2024数证杯决赛团体赛

容器密码

个人赛:

4zL!$WpRkmANv@XFQ#7HdEyU&GpoTb56YZ^Jq83!Wr(tqA%XsPB7f@CY1xRmKH9#Le*WVG9NuvT$kJ2@7b64Tp(FLM#zqRY8Hv%!KU^9C&YXL*powq87Hr

团体赛:

mW7@B!tRp*Xz46Y9#KFUV^J2&NqoHqTpLCE%8rvGW(AX#1k@YL3$M5!bWY*9HLFq7UZR6^T!XoVmPK28J&CY9%6(Arz#tbU4oXYKLp7Wq^FV9H

题目

请根据计算机以及内存检材,回答以下问题: (17道题,共54.0分)

1.计算机中曾挂载的bitlocker加密的分区的驱动器号为?(答案格式:大写字母,如C) (2.0分)

先找到对应的虚拟磁盘

image-20250502105840103

image-20250502121704759

V

2.分析计算机和内存检材,计算机中的Bitlocker加密分区的恢复密钥后6位为?(答案格式:123456) (4.0分)

image-20250502105950649

image-20250502121459365
469876-653598-354629-023573-566423-569162-055055-432267

432267

3.计算机中通过向日葵接收的最后一个文件名称为?(答案格式:需带后缀名,如Abc.doc) (4.0分)

image-20250502112244266

我们走在大路上.doc

4.计算机中加密容器8df84968a5b8c4d072c4daa4fd02cb19的解密密码为? (2.0分)

image-20250502115525926

image-20250502120055005

用xways才行

ppnn13%323658970YYZZ

ppnn13%323658970YYZZ

5.接上题,计算机中曾挂载的该加密容器分区中最后访问的文件,其文件名为?(答案格式:需带后缀名,如Abc.doc) (2.0分)

image-20250502121010500

d7ed12489b9f8b521db78d121badbe83.jpg

6.请找到计算机中MD5值为2EA4D8A203F6CAFBDA0F6947EE2F0FE5的文件,写出其文件内容;(答案格式:需与实际一致,且涉及符号的部分半角全角需与实际一致) (4.0分)

image-20250502113222084

MD5不对

火眼分析自动给解密了

image-20250502121940383

解密之前的用xray看

image-20250502122347448

image-20250502122438211

好好学习!

7.计算机中sharisun520@hotmail.com在2010年5月11日收到的邮件附件图片中的联系电话为? (6.0分)

image-20250502110813510

image-20250502110828533

打开都是乱码:

image-20250502110916114

image-20250502110954748

image-20250502111042623

image-20250502111053707

087864898788

8.计算机中MD5值为E653DF74D36008353C88F5A58B8F9326的文件是从哪个网址上下载的?(答案格式: http://abc/... ) (1.0分)

image-20250502111353099

image-20250502111421326

http://suprbaydvdcaynfo4dgdzgxb4zuso7rftlil5yg5kqjefnw4wq4ulcad.onion/attachment.php?aid=3909

9.计算机中2024年11月12日 11:23:25访问的暗网网址为?(答案格式: http://abc/... ) (1.0分)

image-20250502110726130

http://suprbaydvdcaynfo4dgdzgxb4zuso7rftlil5yg5kqjefnw4wq4ulcad.onion/Thread-The-Guess-The-Movie-game

10.请找到嫌疑人曾经接收的文件“DefeatedJoyousNightingale.pdf“,计算其SHA-256值;(答案格式:如遇字母全大写) (6.0分)

image-20250502111458164

B4380011D8C1E4AB6CCCA1380CE81F9B9144EA8D06E9814210D63A959B74E6E3

11.计算机中包含由两个字母、五个数字、“CW”和四个数字组成的内容的文件名是?(答案格式:需带后缀名,如Abc.doc) (3.0分)

注意是内容

[A-Za-z]{2}\d{5}CW\d{4}

12.请写出计算机中系统分区上文件系统的卷序列号;(答案格式:全部8字节,小端序,忽略空格,如FA33C08ED0BC007C) (2.0分)

image-20250502123224366

D466CEF666CED7FE

13.计算机中最后接入的U盘的卷标名称是什么?(答案格式:如abcd111A) (5.0分)

image-20250502123910210

image-20250502123921511

去注册表看卷标名称:

思路二:

