Memlabs Lab 4 Writeup

Anarta Poashan
1 min readJul 27, 2020

--

Problem : My system was recently compromised. The Hacker stole a lot of information but he also deleted a very important file of mine. I have no idea on how to recover it. The only evidence we have, at this point of time is this memory dump. Please help me.

Solution : Running volatility filescan with grep for .txt files gives a suspicious looking important.txt file. However dumping the file using dumpfile plugin does not work.

Running pslist gives a StikyNot.exe process. Running file scan with grep for .snt gives a StickyNotes.snt file which contains the text

The clipboard plugin works well but it doesn’t give the flag

Searching for recovery of deleted data on volatility yields results related to mftparser. Using the plugin with grep for important.txt gives the flag.

inctf{1_is_n0t_EQu4l_7o_2_bUt_th1s_d0s3nt_m4ke_s3ns3} Good work :P

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

--

--

No responses yet

Write a response