and we'll need a password as well . Hopefull and luckily greping for pass gave a good info

A file called PASSWORD.PNG !!!!

lets dump and open it quickly , hopefully no gimp or offset changing rgb values .

Phew and we got the password :

image

The the right lower block ,

Now we have the password we can open the keypass software and get out first flag .

image

The workflow is to open this and see put the .kbdx and use the password we recovered and see if there's a flag

image

And we got the first flag : 3

image

But the flag contents said this is the 2nd flag ?

Reading the description again , i forgot to check the lead on enviorment variables

After checking for env using envars plugin i found a b64 on a TEMP_var

image
flag{w3lc0m3_T0_$T4g3_!_Of_L4B_2}

Now onto finding the 3rd flag the hint was chrome ? After googling how to get history and stuff related like downloads , there'a s plugin to extrcat chrome history : p

Also forgot to add , Win7SP1x64 !!, is how a Volatility profile identifier works . That means windoes 7 (why vol 3 dosent work smh) , Service pack 1 and X64 operation system .

Service Pack (SP) is a collection of updates, fixes etc stuff ..

After trying to get the chrome history i got into an error , apparently the plugin is broken for vol2 , so i'll just have to grep (findstr) chrome history

image

After going through the strings from the history dump i found a mega link

image openin that image

And this zip file needs a password which is the uh SHA1 of Lab 1 stage-3 : )

after doing that we get an image of the flag :) and we're dong with lab3

flag{oK_So_Now_St4g3_3_is_DoNE!!}


Lab 3

Starting off like any lab , we will do imageinfo or kdgbscan to see info about the OS

image

we can see that there are multiple window profiles ? so we might need to check for all the profiles ig

Moving onto to see what processes were running might give us more insight

image

Also we see dump it .exe running , and its used to make the memory dump . A intuitive way to think about this is that whatever was running before dumpit.exe should be our focus and here we see 2 notepad.exe 's running .

Now the workflow for any DFIR challenge is to dump the info that you see might be worth looking into , so lets do that

image

After running comndscan i got this

image

seems like no lead .

tehn i looked at the clues , which was about steghide ?? So i started searching for png , jpeg and jpg in the dump ..

And there was one actually :) jpeg

image

After dumping it and opening it i saw

image

So this image might have been steghided with a password and we'll need a password to uncover ig .

The way i thought was since steghide is a cmd line tool , the person who made the dump should run it on the commands line to steghide it . So the location or any insight could be that of getting the cmdline stdin .

image

So yea , earlier we say two things running on notepad.exe that might have been this python encryption texts ,

notepad.exe pid:   3736
Command line : "C:\Windows\system32\NOTEPAD.EXE" C:\Users\hello\Desktop\evilscript.py
************************************************************************
notepad.exe pid:   3432
Command line : "C:\Windows\system32\NOTEPAD.EXE" C:\Users\hello\Desktop\vip.txt
image

Dumping them

we get

C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>type vip.txt
am1gd2V4M20wXGs3b2U=

C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>type evilscript.py
import sys
import string

def xor(s):

        a = ''.join(chr(ord(i)^3) for i in s)
        return a


def encoder(x):

        return x.encode("base64")


if __name__ == "__main__":

        f = open("C:\\Users\\hello\\Desktop\\vip.txt", "w")

        arr = sys.argv[1]

        arr = encoder(xor(arr))

        f.write(arr)

        f.close()

vip.txt contained the base64 string am1gd2V4M20wXGs3b2U= and evilscript.py revealed the encoding routine: it XORs each character with the value 3 and then encodes the result with base64. Knowing this, I reversed the process by base64-decoding the vip.txt payload and XORing each byte with 3, which yielded the recovered secret: inctf{0n3_h4lf} :)

Since the description said , you need to use the first part to get the 2nd part i used the flag part 1 was a password to extract the info .

image

and we got the 2nd half

image
inctf{0n3_h4lf_1s_n0t_3n0ugh}

Lab 4

First lets run imageinfo using KDGB

image

Then lets see what proccess are there

image

Next , wel'll have to use a plugin called psxview :3

image

It cross-checks multiple methods (pslist, pstree, thrdproc, etc.) to find processes that might be hidden by rootkits.

C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>volatility_2.6_win64_standalone.exe -f "C:\Users\SIDDHARTH U\Downloads\MemLabs-Lab4\MemoryDump_Lab4.raw" --profile=Win7SP1x64 psxview
Volatility Foundation Volatility Framework 2.6
Offset(P)          Name                    PID pslist psscan thrdproc pspcid csrss session deskthrd ExitTime
------------------ -------------------- ------ ------ ------ -------- ------ ----- ------- -------- --------
0x000000003e920350 conhost.exe            2636 True   True   True     True   True  True    True
0x000000003f1c1b30 services.exe            472 True   True   True     True   True  True    False
0x000000003fc62b30 dwm.exe                3000 True   True   True     True   True  True    True
0x000000003e930060 winlogon.exe           2728 True   True   True     True   True  True    True
0x000000003ec1b890 svchost.exe             220 True   True   True     True   True  True    True
0x000000003e8f0610 GoogleCrashHan         2272 True   True   True     True   True  True    False
0x000000003eaa4420 DumpIt.exe             2624 True   True   True     True   True  True    True
0x000000003efb9b30 svchost.exe             840 True   True   True     True   True  True    False
0x000000003ecaab30 spoolsv.exe            1132 True   True   True     True   True  True    True
0x000000003fceeb30 VBoxTray.exe           2384 True   True   True     True   True  True    True
0x000000003efacb30 svchost.exe             804 True   True   True     True   True  True    True
0x000000003eec1b30 lsm.exe                 488 True   True   True     True   True  True    False
0x000000003eaf7b30 explorer.exe           1944 True   True   True     True   True  True    True
0x000000003e86e910 SearchProtocol         1696 True   True   True     True   True  True    True
0x000000003fcaeb30 explorer.exe           3012 True   True   True     True   True  True    True
0x000000003ed81b30 taskhost.exe           1804 True   True   True     True   True  True    True
0x000000003ef30b30 VBoxService.ex          640 True   True   True     True   True  True    False
0x000000003eeb5940 lsass.exe               480 True   True   True     True   True  True    False
0x000000003eff1060 audiodg.exe             952 True   True   True     True   True  True    True
0x000000003e892b30 dllhost.exe            2076 True   True   True     True   True  True    True
0x000000003ec45630 svchost.exe             484 True   True   True     True   True  True    True
0x000000003fc54b30 taskhost.exe           2976 True   True   True     True   True  True    True
0x000000003efc6850 svchost.exe             864 True   True   True     True   True  True    True
0x000000003e8f6b30 GoogleCrashHan         2284 True   True   True     True   True  True    False
0x000000003edf9630 taskeng.exe            1824 True   True   True     True   True  True    False
0x000000003ecd7b30 svchost.exe            1176 True   True   True     True   True  True    True
0x000000003ed452e0 svchost.exe            1276 True   True   True     True   True  True    True
0x000000003fd18b30 StikyNot.exe           2432 True   True   True     True   True  True    True
0x000000003ee6f760 wininit.exe             384 True   True   True     True   True  True    True
0x000000003e879890 SearchFilterHo         1688 True   True   True     True   True  True    True
0x000000003ebabab0 VBoxTray.exe           1592 True   True   True     True   True  True    True
0x000000003eabbb30 dwm.exe                1908 True   True   True     True   True  True    True
0x000000003ee751f0 winlogon.exe            412 True   True   True     True   True  True    True
0x000000003ef43a70 svchost.exe             708 True   True   True     True   True  True    True
0x000000003e801ab0 SearchIndexer.         1068 True   True   True     True   True  True    False
0x000000003ef02b30 svchost.exe             580 True   True   True     True   True  True    False
0x000000003ff67960 csrss.exe               376 True   True   True     True   False True    True
0x000000003ee57b30 csrss.exe               328 True   True   True     True   False True    True
0x000000003ff5f040 System                    4 True   True   True     True   False False   False
0x000000003f6af950 smss.exe                256 True   True   True     True   False False   False
0x000000003eeac460 csrss.exe              2700 True   True   True     True   False True    True
0x000000003edfab30 LogonUI.exe            2148 False  True   False    False  False False   False    2019-06-29 07:29:59 UTC+0000
0x000000003ea94630 csrss.exe              2672 False  True   False    False  False False   False    2019-06-29 07:29:59 UTC+0000
0x000000003fc5ab30 dllhost.exe            2572 False  True   False    False  False False   False    2019-06-29 07:30:07 UTC+0000