看名字只有

image-20250502124958993

image-20250502133332835

验证:

image-20250502133357927

image-20250502133442917

xing120G

14.计算机中程序wordpad.exe一共运行了多少次?(答案格式:请直接写数字,如6) (1.0分)

image-20250502112609664

2

15.计算机内存中正打开的图片中的动物为?(答案格式:直接写出动物名称,如狗) (4.0分)

image-20250502125306604

导出后foremost分离

foremost -T minidump_pid_868.dmp

image-20250502130618118

16.计算机内存中本地浏览器使用哪个端口连接到了184.30.21.38?(答案格式:纯数字) (2.0分)

image-20250502130739940

50391

17.计算机内存中极速浏览器最后浏览的网址的登录密码?(答案格式:与实际大小写需一致) (5.0分)

image-20250502131804648

https://www.hdavchina.com/

image-20250502132833454

image-20250502133128125

Zhang333

请根据手机检材,回答以下问题: (9道题,共34.0分)

1.分析手机检材,请找出嫌疑人的手机号; (2.0分)

image-20250502134011411

13023161693

2.分析手机检材,嫌疑人曾经访问的公共服务后台管理系统的URL是?(答题格式: https://abc/... ) (4.0分)

image-20250502134148593

https://ltadpoles.github.io/#/login

3.分析手机检材,找出嫌疑人在笔记中记录的接头地点;(答案格式:需与实际完全一致) (4.0分)

image-20250502210146588

根据文件结构来看,观察原文件和模拟器文件的结构,分别复制进去

image-20250502210227489

image-20250502210235740

上海市浦东新区木兰花路666号

4.分析手机检材,找出嫌疑人的接头暗号;(答案格式:需与实际完全一致) (6.0分)

image-20250502210300440

送你一朵小红花

5.分析手机检材,找出嫌疑人10月23日开的腾讯会议的入会密码; (2.0分)

image-20250502182721375

201808

6.分析手机检材,找出嫌疑人公司即将发布的新产品型号;(答案格式:需与实际大小写完全一致) (4.0分)

image-20250502210415841

image-20250502211358794

生日爆破

image-20250502211425037

AeroX-900

7.分析手机检材,找到嫌疑人曾经发送的项目前期资料文件,计算其SHA256;(答案格式:如遇字母全大写) (4.0分)

image-20250502211257529

image-20250502211312252

image-20250502211320992

c81de1b2d58755ef712e0c52381be6a6de58d491f4f2bfe9ff34d21f336c315e

8.分析手机检材,嫌疑人曾进行过一次交易,请问嫌疑人与转账的接收者什么时候成为好友?(答案格式:2021-01-01 01:01:01) (2.0分)

image-20250502210848535

2024-10-23 15:33:21

9.分析手机检材,写出嫌疑人钱包账户的导入时间;(北京时区,答案格式:1990-01-01 01:01:01) (6.0分)

image-20250502212941607

位置:persist-root

image-20250502213028231

image-20250502213340998

2024-11-22 17:18:30.166000

请根据服务器检材,回答以下问题: (20道题,共65.0分)

1.请写出服务器系统内核版本;(答案格式:1.1.1-11-abcdefe) (1.0分)

image-20250502224345929

6.8.0-48-generic

2.请写出服务器的ens33网卡的ip地址; (1.0分)

image-20250502224500454

10.172.29.128

3.请写出mysql数据库密码; (4.0分)

image-20250502225100838

网站源码

image-20250502225306648

image-20250502231634568

123568

4.后台服务中注册中心的服务端口是多少?(答案格式:纯数字) (2.0分)

image-20250502232659573

在cloud里面

image-20250502233545272

7000

5.服务器nginx日志中,哪个ip访问系统最为频繁?(答案格式:6.6.6.6) (6.0分)

cat access.log.1 | awk '{print $1}' | sort | uniq -c | sort -nr

image-20250502233146025

56.111.197.176

6.请写出平台管理员密码加密算法;(答案格式:aes) (3.0分)

image-20250502234745186

image-20250502234734503

MD5

7.假设某管理员密码是123456,请问该管理员的密码在数据库中存储的值是多少?(答案格式:如有字母,全大写) (5.0分)

XehGyeyrVgOV4P8Uf70REVpIw3iVNwNs

image-20250502234834872

985eb5b028065701341a478a9215e7b2

8.已知某人卖出了5.2个ETH/USDT,请问他的二级推荐人可以获得多少个ETH佣金?(答案格式:写出数字即可,保留小数点后5位) (6.0分)

