Forwarded from Team ETF (Groot)
Explanation:-
There are two types of scan in volatility to detect profile.
1. By imageinfo ( above picture )
2. Kdbg scan ( tmrw I will discuss this)
Here in the above figure we can see that there we scanned using imageinfo, and it detected some of the profiles ( which os memory fike it is ).
Profile :- WinXPSP2x86 ( see highlighted)
Possible doubts :-
1.Here we have used memory dump of cridex.vmem
.vmem -> virtualbox memory
cridex is the one of the malware name
2. I already thought you earlier how to get memory file.
Error:-
There's installation error in my tool. Probably you won't get failed error while running tool.
There are two types of scan in volatility to detect profile.
1. By imageinfo ( above picture )
2. Kdbg scan ( tmrw I will discuss this)
Here in the above figure we can see that there we scanned using imageinfo, and it detected some of the profiles ( which os memory fike it is ).
Profile :- WinXPSP2x86 ( see highlighted)
Possible doubts :-
1.Here we have used memory dump of cridex.vmem
.vmem -> virtualbox memory
cridex is the one of the malware name
2. I already thought you earlier how to get memory file.
Error:-
There's installation error in my tool. Probably you won't get failed error while running tool.
Forwarded from Team ETF (ᴵ ᵃᵐ ᵍʳᵒᵒᵗ)
Sorry I forgot to tell the about captured memory file,
It's from otterctf.com
Login and see in memory forensics section
Or
Direct dwnld from
https://mega.nz/#!sh8wmCIL!b4tpech4wzc3QQ6YgQ2uZnOmctRZ2duQxDqxbkWYipQ
It's from otterctf.com
Login and see in memory forensics section
Or
Direct dwnld from
https://mega.nz/#!sh8wmCIL!b4tpech4wzc3QQ6YgQ2uZnOmctRZ2duQxDqxbkWYipQ
mega.nz
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 20GB now
Forwarded from Team ETF (Groot)
If u really have any doubts
Contact me
@Etf_Zan_bot ( bot )
@zincster ( id )
I will try to respond fast😐
Contact me
@Etf_Zan_bot ( bot )
@zincster ( id )
I will try to respond fast😐
Forwarded from Team ETF (ᴵ ᵃᵐ ᵍʳᵒᵒᵗ)
Ok hold your beers 🍻 guyz,
If you are following otterctf no worries,
If not I will begin with the question too.
1. In the above given dump file ( otterctf.vmem)
The user used to play a online game, and u need to find the game name and it's server ip address.
How will u do, think?
Answer:-
Do netscan using volatility
If you are following otterctf no worries,
If not I will begin with the question too.
1. In the above given dump file ( otterctf.vmem)
The user used to play a online game, and u need to find the game name and it's server ip address.
How will u do, think?
Answer:-
Do netscan using volatility