Ok uhm there's a wierd proccess called StikyNot i can see .

and 2 proccess which were hidden

0x000000003ff67960 csrss.exe               376 True   True   True     True   False True    True
0x000000003ee57b30 csrss.exe               328 True   True   True     True   False True    True

My idea for now is to see what commands did these proccess run ?

for that cmdsline will help us

image

After that , we can see that , it spwaned stickey note program .

image

We'll dump the exe and see it later .

Moving onto to finding interesting stuff , a focus should be on identifying what kind of files are in the memory dump .

There are a lot of files now , but the user of the PC is called slim shady , so i'll search what files is under him or related to slimshady .

2019-06-27 13:14:13 UTC+0000 2019-06-27 13:14:13 UTC+0000   2019-06-27 13:14:13 UTC+0000   2019-06-27 13:14:13 UTC+0000   Users\SlimShady\Desktop\Important.txt
Volatility Foundation Volatility Framework 2.6
0x000000003e839710      2      2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003e83b2d0      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\Videos\desktop.ini
0x000000003e88a8c0      1      1 -W-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\FXSAPIDebugLogFile.txt
0x000000003e88ba20      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Themes\slideshow.ini
0x000000003e89b070     15      0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\GDIPFONTCACHEV1.DAT
0x000000003e8a85b0      2      0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\Flag not here.lnk
0x000000003e8a9610     16      0 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
0x000000003e8aa6f0      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
0x000000003e8ab250      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003e8acc40     17      1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
0x000000003e8ad250     14      0 R--r-- \Device\HarddiskVolume2\Users\eminem\Desktop\galf.jpeg
0x000000003e8af4a0     17      1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
0x000000003e8b04e0     15      0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
0x000000003e8b1a50      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\desktop.ini
0x000000003e8b2a80      1      1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
0x000000003e8bbf20      4      1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PID8EC.tmp
0x000000003e8c01a0      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003e8cdb20     15      0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003e8ce500      8      1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PIDAB5.tmp
0x000000003e8ce650      1      1 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003e8d19e0     16      0 R--r-- \Device\HarddiskVolume2\Users\eminem\Desktop\Screenshot1.png
0x000000003e8d1c80      2      0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\galf.lnk
0x000000003e8d7dd0      2      0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\337ed59af273c758.customDestinations-ms
0x000000003e8da350      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003e8da630      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt
0x000000003e8e5a50      8      1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PIE007.tmp
0x000000003e8e5ba0      2      0 RW-rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\Screenshot1.lnk
0x000000003e8e83c0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\Links
0x000000003e8ecc80      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003e8ecdd0      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003e8f1aa0      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\Links\desktop.ini
0x000000003e8fc590      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Network Shortcuts
0x000000003e9058a0      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003e905b80      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003e912190      6      0 R--r-d \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt\DumpIt.exe
0x000000003e915070      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\Links
0x000000003e9189d0     10      0 R--r-d \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt\DumpIt.exe
0x000000003e921a30     16      0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
0x000000003e922070      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt
0x000000003e925ab0      2      2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003ea20070      1      1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TM
0x000000003ea28c10      2      1 RW-r-- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
0x000000003ea34c10      1      1 RW---- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT
0x000000003ea35ac0      1      1 RW---- \Device\HarddiskVolume2\Users\eminem\ntuser.dat.LOG1
0x000000003ea35f20      1      1 RW---- \Device\HarddiskVolume2\Users\eminem\ntuser.dat.LOG2
0x000000003ea366b0      2      1 RW-r-- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
0x000000003ea37ad0      1      1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ea38dd0      2      1 RW-r-- \Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
0x000000003ea41960      2      1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\eminem\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ea44dd0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003ea60640      1      1 RW---- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat
0x000000003ea64850      1      1 RW---- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
0x000000003ea64f20      1      1 RW---- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
0x000000003ea66dc0      2      1 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TM.blf
0x000000003ea6cf20      2      1 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TMContainer00000000000000000001.regtrans-ms
0x000000003ea6d070      2      1 RW-r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TMContainer00000000000000000002.regtrans-ms
0x000000003ea75370      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Credentials
0x000000003ea7ea70     16      0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
0x000000003ea83890      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Credentials
0x000000003eaa4d00      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
0x000000003eaa8ea0      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003eae05d0      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\Pictures\desktop.ini
0x000000003eafe3c0     14      0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000006.db
0x000000003eb04f20      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003eb219e0      8      0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Local\IconCache.db
0x000000003eb27070      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms
0x000000003eb5ad10      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop
0x000000003eb78f20      2      0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
0x000000003eb89790      2      2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003eb8ab30     16      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
0x000000003eb8bc90      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
0x000000003eb914f0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Burn
0x000000003eb91820     16      0 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop\desktop.ini
0x000000003eb91970      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Burn
0x000000003eb94a20     16      0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003eb95070     10      0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003eb95bb0      2      0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
0x000000003eba2070      2      0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk
0x000000003eba33b0      2      0 R--rw- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
0x000000003eba3e60      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\Desktop
0x000000003eba4d00     16      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
0x000000003eba84b0     16      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
0x000000003eba9d10     15      0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003ebaaf20      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
0x000000003ebab1e0      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
0x000000003ebab650      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
0x000000003ebac710      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
0x000000003ebaee50     16      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
0x000000003ebafa90      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
0x000000003ebb1070     16      0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003ebb36c0     16      0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003ebb5440      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003ebb91f0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003ebb99c0     16      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
0x000000003ebbaea0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003ebbca20      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003ebbfa70      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini
0x000000003ebc0690      8      0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
0x000000003ebc1670     16      0 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003ebccdd0      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
0x000000003ebcd590      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\Documents\desktop.ini
0x000000003ebd05e0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003ebd1070      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003ebd2570      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
0x000000003ebdc890      2      0 R--rwd \Device\HarddiskVolume2\Users\eminem\Music\desktop.ini
0x000000003ebe2a20      1      1 RW-rw- \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt\2PAC-20190629-072925.raw
0x000000003ebe38e0      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003ebeedc0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003ec36d80      2      2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003ec45300      2      2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003ecd4070      2      0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
0x000000003edeb470      2      1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\UsrClass.dat{a96b97fe-96f7-11e9-9a46-0800275e72bc}.TM
0x000000003eeb97d0      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003eebb430      2      2 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003ef033f0      2      1 R--rwd \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Network Shortcuts
0x000000003ef47f20      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003eff6f20     16      0 R--r-- \Device\HarddiskVolume2\Users\eminem\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms
0x000000003f602590      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003f7daa90      4      1 RWD--- \Device\HarddiskVolume2\Users\eminem\AppData\Local\Temp\~PID92B.tmp
0x000000003f9ccf20      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003f9ce930      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003f9cea80      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003f9cebd0      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003f9ffcb0      1      1 R--rw- \Device\HarddiskVolume2\Users\eminem\Desktop\DumpIt
0x000000003fc48070      1      1 RW-rwd \Device\HarddiskVolume2\Users\eminem\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db

