{"id":2797,"date":"2026-04-17T18:27:00","date_gmt":"2026-04-17T18:27:00","guid":{"rendered":"https:\/\/zombierollz.blog\/?p=2797"},"modified":"2026-04-17T11:28:30","modified_gmt":"2026-04-17T11:28:30","slug":"boogeyman-2","status":"publish","type":"post","link":"https:\/\/zombierollz.blog\/?p=2797","title":{"rendered":"Boogeyman 2"},"content":{"rendered":"\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-0895c23b12019b4ab751ca8fa99ec61c wp-block-paragraph\"><a href=\"https:\/\/tryhackme.com\/room\/boogeyman2\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/tryhackme.com\/room\/boogeyman2<\/a><br>Created by: tryhackme, ar33zy<\/p>\n\n\n\n<p class=\"has-palette-color-8-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-87e94b7d48915915ad0b10b1f468b023 wp-block-paragraph\">&#8220;This room may require the combined knowledge gained from the&nbsp;<a href=\"https:\/\/tryhackme.com\/path-action\/soclevel1\/join\" target=\"_blank\" rel=\"noreferrer noopener\">SOC&nbsp;L1<\/a>&nbsp;Path. We recommend going&nbsp;through the following rooms before attempting this challenge.&#8221;<br><br><a href=\"https:\/\/tryhackme.com\/room\/phishingemails1tryoe\" target=\"_blank\" rel=\"noreferrer noopener\">Phishing&nbsp;Analysis Fundamentals<\/a><br><a href=\"https:\/\/tryhackme.com\/room\/phishingemails3tryoe\" target=\"_blank\" rel=\"noreferrer noopener\">Phishing&nbsp;Analysis Tools<\/a><br><a href=\"https:\/\/tryhackme.com\/room\/boogeyman1\" target=\"_blank\" rel=\"noreferrer noopener\">Boogeyman 1<\/a><br><a href=\"https:\/\/tryhackme.com\/room\/volatility\" target=\"_blank\" rel=\"noreferrer noopener\">Volatility<\/a><br><br>I&#8217;ve just completed the Volatility room and highly recommend it! We are going to be using this tool along with Olevba.<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"434\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-065704-1024x434.png\" alt=\"\" class=\"wp-image-2798\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-065704-1024x434.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-065704-300x127.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-065704-768x325.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-065704.png 1058w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-8da8d6b55cb6510a44744e258140e347 wp-block-paragraph\"><a href=\"https:\/\/github.com\/volatilityfoundation\/volatility3\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/github.com\/volatilityfoundation\/volatility3<\/a><br><a href=\"https:\/\/volatility3.readthedocs.io\/en\/latest\/volatility3.plugins.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/volatility3.readthedocs.io\/en\/latest\/volatility3.plugins.html<\/a><br><a href=\"https:\/\/github.com\/decalage2\/oletools\">https:\/\/github.com\/decalage2\/oletools<\/a><br><br>On to task 2!<\/p>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-74764f24bec3877efd3cae82060901c7 wp-block-paragraph\">&#8220;Maxine, a Human Resource Specialist working for Quick Logistics LLC, received an application from one of the open positions in the company. Unbeknownst to her, the attached resume was malicious and compromised her workstation.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"709\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-071214-1024x709.png\" alt=\"\" class=\"wp-image-2800\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-071214-1024x709.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-071214-300x208.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-071214-768x531.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-071214.png 1224w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-4ecf8bb7a27abf0d6c32f65ec1e5a73d wp-block-paragraph\">&#8220;The security team was able to flag some suspicious commands executed on the workstation of Maxine, which prompted the investigation.&nbsp;Given this, you are tasked to analyse and assess the impact of the compromise.&#8221;<br><br>&#8220;What email was used to send the phishing email?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"610\" height=\"556\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-073850.png\" alt=\"\" class=\"wp-image-2801\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-073850.png 610w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-073850-300x273.png 300w\" sizes=\"auto, (max-width: 610px) 100vw, 610px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"757\" height=\"750\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-074102.png\" alt=\"\" class=\"wp-image-2802\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-074102.png 757w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-074102-300x297.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-074102-150x150.png 150w\" sizes=\"auto, (max-width: 757px) 100vw, 757px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-a1079c185ff652ce9ed5735d5c1931e0 wp-block-paragraph\">&#8220;What is the email of the victim employee?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"654\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075410-1024x654.png\" alt=\"\" class=\"wp-image-2803\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075410-1024x654.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075410-300x192.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075410-768x491.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075410.png 1160w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-3b8c500a0c48ffea86ea16153863d71d wp-block-paragraph\">&#8220;What is the name of the attached malicious document?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"765\" height=\"427\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075659.png\" alt=\"\" class=\"wp-image-2804\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075659.png 765w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-08-075659-300x167.png 300w\" sizes=\"auto, (max-width: 765px) 100vw, 765px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-5da027187e69ed3a8f4f1d457e27b53a wp-block-paragraph\">&#8220;What is the MD5 hash of the malicious attachment?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"954\" height=\"782\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055033.png\" alt=\"\" class=\"wp-image-2805\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055033.png 954w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055033-300x246.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055033-768x630.png 768w\" sizes=\"auto, (max-width: 954px) 100vw, 954px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"572\" height=\"262\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055124.png\" alt=\"\" class=\"wp-image-2807\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055124.png 572w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055124-300x137.png 300w\" sizes=\"auto, (max-width: 572px) 100vw, 572px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"736\" height=\"482\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055235.png\" alt=\"\" class=\"wp-image-2808\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055235.png 736w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-055235-300x196.png 300w\" sizes=\"auto, (max-width: 736px) 100vw, 736px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-29af36d8fc70ec4e15c99b311c784c0c wp-block-paragraph\">&#8220;What URL is used to download the stage 2 payload based on the document&#8217;s macro?