*重构

find ./ -type f -exec sed -i 's/127.0.0.1/192.168.217.233/g' {} +
image-20250503000205238

image-20250503000655036

image-20250503000647463

    public void processOrder(ExchangeOrder order, ExchangeTrade trade, ExchangeCoin coin, boolean secondReferrerAward) {
        BigDecimal turnover;
        BigDecimal fee;
        BigDecimal incomeCoinAmount;
        BigDecimal outcomeCoinAmount;
        try {
            Long time = Long.valueOf(Calendar.getInstance().getTimeInMillis());
            ExchangeOrderDetail orderDetail = new ExchangeOrderDetail();
            orderDetail.setOrderId(order.getOrderId());
            orderDetail.setTime(time.longValue());
            orderDetail.setPrice(trade.getPrice());
            orderDetail.setAmount(trade.getAmount());
            if (order.getDirection() == ExchangeOrderDirection.BUY) {
                turnover = trade.getBuyTurnover();
            } else {
                turnover = trade.getSellTurnover();
            }
            orderDetail.setTurnover(turnover);
            if (order.getDirection() == ExchangeOrderDirection.BUY) {
                fee = trade.getAmount().multiply(coin.getFee());
            } else {
                fee = turnover.multiply(coin.getFee());
            }
            if (order.getMemberId().longValue() == 1 || order.getMemberId().longValue() == 10001) {
                fee = BigDecimal.ZERO;
            }
            orderDetail.setFee(fee);
            this.exchangeOrderDetailRepository.save((ExchangeOrderDetailRepository) orderDetail);
            OrderDetailAggregation aggregation = new OrderDetailAggregation();
            aggregation.setType(OrderTypeEnum.EXCHANGE);
            aggregation.setAmount(order.getAmount().doubleValue());
            aggregation.setFee(orderDetail.getFee().doubleValue());
            aggregation.setTime(orderDetail.getTime());
            aggregation.setDirection(order.getDirection());
            aggregation.setOrderId(order.getOrderId());
            if (order.getDirection() == ExchangeOrderDirection.BUY) {
                aggregation.setUnit(order.getBaseSymbol());
            } else {
                aggregation.setUnit(order.getCoinSymbol());
            }
            Member member = this.memberService.findOne(order.getMemberId());
            if (member != null) {
                aggregation.setMemberId(member.getId());
                aggregation.setUsername(member.getUsername());
                aggregation.setRealName(member.getRealName());
            }
            this.orderDetailAggregationRepository.save((OrderDetailAggregationRepository) aggregation);
            if (order.getDirection() == ExchangeOrderDirection.BUY) {
                incomeCoinAmount = trade.getAmount().subtract(fee);
            } else {
                incomeCoinAmount = turnover.subtract(fee);
            }
            String incomeSymbol = order.getDirection() == ExchangeOrderDirection.BUY ? order.getCoinSymbol() : order.getBaseSymbol();
            MemberWallet incomeWallet = this.memberWalletService.findByCoinUnitAndMemberId(incomeSymbol, order.getMemberId());
            this.memberWalletService.increaseBalance(incomeWallet.getId(), incomeCoinAmount);
            String outcomeSymbol = order.getDirection() == ExchangeOrderDirection.BUY ? order.getBaseSymbol() : order.getCoinSymbol();
            if (order.getDirection() == ExchangeOrderDirection.BUY) {
                outcomeCoinAmount = turnover;
            } else {
                outcomeCoinAmount = trade.getAmount();
            }
            MemberWallet outcomeWallet = this.memberWalletService.findByCoinUnitAndMemberId(outcomeSymbol, order.getMemberId());
            this.memberWalletService.decreaseFrozen(outcomeWallet.getId(), outcomeCoinAmount);
            MemberTransaction transaction = new MemberTransaction();
            transaction.setAmount(incomeCoinAmount);
            transaction.setSymbol(incomeSymbol);
            transaction.setAddress("");
            transaction.setMemberId(incomeWallet.getMemberId());
            transaction.setType(TransactionType.EXCHANGE);
            transaction.setFee(fee);
            transaction.setDiscountFee("0");
            transaction.setRealFee(fee.toString());
            this.transactionService.save(transaction);
            MemberTransaction transaction2 = new MemberTransaction();
            transaction2.setAmount(outcomeCoinAmount.negate());
            transaction2.setSymbol(outcomeSymbol);
            transaction2.setAddress("");
            transaction2.setMemberId(incomeWallet.getMemberId());
            transaction2.setType(TransactionType.EXCHANGE);
            transaction2.setFee(BigDecimal.ZERO);
            transaction2.setRealFee("0");
            transaction2.setDiscountFee("0");
            this.transactionService.save(transaction2);
            try {
                if (order.getDirection() == ExchangeOrderDirection.SELL) {
                    promoteReward(fee, member, incomeSymbol, secondReferrerAward);
                }
            } catch (Exception e) {
                e.printStackTrace();
                log.error("发放币币交易推广手续费佣金出错", (Throwable) e);
            }
        } catch (Exception e2) {
            log.info(">>>>>处理交易明细出错>>>>>>>>>{}", (Throwable) e2);
            e2.printStackTrace();
        }
    }