C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>volatility_2.6_win64_standalone.exe -f "C:\Users\SIDDHARTH U\Downloads\MemLabs-Lab4\MemoryDump_Lab4.raw" --profile=Win7SP1x64 filescan | findstr "SlimShady"
Volatility Foundation Volatility Framework 2.6
0x000000003e900e60      2      1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms
0x000000003e90df20      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\desktop.ini
0x000000003ed01740      1      1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ed382c0      2      1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms
0x000000003ee47750      2      1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM
0x000000003ee49c40      2      1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TM.blf
0x000000003ee4b480      1      1 RW---- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
0x000000003ee4b5d0      1      1 RW---- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat
0x000000003ee4cb20      2      1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TMContainer00000000000000000002.regtrans-ms
0x000000003ee4cc70      1      0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\337ed59af273c758.customDestinations-ms
0x000000003ee4cf20      1      1 RW---- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2
0x000000003ee8e8c0      1      1 RW---- \Device\HarddiskVolume2\Users\SlimShady\ntuser.dat.LOG1
0x000000003ee9b590     16      0 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\9b9cdc69c1c24e2b.automaticDestinations-ms
0x000000003eeb6950      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003eeb7bb0     16      0 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
0x000000003eed64e0     16      0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
0x000000003eeec530     15      0 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003eeef070     17      1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
0x000000003f631070      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Printer Shortcuts
0x000000003f633d50      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
0x000000003f666aa0      1      1 RW---- \Device\HarddiskVolume2\Users\SlimShady\ntuser.dat.LOG2
0x000000003f939720      2      0 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\Important.lnk
0x000000003f9ff6d0      1      1 RW---- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT
0x000000003f9ff8e0      2      1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf
0x000000003fc398d0     16      0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\Desktop\Important.txt
0x000000003fc39a20     17      1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
0x000000003fc39cd0      2      1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TMContainer00000000000000000001.regtrans-ms
0x000000003fc39f20      1      1 RW-rwd \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TM
0x000000003fc3c910      2      1 RW-rw- \Device\clfs\Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\UsrClass.dat{8381e871-9808-11e9-b1e1-0800275e72bc}.TM
0x000000003fc3dbb0      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Credentials
0x000000003fc3dd00      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Credentials
0x000000003fcbd070      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini
0x000000003fcc5140     13      0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\IconCache.db
0x000000003fce9640     15      0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000003.db
0x000000003fcedca0      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini
0x000000003fcee070      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
0x000000003fcee1e0      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
0x000000003fcf0a20      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
0x000000003fcf9690     16      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Desktop\desktop.ini
0x000000003fcfa070      2      0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
0x000000003fcfb240      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Burn
0x000000003fcfba20      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
0x000000003fcfc7c0      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Burn
0x000000003fcfd320      2      0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
0x000000003fcfd5c0      1      1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019062920190630\index.dat
0x000000003fcfd920      2      0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk
0x000000003fcfdb00      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Desktop
0x000000003fcfe810      2      0 R--rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
0x000000003fcfeac0      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Desktop
0x000000003fcfef20      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
0x000000003fd00280      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
0x000000003fd0a970      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms
0x000000003fd0b070      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
0x000000003fd0b480      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
0x000000003fd13850      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Documents\desktop.ini
0x000000003fd15800      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms
0x000000003fd17c80      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003fd17dd0      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries
0x000000003fd1a340      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Pictures\desktop.ini
0x000000003fd1bd50     11      0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
0x000000003fd1c490     18      2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
0x000000003fd1c5e0      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms
0x000000003fd214d0     18      2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
0x000000003fd22d90     18      2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
0x000000003fd23d10      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\desktop.ini
0x000000003fd24c70     18      2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
0x000000003fd252e0      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\Music\desktop.ini
0x000000003fd25bc0     18      2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
0x000000003fd26840     18      2 RW-rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
0x000000003fd276c0      2      0 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini
0x000000003fd32070      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003fd32740      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003fd32890      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
0x000000003fd32c80      2      1 R--rwd \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Start Menu
0x000000003fd3d6d0     17      1 RW-rw- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
0x000000003fd40910     17      1 RW-r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Sticky Notes\StickyNotes.snt
0x000000003ff3dca0      1      0 R--r-- \Device\HarddiskVolume2\Users\SlimShady\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms

From memlabs 2 , we should also see if there are any potential images , as they prolly hide a clue .

image

Ok so it's a joker image !

image

Also when i tried to dump the important.txt , it showed an exmpty file ? Even tho the offset was correct and all .