&#8221;<br><br>The easiest way to obtain the next few answers is by using olevba. You can also view the macros through LibreOffice.<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"980\" height=\"558\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065059.png\" alt=\"\" class=\"wp-image-2810\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065059.png 980w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065059-300x171.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065059-768x437.png 768w\" sizes=\"auto, (max-width: 980px) 100vw, 980px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"613\" height=\"254\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062114.png\" alt=\"\" class=\"wp-image-2811\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062114.png 613w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062114-300x124.png 300w\" sizes=\"auto, (max-width: 613px) 100vw, 613px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"814\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062042-1024x814.png\" alt=\"\" class=\"wp-image-2812\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062042-1024x814.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062042-300x238.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062042-768x610.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062042.png 1057w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"610\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062209-1024x610.png\" alt=\"\" class=\"wp-image-2813\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062209-1024x610.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062209-300x179.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062209-768x457.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062209.png 1169w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-5d706778496b22527f3a2e4d6fa91610 wp-block-paragraph\">&#8220;What is the name of the process that executed the newly downloaded stage 2 payload?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"895\" height=\"467\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062315.png\" alt=\"\" class=\"wp-image-2814\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062315.png 895w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062315-300x157.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062315-768x401.png 768w\" sizes=\"auto, (max-width: 895px) 100vw, 895px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-d0eea75b53f32b4a477f3db59aad7f93 wp-block-paragraph\">&#8220;What is the full file path of the malicious stage 2 payload?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"582\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062433-1024x582.png\" alt=\"\" class=\"wp-image-2815\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062433-1024x582.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062433-300x171.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062433-768x437.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-062433.png 1162w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-15648c33c937672d13f248e9d0846f54 wp-block-paragraph\">&#8220;What is the PID of the process that executed the stage 2 payload?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"815\" height=\"203\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-063308.png\" alt=\"\" class=\"wp-image-2816\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-063308.png 815w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-063308-300x75.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-063308-768x191.png 768w\" sizes=\"auto, (max-width: 815px) 100vw, 815px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-3f5f54f798a04d551c697d4e62166a9b wp-block-paragraph\">Scroll down to find wscript.<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"157\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065643-1024x157.png\" alt=\"\" class=\"wp-image-2817\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065643-1024x157.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065643-300x46.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065643-768x117.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065643.png 1171w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-2d5867898db45d651a62ef582505619b wp-block-paragraph\">&#8220;What is the parent PID of the process that executed the stage 2 payload?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"134\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065738-1024x134.png\" alt=\"\" class=\"wp-image-2819\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065738-1024x134.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065738-300x39.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065738-768x100.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-065738.png 1177w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-f3dea4ee33e23b15428585b17f1ccb09 wp-block-paragraph\">&#8220;What URL is used to download the malicious binary executed by the stage 2 payload?&#8221;<br><br>Doing the previous Volatility room and keeping notes assisted me with the next questions!<br><br>While in \/Desktop\/Artefacts, I created a new directory. I went with mkdir resume_investigation. After this is confirmed, I used the command: vol -f WKSTN-2961.raw -o resume_investigation\/ windows.memmap.Memmap &#8211;pid 4260 &#8211;dump<br><br>At first, I thought my VM was hung up after running this but it eventually kicked through. <\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"105\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-080251-1024x105.png\" alt=\"\" class=\"wp-image-2821\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-080251-1024x105.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-080251-300x31.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-080251-768x79.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-080251.png 1142w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-5537ee08c91052ada655ba82313457d1 wp-block-paragraph\">I performed some more commands, but I am not finding the answers. So instead of doing pid 4260, I rerun the command with the ppid of 1124 vol -f WKSTN-2961.raw -o resume_investigation\/ windows.memmap.Memmap &#8211;pid 1124 &#8211;dump.<br><br>After this, I obtain the executable.<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"935\" height=\"108\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-083125.png\" alt=\"\" class=\"wp-image-2822\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-083125.png 935w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-083125-300x35.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-09-083125-768x89.png 768w\" sizes=\"auto, (max-width: 935px) 100vw, 935px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-01ebf9dc830812bba093d5654ec703ec wp-block-paragraph\">&#8220;What is the PID of the malicious process used to establish the C2 connection?