找到promoteReward

public void promoteReward(BigDecimal fee, Member member, String incomeSymbol, boolean secondReferrerAward) {
        RewardPromotionSetting rewardPromotionSetting = this.rewardPromotionSettingService.findByType(PromotionRewardType.EXCHANGE_TRANSACTION);
        if (rewardPromotionSetting != null && member.getInviterId() != null && DateUtil.diffDays(new Date(), member.getRegistrationTime()) <= rewardPromotionSetting.getEffectiveTime()) {
            Member member1 = this.memberService.findOne(member.getInviterId());
            MemberWallet memberWallet = this.memberWalletService.findByCoinUnitAndMemberId(incomeSymbol, member1.getId());
            JSONObject jsonObject = JSONObject.parseObject(rewardPromotionSetting.getInfo());
            BigDecimal reward = BigDecimalUtils.mulRound(fee, BigDecimalUtils.getRate(jsonObject.getBigDecimal("one")), 8);
            if (reward.compareTo(BigDecimal.ZERO) > 0) {
                this.memberWalletService.increaseBalance(memberWallet.getId(), reward);
                MemberTransaction memberTransaction = new MemberTransaction();
                memberTransaction.setAmount(reward);
                memberTransaction.setFee(BigDecimal.ZERO);
                memberTransaction.setMemberId(member1.getId());
                memberTransaction.setSymbol(incomeSymbol);
                memberTransaction.setType(TransactionType.PROMOTION_AWARD);
                memberTransaction.setDiscountFee("0");
                memberTransaction.setRealFee("0");
                this.transactionService.save(memberTransaction);
                RewardRecord rewardRecord1 = new RewardRecord();
                rewardRecord1.setAmount(reward);
                rewardRecord1.setCoin(memberWallet.getCoin());
                rewardRecord1.setMember(member1);
                rewardRecord1.setRemark(rewardPromotionSetting.getType().getCnName());
                rewardRecord1.setType(RewardRecordType.PROMOTION);
                this.rewardRecordService.save(rewardRecord1);
            }
            if (!secondReferrerAward) {
                log.info("控制字段 : secondReferrerAward ={} , 跳过二级推荐人返佣", Boolean.valueOf(secondReferrerAward));
                return;
            }
            if (member1.getInviterId() != null && DateUtil.diffDays(new Date(), member1.getRegistrationTime()) <= rewardPromotionSetting.getEffectiveTime()) {
                Member member2 = this.memberService.findOne(member1.getInviterId());
                MemberWallet memberWallet1 = this.memberWalletService.findByCoinUnitAndMemberId(incomeSymbol, member2.getId());
                BigDecimal reward1 = BigDecimalUtils.mulRound(fee, BigDecimalUtils.getRate(jsonObject.getBigDecimal("two")), 8);
                if (reward1.compareTo(BigDecimal.ZERO) > 0) {
                    this.memberWalletService.increaseBalance(memberWallet1.getId(), reward);
                    MemberTransaction memberTransaction2 = new MemberTransaction();
                    memberTransaction2.setAmount(reward1);
                    memberTransaction2.setFee(BigDecimal.ZERO);
                    memberTransaction2.setMemberId(member2.getId());
                    memberTransaction2.setSymbol(incomeSymbol);
                    memberTransaction2.setType(TransactionType.PROMOTION_AWARD);
                    this.transactionService.save(memberTransaction2);
                    RewardRecord rewardRecord12 = new RewardRecord();
                    rewardRecord12.setAmount(reward1);
                    rewardRecord12.setCoin(memberWallet1.getCoin());
                    rewardRecord12.setMember(member2);
                    rewardRecord12.setRemark(rewardPromotionSetting.getType().getCnName());
                    rewardRecord12.setType(RewardRecordType.PROMOTION);
                    this.rewardRecordService.save(rewardRecord12);
                }
            }
        }
    }