This lead me to exploring and goggling , and after some time i stumbled upon how to recvover deleated files .

image

After seaching it in the delated dump files we get the flag :)

image
flag inctf{1_is_n0t_EQu4l_7o_2_bUt_th1s_d0s3nt_m4ke_s3ns3}

Explaining the MFT table : p

Master File Table
01/07/2021
[This document applies only to version 3 of NTFS volumes.]

The master file table (MFT) stores the information required to retrieve files from an NTFS partition.

A file may have one or more MFT records, and can contain one or more attributes. In NTFS, a file reference is the MFT segment reference of the base file record. For more information, see MFT_SEGMENT_REFERENCE.

The MFT contains file record segments; the first 16 of these are reserved for special files, such as the following:

0: MFT ($Mft)
5: root directory (\)
6: volume cluster allocation file ($Bitmap)
8: bad-cluster file ($BadClus)
Each file record segment starts with a file record segment header. For more information, see FILE_RECORD_SEGMENT_HEADER. Each file record segment is followed by one or more attributes. Each attribute starts with an attribute record header. For more information, see ATTRIBUTE_RECORD_HEADER. The attribute record includes the attribute type (such as $DATA or $BITMAP), an optional name, and the attribute value. The user data stream is an attribute, as are all streams. The attribute list is terminated with 0xFFFFFFFF ($END).

The following are some example attributes.

The $Mft file contains an unnamed $DATA attribute that is the sequence of MFT record segments, in order.
The $Mft file contains an unnamed $BITMAP attribute that indicates which MFT records are in use.
The $Bitmap file contains an unnamed $DATA attribute that indicates which clusters are in use.
The $BadClus file contains a $DATA attribute named $BAD that contains an entry that corresponds to each bad cluster.
When there is no more space for storing attributes in the file record segment, additional file record segments are allocated and inserted in the first (or base) file record segment in an attribute called the attribute list. The attribute list indicates where each attribute associated with the file can be found. This includes all attributes in the base file record, except for the attribute list itself. For more information, see ATTRIBUTE_LIST_ENTRY.

Structures related to the MFT include the following:

ATTRIBUTE_LIST_ENTRY
ATTRIBUTE_RECORD_HEADER
FILE_NAME
FILE_RECORD_SEGMENT_HEADER
MFT_SEGMENT_REFERENCE
MULTI_SECTOR_HEADER
STANDARD_INFORMATION

The plugin that interests us for retrieving entries from the MFT table is "MFTParser".

Use mftparser output, filescan, pslist or vads to find processes that might have opened the file, and check pagefile or memory-mapped files for content. Timestamps can tell you which process was active when the file was created or deleted and guide you to memory region .

ach MFT entry is typically 1 KB in size and contains metadata about a file rather than the file data itself, though very small files may be stored directly within the entry.

Even after a file is deleted, the MFT entry is often left intact with a “deleted” flag. The space for its clusters may eventually be overwritten, but the metadata remains until reused


Lab 5

image

First rituals should be running pslist and kDBG scan

image

WIntrar !!, flahsbacks to first lab , we'll see if some zip file is there and try to dump it .

Okie so lets see what command was it used to spwan it from (not pstree but cmdline)

image

we're onto something here .

nvm it's actually the 2nd part and the password is the first part flag . (Hint: You’ll get the stage 2 flag only when you have the stage 1 flag.) opps

I tried to see deleated files , and then nothing happened ..

Now lets move onto hidden files and see if filescan can get us something .

Ok after locking in and reading the clues again , it's related to a network as the attacker is outside , so i started looking for plugins that could uncover this

image

Nothing much here tho .

AFter exploring more and reading a writeup for this , i came across a plugin which does

iehistory
This plugin recovers fragments of IE history index.dat cache files. It can find basic accessed links (via FTP or HTTP), redirected links ( - REDR), and deleted entries ( - LEAK). It applies to any process which loads and uses the wininet.dll library, not just Internet Explorer. Typically that includes Windows Explorer and even malware samples.
image

Decoding that gives the first flag :))

flag{!!w3LL_d0n3_St4g3–1_0f_L4B_5_D0n3!!} and entering that to the zipped wintrar file gives us the 2nd flag in an image

image

Lab 6

Lets check the profile info

image

This came from a 64-bit Windows 7 SP1 machine .

image

cmd.exe (PID 880) - suggests manual command-line activity.

chrome.exe instances (PIDs 2124, 2132, 2168, 2340, etc.) - multiple browser tabs

firefox.exe cluster (PIDs 2080–3316) - another browser session, possibly used concurrently

WinRAR.exe (PID 3716) - indicates file compression/extraction activity like before

Lets dump wintrar , it should be a direct indication of something

image

Yes and now let's dump it

image

AFter trying to unrar it , well it needs a password :((

C:\Users\SIDDHARTH U\Downloads\volatility_2.6_win64_standalone\volatility_2.6_win64_standalone>volatility_2.6_win64_standalone.exe --plugins=plugins/ -f "C:\Users\SIDDHARTH U\Downloads\MemLabs-Lab6\MemoryDump_Lab6.raw" --profile=Win7SP1x64 consoles
Volatility Foundation Volatility Framework 2.6
**************************************************
ConsoleProcess: conhost.exe Pid: 916
Console: 0xff086200 CommandHistorySize: 50
HistoryBufferCount: 2 HistoryBufferMax: 4
OriginalTitle: %SystemRoot%\system32\cmd.exe
Title: C:\Windows\system32\cmd.exe
AttachedProcess: cmd.exe Pid: 880 Handle: 0x60
----
CommandHistory: 0x1fedc0 Application: whoami.exe Flags:
CommandCount: 0 LastAdded: -1 LastDisplayed: -1
FirstCommand: 0 CommandCountMax: 50
ProcessHandle: 0x0
----
CommandHistory: 0x1feab0 Application: cmd.exe Flags: Allocated, Reset
CommandCount: 2 LastAdded: 1 LastDisplayed: 1
FirstCommand: 0 CommandCountMax: 50
ProcessHandle: 0x60
Cmd #0 at 0x1fd530: whoami
Cmd #1 at 0x1fdde0: env
----
Screen 0x1e0f80 X:80 Y:300
Dump:
Microsoft Windows [Version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\Jaffa>whoami
virus-pc\jaffa

C:\Users\Jaffa>env
'env' is not recognized as an internal or external command,
operable program or batch file.