&#8221;<br><br>I saw this earlier while I was looking for the exe, but if you do strings pid.1124.dmp | grep updater, you will notice the pattern.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"878\" height=\"289\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-062239-2.png\" alt=\"\" class=\"wp-image-2828\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-062239-2.png 878w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-062239-2-300x99.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-062239-2-768x253.png 768w\" sizes=\"auto, (max-width: 878px) 100vw, 878px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"176\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-054734-1024x176.png\" alt=\"\" class=\"wp-image-2825\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-054734-1024x176.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-054734-300x51.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-054734-768x132.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-054734.png 1178w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-0563e806a1d6ecaf8dc117ec60ab8033 wp-block-paragraph\">&#8220;What is the full file path of the malicious process used to establish the C2 connection?&#8221;<br><br>See above for the path. <br><br>&#8220;What is the IP address and port of the C2 connection initiated by the malicious binary? (Format: IP address:port)&#8221;<br><br>For this, I used vol -f WKSTN-2961.raw windows.netscan | grep -iE &#8220;wscript|updater&#8221;. I get 128.199.95.189:8080 for the answer.<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"384\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-065454-1024x384.png\" alt=\"\" class=\"wp-image-2829\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-065454-1024x384.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-065454-300x113.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-065454-768x288.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-065454.png 1172w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-8d5f6e64b0b66a9efb982a355a51d8f2 wp-block-paragraph\">&#8220;What is the full file path of the malicious email attachment based on the memory dump?&#8221;<br><br>I use the command vol -f WKSTN-2961.raw windows.handles &#8211;pid 4260 | grep -i &#8220;file&#8221;. Let&#8217;s look into INetCache. <code>INetCache<\/code> is where Internet Explorer\/Outlook stores temporary internet files and email attachments!<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"255\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-070935-1024x255.png\" alt=\"\" class=\"wp-image-2830\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-070935-1024x255.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-070935-300x75.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-070935-768x192.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-070935.png 1175w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-2075ca3a7f52dbb9de67fe23180f1328 wp-block-paragraph\">&#8220;The attacker implanted a scheduled task right after establishing the C2 callback. What is the full command used by the attacker to maintain persistent access?&#8221;<br><br>Running vol -f WKSTN-2961.raw windows.cmdline, I see there is an empty cmd.exe coming up&#8230; hmmmm. Let&#8217;s dump it!<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"301\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-072948-1024x301.png\" alt=\"\" class=\"wp-image-2831\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-072948-1024x301.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-072948-300x88.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-072948-768x226.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-072948.png 1187w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-169de2c15af593cc096d3c09ad0bc937 wp-block-paragraph\">vol -f WKSTN-2961.raw -o resume_investigation\/ windows.memmap.Memmap &#8211;pid 6932 &#8211;dump<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"564\" height=\"57\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-074357.png\" alt=\"\" class=\"wp-image-2832\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-074357.png 564w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-074357-300x30.png 300w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"116\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-080430-1024x116.png\" alt=\"\" class=\"wp-image-2833\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-080430-1024x116.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-080430-300x34.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-080430-768x87.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-10-080430.png 1174w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-palette-color-7-color has-palette-color-4-background-color has-text-color has-background has-link-color wp-elements-a5161ccfec8bd1f0a2a889dccdf627b1 wp-block-paragraph\">So unfortunately, it didn&#8217;t give me the full schtask. I also looked into the other pid to no avail. Knowing it was schtask, I decided to do strings WKSTN-2961.raw | grep -i &#8220;schtasks&#8221; and got the full path!<\/p>\n\n\n\n<figure class=\"wp-block-image alignwide size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"305\" src=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-11-072714-1024x305.png\" alt=\"\" class=\"wp-image-2834\" srcset=\"https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-11-072714-1024x305.png 1024w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-11-072714-300x89.png 300w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-11-072714-768x229.png 768w, https:\/\/zombierollz.blog\/wp-content\/uploads\/2026\/04\/Screenshot-2026-04-11-072714.png 1175w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>https:\/\/tryhackme.com\/room\/boogeyman2Created by: tryhackme, ar33zy &#8220;This room may require the combined knowledge gained from the&nbsp;SOC&nbsp;L1&nbsp;Path. We recommend going&nbsp;through the following rooms before attempting this challenge.&#8221; Phishing&nbsp;Analysis FundamentalsPhishing&nbsp;Analysis ToolsBoogeyman 1Volatility I&#8217;ve just completed the Volatility room and highly recommend it! We are going to be using this tool along with Olevba. https:\/\/github.com\/volatilityfoundation\/volatility3https:\/\/volatility3.readthedocs.io\/en\/latest\/volatility3.plugins.htmlhttps:\/\/github.com\/decalage2\/oletools On to task 2! &#8220;Maxine, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2797","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"blocksy_meta":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2797"}],"version-history":[{"count":7,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2797\/revisions"}],"predecessor-version":[{"id":2835,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=\/wp\/v2\/posts\/2797\/revisions\/2835"}],"wp:attachment":[{"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zombierollz.blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}