image-20250503001253704

image-20250503002054257

所以,ETH/USDT的手续费是0.001,然后二级推荐人是0.1

5.2*0.001*0.1=0.00052

0.00052

9.请找到受害人“王涵”的手机号; (1.0分)

image-20250503000357964

15780139471

10.请写出嫌疑人的违法交易网站的中文名称;(答案格式:2个汉字) (3.0分)

image-20250503000409003

币严

11.请写出数据库中Recharge表的status字段中,0代表的中文含义; (1.0分)

image-20250503000436270

未到账

12.平台中所有账户中ETH余额最多的地址是多少?(答案格式:0x123F...) (6.0分)

既然是区块链,应该不会存储在数据库里面

./start.sh 
var maxBalance = web3.toBigNumber(0);
var richest = "";
eth.accounts.forEach(function(account) {
    var balance = eth.getBalance(account);
    if (balance.gt(maxBalance)) {
        maxBalance = balance;
        richest = account;
    }
});
console.log("Richest account is: " + richest);
console.log("Balance: " + web3.fromWei(maxBalance, "ether") + " ETH");

image-20250503004242286

13.区块链搭建工具是?(答案格式:abcd) (1.0分)

geth

14.区块链对外提供的的http端口是? (2.0分)

image-20250503004700985

http://192.168.217.233:8545/

只有这个能访问

8551

15.服务器网站数据库使用的字符集为?(答案格式:如有字母,请小写) (1.0分)

image-20250503004853313

utf8mb4

16.由于服务器定时清理了交易数据,请找寻整个区块链中最大的交易金额(答案格式:0x123F...) (6.0分)

var maxValue = web3.toBigNumber(0);
var maxTxHash = "";
var latest = eth.blockNumber;

for (var i = 0; i <= latest; i++) {
    var block = eth.getBlock(i, true);
    if (block && block.transactions.length > 0) {
        block.transactions.forEach(function(tx) {
            if (tx.value.gt(maxValue)) {
                maxValue = tx.value;
                maxTxHash = tx.hash;
            }
        });
    }
}

console.log("Max transaction value: " + web3.fromWei(maxValue, "ether") + " ETH");
console.log("Transaction hash: " + maxTxHash);

image-20250503005056308

0x960c77907381d08ecc019c0ad9d668a4bd456070f6f17ce0696d716150a50138

17.请写出嫌疑人在chrome上使用的钱包名称;(答案格式:如有字母全小写) (2.0分)

image-20250503005244494

metamask

18.请写出chrome钱包插件使用的pbkdf2加密算法的轮次;(答案格式:纯数字) (4.0分)

image-20250503005750765

image-20250503005812715

image-20250503010258389

600000

19.Chrome钱包密码的算法中对iv的加密方式是什么?(答案格式:如有字母请小写,如md5) (4.0分)

image-20250503011156755

image-20250503011211385

AES-GCM

20.已知服务器中嫌疑人的钱包登录密码为八位纯数字生日1994****,请写出该密码; (6.0分)

加密数据:

{
    "data": "4OBSCQ3fpgiiQG1CUT2KVKU9Sma1ixgcZ1xBb+XeQXlX9yFbyj6HgpPH4vKktB39FPVD5wlV0fFrKkrB4YvkwS4y0P2y15GrSMvJ7ZPV2FdT+o7/s9ydryf4j/dvWssWhlpIf8+Z/GTWxrd0pEKCumJ0SgM7pNCn+LPufqgAAc8Phk1V2G78YFFn27hoPalU+mfyLirBvbcNCe7PZhUEf02OB9HJxc6NL8VGHZ0mugf8CMCU4CfoMWBjGB358XwYgqVCAYfPeP612BcqH/2qGsf4v5MUynaoWjR3CDxg6z5n/SzvayET9KxzpnP5/YwrI1Kr6KSuX8hfWa4G7Qect7gRcJ5OSP9vjDAE0Oa7+2RoOvSuDhONrit9JD1j3PlF/HLHjCWcAxFPAqQHnaXHUT7+O/UR/nHBBUjwZqXcA3NvY6Up9gEyp7v252JKw/ybv9PYsNVBNNzaOCHM+2vLu4AEdhsJjEmzz1BMnl2a10lX3PIxT6g+eVdHNVOkeESS7Xiufrh1BNEXemU+/Mj8zOzC8X3sC+h7k6V+j8FO5gFFIsGVsehmhjQ0g3hv5OjHLu+8UbJ19HVC6nzyopbHF1EbgVc4bEfnsqxpBQT4xGY27MQLFa2SlcpRpue1NpZWdhV2C8/wTSBmcgnm3PHWgvBiuA==",
    "iv": "oi49chysOL0hAXfqbviWIA==",
    "keyMetadata": {
        "algorithm": "PBKDF2",
        "params": {
            "iterations": 600000
        }
    },
    "salt": "fhlH2383hn7sqEKiLN8zSqv/F/v9x0s3xj/1zBI1zkA="
}