C:\Users\Jaffa>
**************************************************
ConsoleProcess: conhost.exe Pid: 4092
Console: 0xff086200 CommandHistorySize: 50
HistoryBufferCount: 1 HistoryBufferMax: 4
OriginalTitle: C:\Users\Jaffa\Desktop\DumpIt.exe
Title: C:\Users\Jaffa\Desktop\DumpIt.exe
AttachedProcess: DumpIt.exe Pid: 4084 Handle: 0x60
----
CommandHistory: 0x30eab0 Application: DumpIt.exe Flags: Allocated
CommandCount: 0 LastAdded: -1 LastDisplayed: -1
FirstCommand: 0 CommandCountMax: 50
ProcessHandle: 0x60
----
Screen 0x2f0f80 X:80 Y:300
Dump:
  DumpIt - v1.3.2.20110401 - One click memory memory dumper
  Copyright (c) 2007 - 2011, Matthieu Suiche <http://www.msuiche.net>
  Copyright (c) 2010 - 2011, MoonSols <http://www.moonsols.com>


    Address space size:        1610547200 bytes (   1535 Mb)
    Free space size:           9889345536 bytes (   9431 Mb)

    * Destination = \??\C:\Users\Jaffa\Desktop\VIRUS-PC-20190819-144155.raw

    --> Are you sure you want to continue? [y/n] y
    + Processing...

Jaffa tried running envars before dumpit.exe so that's a lead for us

From pervious lab refrence , lets try runnning envars for all the sus proccess we saw earlier .

