This was probably the easiest memory forensics challenge that I ever attempted.

Challenge Description

Screenshot from 2019-07-01 18-48-52

The description does not provide anything, so let us look at the file 🙂

Okay, let us take a look at the challenge file. It is a WindowsXP memory dump.

Hmm, let me see the command history using the cmdscan plugin

Hmm, they created a directory with the name “hu5ky_4nd_f0r3n51c”

Okay, let us have a look what files are present in the above-mentioned directory/folder.

Hmm, the file present in the folder is “f149999”

Next step is quite predictable, dump the file. Simple,

$ volatility -f husky_memory.raw --profile=WinXPSP2x86 dumpfiles -Q 0x0000000002c5dd18 -D .

Let us analyze what file is this. Let us open it in a hex editor

As you can see it is reversed RAR archive. Just reverse the bytes to get the proper archive.

So after correcting the archive, we see that it is a locked archive. Hmm, have to search for the password. Luckily I guessed that the folder-name was in l33t, so it could be the password. Voila, and we got the flag.