Volatility Foundation Volatility Framework 2.6
Pid      Process              Block              Variable                       Value
-------- -------------------- ------------------ ------------------------------ -----
    2124 chrome.exe           0x00000000003453f0 ALLUSERSPROFILE                C:\ProgramData
    2124 chrome.exe           0x00000000003453f0 APPDATA                        C:\Users\Jaffa\AppData\Roaming
    2124 chrome.exe           0x00000000003453f0 CHROME_CRASHPAD_PIPE_NAME      \\.\pipe\crashpad_2124_HYPTHIKRKHINVSMY
    2124 chrome.exe           0x00000000003453f0 CHROME_RESTART                 Google Chrome|Whoa! Google Chrome has crashed. Relaunch now?|LEFT_TO_RIGHT
    2124 chrome.exe           0x00000000003453f0 CommonProgramFiles             C:\Program Files\Common Files
    2124 chrome.exe           0x00000000003453f0 CommonProgramFiles(x86)        C:\Program Files (x86)\Common Files
    2124 chrome.exe           0x00000000003453f0 CommonProgramW6432             C:\Program Files\Common Files
    2124 chrome.exe           0x00000000003453f0 COMPUTERNAME                   VIRUS-PC
    2124 chrome.exe           0x00000000003453f0 ComSpec                        C:\Windows\system32\cmd.exe
    2124 chrome.exe           0x00000000003453f0 FP_NO_HOST_CHECK               NO
    2124 chrome.exe           0x00000000003453f0 HOMEDRIVE                      C:
    2124 chrome.exe           0x00000000003453f0 HOMEPATH                       \Users\Jaffa
    2124 chrome.exe           0x00000000003453f0 LOCALAPPDATA                   C:\Users\Jaffa\AppData\Local
    2124 chrome.exe           0x00000000003453f0 LOGONSERVER                    \\VIRUS-PC
    2124 chrome.exe           0x00000000003453f0 NUMBER_OF_PROCESSORS           1
    2124 chrome.exe           0x00000000003453f0 OS                             Windows_NT
    2124 chrome.exe           0x00000000003453f0 Path                           C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
    2124 chrome.exe           0x00000000003453f0 PATHEXT                        .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    2124 chrome.exe           0x00000000003453f0 PROCESSOR_ARCHITECTURE         AMD64
    2124 chrome.exe           0x00000000003453f0 PROCESSOR_IDENTIFIER           Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
    2124 chrome.exe           0x00000000003453f0 PROCESSOR_LEVEL                6
    2124 chrome.exe           0x00000000003453f0 PROCESSOR_REVISION             9e0a
    2124 chrome.exe           0x00000000003453f0 ProgramData                    C:\ProgramData
    2124 chrome.exe           0x00000000003453f0 ProgramFiles                   C:\Program Files
    2124 chrome.exe           0x00000000003453f0 ProgramFiles(x86)              C:\Program Files (x86)
    2124 chrome.exe           0x00000000003453f0 ProgramW6432                   C:\Program Files
    2124 chrome.exe           0x00000000003453f0 PSModulePath                   C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    2124 chrome.exe           0x00000000003453f0 PUBLIC                         C:\Users\Public
    2124 chrome.exe           0x00000000003453f0 RAR password                   easypeasyvirus
    2124 chrome.exe           0x00000000003453f0 SESSIONNAME                    Console
    2124 chrome.exe           0x00000000003453f0 SystemDrive                    C:
    2124 chrome.exe           0x00000000003453f0 SystemRoot                     C:\Windows
    2124 chrome.exe           0x00000000003453f0 TEMP                           C:\Users\Jaffa\AppData\Local\Temp
    2124 chrome.exe           0x00000000003453f0 TMP                            C:\Users\Jaffa\AppData\Local\Temp
    2124 chrome.exe           0x00000000003453f0 USERDOMAIN                     VIRUS-PC
    2124 chrome.exe           0x00000000003453f0 USERNAME                       Jaffa
    2124 chrome.exe           0x00000000003453f0 USERPROFILE                    C:\Users\Jaffa
    2124 chrome.exe           0x00000000003453f0 windir                         C:\Windows
    2124 chrome.exe           0x00000000003453f0 windows_tracing_flags          3
    2124 chrome.exe           0x00000000003453f0 windows_tracing_logfile        C:\BVTBin\Tests\installpackage\csilogfile.log
    2132 chrome.exe           0x0000000000561320 ALLUSERSPROFILE                C:\ProgramData
    2132 chrome.exe           0x0000000000561320 APPDATA                        C:\Users\Jaffa\AppData\Roaming
    2132 chrome.exe           0x0000000000561320 CommonProgramFiles             C:\Program Files\Common Files
    2132 chrome.exe           0x0000000000561320 CommonProgramFiles(x86)        C:\Program Files (x86)\Common Files
    2132 chrome.exe           0x0000000000561320 CommonProgramW6432             C:\Program Files\Common Files
    2132 chrome.exe           0x0000000000561320 COMPUTERNAME                   VIRUS-PC
    2132 chrome.exe           0x0000000000561320 ComSpec                        C:\Windows\system32\cmd.exe
    2132 chrome.exe           0x0000000000561320 FP_NO_HOST_CHECK               NO
    2132 chrome.exe           0x0000000000561320 HOMEDRIVE                      C:
    2132 chrome.exe           0x0000000000561320 HOMEPATH                       \Users\Jaffa
    2132 chrome.exe           0x0000000000561320 LOCALAPPDATA                   C:\Users\Jaffa\AppData\Local
    2132 chrome.exe           0x0000000000561320 LOGONSERVER                    \\VIRUS-PC
    2132 chrome.exe           0x0000000000561320 NUMBER_OF_PROCESSORS           1
    2132 chrome.exe           0x0000000000561320 OS                             Windows_NT
    2132 chrome.exe           0x0000000000561320 Path                           C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
    2132 chrome.exe           0x0000000000561320 PATHEXT                        .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    2132 chrome.exe           0x0000000000561320 PROCESSOR_ARCHITECTURE         AMD64
    2132 chrome.exe           0x0000000000561320 PROCESSOR_IDENTIFIER           Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
    2132 chrome.exe           0x0000000000561320 PROCESSOR_LEVEL                6
    2132 chrome.exe           0x0000000000561320 PROCESSOR_REVISION             9e0a
    2132 chrome.exe           0x0000000000561320 ProgramData                    C:\ProgramData
    2132 chrome.exe           0x0000000000561320 ProgramFiles                   C:\Program Files
    2132 chrome.exe           0x0000000000561320 ProgramFiles(x86)              C:\Program Files (x86)
    2132 chrome.exe           0x0000000000561320 ProgramW6432                   C:\Program Files
    2132 chrome.exe           0x0000000000561320 PSModulePath                   C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    2132 chrome.exe           0x0000000000561320 PUBLIC                         C:\Users\Public
    2132 chrome.exe           0x0000000000561320 RAR password                   easypeasyvirus
    2132 chrome.exe           0x0000000000561320 SESSIONNAME                    Console
    2132 chrome.exe           0x0000000000561320 SystemDrive                    C:
    2132 chrome.exe           0x0000000000561320 SystemRoot                     C:\Windows
    2132 chrome.exe           0x0000000000561320 TEMP                           C:\Users\Jaffa\AppData\Local\Temp
    2132 chrome.exe           0x0000000000561320 TMP                            C:\Users\Jaffa\AppData\Local\Temp
    2132 chrome.exe           0x0000000000561320 USERDOMAIN                     VIRUS-PC
    2132 chrome.exe           0x0000000000561320 USERNAME                       Jaffa
    2132 chrome.exe           0x0000000000561320 USERPROFILE                    C:\Users\Jaffa
    2132 chrome.exe           0x0000000000561320 windir                         C:\Windows
    2132 chrome.exe           0x0000000000561320 windows_tracing_flags          3
    2132 chrome.exe           0x0000000000561320 windows_tracing_logfile        C:\BVTBin\Tests\installpackage\csilogfile.log
    2168 chrome.exe           0x0000000000421320 ALLUSERSPROFILE                C:\ProgramData
    2168 chrome.exe           0x0000000000421320 APPDATA                        C:\Users\Jaffa\AppData\Roaming
    2168 chrome.exe           0x0000000000421320 CHROME_CRASHPAD_PIPE_NAME      \\.\pipe\crashpad_2124_HYPTHIKRKHINVSMY
    2168 chrome.exe           0x0000000000421320 CommonProgramFiles             C:\Program Files\Common Files
    2168 chrome.exe           0x0000000000421320 CommonProgramFiles(x86)        C:\Program Files (x86)\Common Files
    2168 chrome.exe           0x0000000000421320 CommonProgramW6432             C:\Program Files\Common Files
    2168 chrome.exe           0x0000000000421320 COMPUTERNAME                   VIRUS-PC
    2168 chrome.exe           0x0000000000421320 ComSpec                        C:\Windows\system32\cmd.exe
    2168 chrome.exe           0x0000000000421320 FP_NO_HOST_CHECK               NO
    2168 chrome.exe           0x0000000000421320 HOMEDRIVE                      C:
    2168 chrome.exe           0x0000000000421320 HOMEPATH                       \Users\Jaffa
    2168 chrome.exe           0x0000000000421320 LOCALAPPDATA                   C:\Users\Jaffa\AppData\Local
    2168 chrome.exe           0x0000000000421320 LOGONSERVER                    \\VIRUS-PC
    2168 chrome.exe           0x0000000000421320 NUMBER_OF_PROCESSORS           1
    2168 chrome.exe           0x0000000000421320 OS                             Windows_NT
    2168 chrome.exe           0x0000000000421320 Path                           C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
    2168 chrome.exe           0x0000000000421320 PATHEXT                        .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    2168 chrome.exe           0x0000000000421320 PROCESSOR_ARCHITECTURE         AMD64
    2168 chrome.exe           0x0000000000421320 PROCESSOR_IDENTIFIER           Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
    2168 chrome.exe           0x0000000000421320 PROCESSOR_LEVEL                6
    2168 chrome.exe           0x0000000000421320 PROCESSOR_REVISION             9e0a
    2168 chrome.exe           0x0000000000421320 ProgramData                    C:\ProgramData
    2168 chrome.exe           0x0000000000421320 ProgramFiles                   C:\Program Files
    2168 chrome.exe           0x0000000000421320 ProgramFiles(x86)              C:\Program Files (x86)
    2168 chrome.exe           0x0000000000421320 ProgramW6432                   C:\Program Files
    2168 chrome.exe           0x0000000000421320 PSModulePath                   C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    2168 chrome.exe           0x0000000000421320 PUBLIC                         C:\Users\Public
    2168 chrome.exe           0x0000000000421320 RAR password                   easypeasyvirus
    2168 chrome.exe           0x0000000000421320 SESSIONNAME                    Console
    2168 chrome.exe           0x0000000000421320 SystemDrive                    C:
    2168 chrome.exe           0x0000000000421320 SystemRoot                     C:\Windows
    2168 chrome.exe           0x0000000000421320 TEMP                           C:\Users\Jaffa\AppData\Local\Temp
    2168 chrome.exe           0x0000000000421320 TMP                            C:\Users\Jaffa\AppData\Local\Temp
    2168 chrome.exe           0x0000000000421320 USERDOMAIN                     VIRUS-PC
    2168 chrome.exe           0x0000000000421320 USERNAME                       Jaffa
    2168 chrome.exe           0x0000000000421320 USERPROFILE                    C:\Users\Jaffa
    2168 chrome.exe           0x0000000000421320 windir                         C:\Windows
    2168 chrome.exe           0x0000000000421320 windows_tracing_flags          3
    2168 chrome.exe           0x0000000000421320 windows_tracing_logfile        C:\BVTBin\Tests\installpackage\csilogfile.log
    2340 chrome.exe           0x0000000000551320 ALLUSERSPROFILE                C:\ProgramData
    2340 chrome.exe           0x0000000000551320 APPDATA                        C:\Users\Jaffa\AppData\Roaming
    2340 chrome.exe           0x0000000000551320 CHROME_CRASHPAD_PIPE_NAME      \\.\pipe\crashpad_2124_HYPTHIKRKHINVSMY
    2340 chrome.exe           0x0000000000551320 CommonProgramFiles             C:\Program Files\Common Files
    2340 chrome.exe           0x0000000000551320 CommonProgramFiles(x86)        C:\Program Files (x86)\Common Files
    2340 chrome.exe           0x0000000000551320 CommonProgramW6432             C:\Program Files\Common Files
    2340 chrome.exe           0x0000000000551320 COMPUTERNAME                   VIRUS-PC
    2340 chrome.exe           0x0000000000551320 ComSpec                        C:\Windows\system32\cmd.exe
    2340 chrome.exe           0x0000000000551320 FP_NO_HOST_CHECK               NO
    2340 chrome.exe           0x0000000000551320 HOMEDRIVE                      C:
    2340 chrome.exe           0x0000000000551320 HOMEPATH                       \Users\Jaffa
    2340 chrome.exe           0x0000000000551320 LOCALAPPDATA                   C:\Users\Jaffa\AppData\Local
    2340 chrome.exe           0x0000000000551320 LOGONSERVER                    \\VIRUS-PC
    2340 chrome.exe           0x0000000000551320 NUMBER_OF_PROCESSORS           1
    2340 chrome.exe           0x0000000000551320 OS                             Windows_NT
    2340 chrome.exe           0x0000000000551320 Path                           C:\Program Files (x86)\Google\Chrome\Application;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
    2340 chrome.exe           0x0000000000551320 PATHEXT                        .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    2340 chrome.exe           0x0000000000551320 PROCESSOR_ARCHITECTURE         AMD64
    2340 chrome.exe           0x0000000000551320 PROCESSOR_IDENTIFIER           Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
    2340 chrome.exe           0x0000000000551320 PROCESSOR_LEVEL                6
    2340 chrome.exe           0x0000000000551320 PROCESSOR_REVISION             9e0a
    2340 chrome.exe           0x0000000000551320 ProgramData                    C:\ProgramData
    2340 chrome.exe           0x0000000000551320 ProgramFiles                   C:\Program Files
    2340 chrome.exe           0x0000000000551320 ProgramFiles(x86)              C:\Program Files (x86)
    2340 chrome.exe           0x0000000000551320 ProgramW6432                   C:\Program Files
    2340 chrome.exe           0x0000000000551320 PSModulePath                   C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    2340 chrome.exe           0x0000000000551320 PUBLIC                         C:\Users\Public
    2340 chrome.exe           0x0000000000551320 RAR password                   easypeasyvirus
    2340 chrome.exe           0x0000000000551320 SESSIONNAME                    Console
    2340 chrome.exe           0x0000000000551320 SystemDrive                    C:
    2340 chrome.exe           0x0000000000551320 SystemRoot                     C:\Windows
    2340 chrome.exe           0x0000000000551320 TEMP                           C:\Users\Jaffa\AppData\Local\Temp
    2340 chrome.exe           0x0000000000551320 TMP                            C:\Users\Jaffa\AppData\Local\Temp
    2340 chrome.exe           0x0000000000551320 USERDOMAIN                     VIRUS-PC
    2340 chrome.exe           0x0000000000551320 USERNAME                       Jaffa
    2340 chrome.exe           0x0000000000551320 USERPROFILE                    C:\Users\Jaffa
    2340 chrome.exe           0x0000000000551320 windir                         C:\Windows
    2340 chrome.exe           0x0000000000551320 windows_tracing_flags          3
    2340 chrome.exe           0x0000000000551320 windows_tracing_logfile        C:\BVTBin\Tests\installpackage\csilogfile.log
    2080 firefox.exe          0x00000000005f1320 ALLUSERSPROFILE                C:\ProgramData
    2080 firefox.exe          0x00000000005f1320 APPDATA                        C:\Users\Jaffa\AppData\Roaming
    2080 firefox.exe          0x00000000005f1320 CommonProgramFiles             C:\Program Files\Common Files
    2080 firefox.exe          0x00000000005f1320 CommonProgramFiles(x86)        C:\Program Files (x86)\Common Files
    2080 firefox.exe          0x00000000005f1320 CommonProgramW6432             C:\Program Files\Common Files
    2080 firefox.exe          0x00000000005f1320 COMPUTERNAME                   VIRUS-PC
    2080 firefox.exe          0x00000000005f1320 ComSpec                        C:\Windows\system32\cmd.exe
    2080 firefox.exe          0x00000000005f1320 FP_NO_HOST_CHECK               NO
    2080 firefox.exe          0x00000000005f1320 HOMEDRIVE                      C:
    2080 firefox.exe          0x00000000005f1320 HOMEPATH                       \Users\Jaffa
    2080 firefox.exe          0x00000000005f1320 LOCALAPPDATA                   C:\Users\Jaffa\AppData\Local
    2080 firefox.exe          0x00000000005f1320 LOGONSERVER                    \\VIRUS-PC
    2080 firefox.exe          0x00000000005f1320 NUMBER_OF_PROCESSORS           1
    2080 firefox.exe          0x00000000005f1320 OS                             Windows_NT
    2080 firefox.exe          0x00000000005f1320 Path                           C:\Program Files (x86)\Mozilla Firefox;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
    2080 firefox.exe          0x00000000005f1320 PATHEXT                        .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    2080 firefox.exe          0x00000000005f1320 PROCESSOR_ARCHITECTURE         AMD64
    2080 firefox.exe          0x00000000005f1320 PROCESSOR_IDENTIFIER           Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
    2080 firefox.exe          0x00000000005f1320 PROCESSOR_LEVEL                6
    2080 firefox.exe          0x00000000005f1320 PROCESSOR_REVISION             9e0a
    2080 firefox.exe          0x00000000005f1320 ProgramData                    C:\ProgramData
    2080 firefox.exe          0x00000000005f1320 ProgramFiles                   C:\Program Files
    2080 firefox.exe          0x00000000005f1320 ProgramFiles(x86)              C:\Program Files (x86)
    2080 firefox.exe          0x00000000005f1320 ProgramW6432                   C:\Program Files
    2080 firefox.exe          0x00000000005f1320 PSModulePath                   C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    2080 firefox.exe          0x00000000005f1320 PUBLIC                         C:\Users\Public
    2080 firefox.exe          0x00000000005f1320 RAR password                   easypeasyvirus
    2080 firefox.exe          0x00000000005f1320 SESSIONNAME                    Console
    2080 firefox.exe          0x00000000005f1320 SystemDrive                    C:
    2080 firefox.exe          0x00000000005f1320 SystemRoot                     C:\Windows
    2080 firefox.exe          0x00000000005f1320 TEMP                           C:\Users\Jaffa\AppData\Local\Temp
    2080 firefox.exe          0x00000000005f1320 TMP                            C:\Users\Jaffa\AppData\Local\Temp
    2080 firefox.exe          0x00000000005f1320 USERDOMAIN                     VIRUS-PC
    2080 firefox.exe          0x00000000005f1320 USERNAME                       Jaffa
    2080 firefox.exe          0x00000000005f1320 USERPROFILE                    C:\Users\Jaffa
    2080 firefox.exe          0x00000000005f1320 windir                         C:\Windows
    2080 firefox.exe          0x00000000005f1320 windows_tracing_flags          3
    2080 firefox.exe          0x00000000005f1320 windows_tracing_logfile        C:\BVTBin\Tests\installpackage\csilogfile.log
    3716 WinRAR.exe           0x00000000002a1320 ALLUSERSPROFILE                C:\ProgramData
    3716 WinRAR.exe           0x00000000002a1320 APPDATA                        C:\Users\Jaffa\AppData\Roaming
    3716 WinRAR.exe           0x00000000002a1320 CommonProgramFiles             C:\Program Files\Common Files
    3716 WinRAR.exe           0x00000000002a1320 CommonProgramFiles(x86)        C:\Program Files (x86)\Common Files
    3716 WinRAR.exe           0x00000000002a1320 CommonProgramW6432             C:\Program Files\Common Files
    3716 WinRAR.exe           0x00000000002a1320 COMPUTERNAME                   VIRUS-PC
    3716 WinRAR.exe           0x00000000002a1320 ComSpec                        C:\Windows\system32\cmd.exe
    3716 WinRAR.exe           0x00000000002a1320 FP_NO_HOST_CHECK               NO
    3716 WinRAR.exe           0x00000000002a1320 HOMEDRIVE                      C:
    3716 WinRAR.exe           0x00000000002a1320 HOMEPATH                       \Users\Jaffa
    3716 WinRAR.exe           0x00000000002a1320 LOCALAPPDATA                   C:\Users\Jaffa\AppData\Local
    3716 WinRAR.exe           0x00000000002a1320 LOGONSERVER                    \\VIRUS-PC
    3716 WinRAR.exe           0x00000000002a1320 NUMBER_OF_PROCESSORS           1
    3716 WinRAR.exe           0x00000000002a1320 OS                             Windows_NT
    3716 WinRAR.exe           0x00000000002a1320 Path                           C:\Program Files\WinRAR;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\
    3716 WinRAR.exe           0x00000000002a1320 PATHEXT                        .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    3716 WinRAR.exe           0x00000000002a1320 PROCESSOR_ARCHITECTURE         AMD64
    3716 WinRAR.exe           0x00000000002a1320 PROCESSOR_IDENTIFIER           Intel64 Family 6 Model 158 Stepping 10, GenuineIntel
    3716 WinRAR.exe           0x00000000002a1320 PROCESSOR_LEVEL                6
    3716 WinRAR.exe           0x00000000002a1320 PROCESSOR_REVISION             9e0a
    3716 WinRAR.exe           0x00000000002a1320 ProgramData                    C:\ProgramData
    3716 WinRAR.exe           0x00000000002a1320 ProgramFiles                   C:\Program Files
    3716 WinRAR.exe           0x00000000002a1320 ProgramFiles(x86)              C:\Program Files (x86)
    3716 WinRAR.exe           0x00000000002a1320 ProgramW6432                   C:\Program Files
    3716 WinRAR.exe           0x00000000002a1320 PSModulePath                   C:\Windows\system32\WindowsPowerShell\v1.0\Modules\
    3716 WinRAR.exe           0x00000000002a1320 PUBLIC                         C:\Users\Public
    3716 WinRAR.exe           0x00000000002a1320 RAR password                   easypeasyvirus
    3716 WinRAR.exe           0x00000000002a1320 SESSIONNAME                    Console
    3716 WinRAR.exe           0x00000000002a1320 SystemDrive                    C:
    3716 WinRAR.exe           0x00000000002a1320 SystemRoot                     C:\Windows
    3716 WinRAR.exe           0x00000000002a1320 TEMP                           C:\Users\Jaffa\AppData\Local\Temp
    3716 WinRAR.exe           0x00000000002a1320 TMP                            C:\Users\Jaffa\AppData\Local\Temp
    3716 WinRAR.exe           0x00000000002a1320 USERDOMAIN                     VIRUS-PC
    3716 WinRAR.exe           0x00000000002a1320 USERNAME                       Jaffa
    3716 WinRAR.exe           0x00000000002a1320 USERPROFILE                    C:\Users\Jaffa
    3716 WinRAR.exe           0x00000000002a1320 windir                         C:\Windows
    3716 WinRAR.exe           0x00000000002a1320 windows_tracing_flags          3
    3716 WinRAR.exe           0x00000000002a1320 windows_tracing_logfile        C:\BVTBin\Tests\installpackage\csilogfile.log

oh we actually got the rar password and it wasnt the flag of the 2nd one ..

Now let's extrcat it

and we get a 2nd'part of the flag?

image

Since the clues mentioned , a link to and we saw some chrome and firefox running mhmm lets try to see history .

I found a amazing volatilyt plugin repo which helped Volatility Plugins

AFter spending a lot of time and clicking a lot of dead ends , i spotted a pastebin link which lead to

image

mhm

imageimage

And it had a mega link which needed a mhmm ,

image

This needs a password and i spend a lot of time looking for what to do next as there wasnt anything explicit mentioned ..


Start
🎵 now playing: ruby
12:00 PM