加密方式:

{
    "name": "AES-GCM",
    "length": 256
}

解密脚本:

import base64
import json
import datetime
from cryptography.hazmat.primitives.kdf.pbkdf2 import PBKDF2HMAC
from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.primitives.ciphers.aead import AESGCM
from cryptography.hazmat.backends import default_backend

# 原始数据(从JSON中提取)
data_b64 = "4OBSCQ3fpgiiQG1CUT2KVKU9Sma1ixgcZ1xBb+XeQXlX9yFbyj6HgpPH4vKktB39FPVD5wlV0fFrKkrB4YvkwS4y0P2y15GrSMvJ7ZPV2FdT+o7/s9ydryf4j/dvWssWhlpIf8+Z/GTWxrd0pEKCumJ0SgM7pNCn+LPufqgAAc8Phk1V2G78YFFn27hoPalU+mfyLirBvbcNCe7PZhUEf02OB9HJxc6NL8VGHZ0mugf8CMCU4CfoMWBjGB358XwYgqVCAYfPeP612BcqH/2qGsf4v5MUynaoWjR3CDxg6z5n/SzvayET9KxzpnP5/YwrI1Kr6KSuX8hfWa4G7Qect7gRcJ5OSP9vjDAE0Oa7+2RoOvSuDhONrit9JD1j3PlF/HLHjCWcAxFPAqQHnaXHUT7+O/UR/nHBBUjwZqXcA3NvY6Up9gEyp7v252JKw/ybv9PYsNVBNNzaOCHM+2vLu4AEdhsJjEmzz1BMnl2a10lX3PIxT6g+eVdHNVOkeESS7Xiufrh1BNEXemU+/Mj8zOzC8X3sC+h7k6V+j8FO5gFFIsGVsehmhjQ0g3hv5OjHLu+8UbJ19HVC6nzyopbHF1EbgVc4bEfnsqxpBQT4xGY27MQLFa2SlcpRpue1NpZWdhV2C8/wTSBmcgnm3PHWgvBiuA=="
iv_b64 = "oi49chysOL0hAXfqbviWIA=="
salt_b64 = "fhlH2383hn7sqEKiLN8zSqv/F/v9x0s3xj/1zBI1zkA="

ciphertext = base64.b64decode(data_b64)
iv = base64.b64decode(iv_b64)
salt = base64.b64decode(salt_b64)

# 参数
iterations = 600000
backend = default_backend()

def derive_key(password: str):
    kdf = PBKDF2HMAC(
        algorithm=hashes.SHA256(),
        length=32,
        salt=salt,
        iterations=iterations,
        backend=backend
    )
    return kdf.derive(password.encode())

# 枚举所有合法日期(格式为 1994MMDD)
for month in range(1, 13):
    for day in range(1, 32):
        try:
            date = datetime.date(1994, month, day)
            password = date.strftime("%Y%m%d")
            key = derive_key(password)
            aesgcm = AESGCM(key)
            try:
                plaintext = aesgcm.decrypt(iv, ciphertext, None)
                try:
                    result = json.loads(plaintext)
                    print(f"[✅] 找到密码:{password}")
                    print("[📦] 解密结果:", json.dumps(result, indent=2, ensure_ascii=False))
                    exit(0)
                except:
                    continue
            except:
                continue
        except:
            continue

print("[❌] 没有找到正确密码")

结果:

[✅] 找到密码:19940822
[📦] 解密结果: [
  {
    "type": "HD Key Tree",
    "data": {
      "mnemonic": [
        115,
        116,
        101,
        109,
        32,
        100,
        101,
        110,
        105,
        97,
        108,
        32,
        102,
        111,
        111,
        100,
        32,
        115,
        99,
        114,
        97,
        112,
        32,
        115,
        104,
        111,
        118,
        101,
        32,
        110,
        101,
        99,
        107,
        32,
        114,
        101,
        98,
        117,
        105,
        108,
        100,
        32,
        108,
        97,
        98,
        101,
        108,
        32,
        114,
        105,
        100,
        101,
        32,
        99,
        97,
        110,
        118,
        97,
        115,
        32,
        101,
        110,
        97,
        99,
        116,
        32,
        115,
        104,
        101,
        114,
        105,
        102,
        102
      ],
      "numberOfAccounts": 1,
      "hdPath": "m/44'/60'/0'/0"
    }
  },
  {
    "type": "Ledger Hardware",
    "data": {
      "hdPath": "m/44'/60'/0'",
      "accounts": [],
      "accountDetails": {},
      "implementFullBIP44": false
    }
  }
]

19940822

(请勿在真机上运行或分析该ex)请根据exe检材,回答问题: (9道题,共29.0分)

1.通过分析恶意程序,找出运行该软件必要的参数是?(答案格式:--xxx-xxx) (2.0分)

image-20250502220450605

--access-token

2.该程序为了控制控制最大并发数,在注册表中设置了MaxMpxCt参数,请给出设置参数的具体值。(答案格式:纯数字) (2.0分)

image-20250502214247902

.rdata:006825E4	000000F0	C	locker::core::os::windows::file_unlockersrc/core/os/windows/file_unlocker.rsreg add HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\LanmanServer\\Parameters /v MaxMpxCt /d 65533 /t REG_DWORD /ffsutil behavior set SymlinkEvaluation R2R:1

65533

3.该程序运行过程中会创建新的分区磁盘,请写出该分区磁盘一级目录中的文件名。(答案格式:如有字母请大写) (2.0分)

image-20250502221801675

RECOVER-cvz8n37-FILES.txt

4.该程序获取计算机名时使用的kernel32库函数是什么?(答案格式:kernel32.xxx) (2.0分)

image-20250502215221943

image-20250502215228506

image-20250502215241294

kernel32.GetComputerNameW

5.根据该程序的加密过程逻辑,已知加密文件后缀为cvz8n37,且系统中存在core_code.c文件,请写出程序在加密该文件前生成的文件名。(答案格式:xxx.cvz8n37) (3.0分)

image-20250502215711766

{"config_id":"","public_key":"MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA4gnBZNNkKwmyzzwdmEHPuAYLLVseu+L3XEKgHhvKvwROTqkBYCE9ZND9I5oBwfCciCa32+FvBXHTVbY9TkTWmMYtgyDMrd3leo9oA8Mt+07jNK+O6ULFRvw+lZAakjkbiWLLBL24kgBWzYJk2brrrAoEx0/Xldp8uOJOUPrc2rpcJqkczeKpw4Qc8q6NKJ/ArEYXdRwbuUq+xkQGZ10bGHbXnI4dGvue1pscK1qXB5f+YDTwBC1/sN0J/LKNWaAQZuZDsGBdsYTw67DhfPrXD5FXy4e5a8pLwxVyLPgP0qjRvedn/GvX8NNdIFrFNuY+n2B5fHOPscbNmSXs4kw/NwIDAQAB","extension":"cvz8n37","note_file_name":"RECOVER-${EXTENSION}-FILES.txt","note_full_text":">> What happened?\n\nImportant files on your network was ENCRYPTED and now they have \"${EXTENSION}\" extension.\nIn order to recover your files you need to follow instructions below.\n\n>> Sensitive Data\n\nSensitive data on your network was DOWNLOADED.\nIf you DON', 27h, \T WANT your sensitive data to be PUBLISHED you have to act quickly.\n\nData includes:\n- Employees personal data, CVs, DL, SSN.\n- Complete network map including credentials for local and remote services.\n- Private financial information including: clients data, bills, budgets, annual reports, bank statements.\n- Manufacturing documents including: datagrams, schemas, drawings in solidworks format\n- And more...\n\n>> CAUTION\n\nDO NOT MODIFY ENCRYPTED FILES YOURSELF.\nDO NOT USE THIRD PARTY SOFTWARE TO RESTORE YOUR DATA.\nYOU MAY DAMAGE YOUR FILES, IT WILL RESULT IN PERMANENT DATA LOSS.\n\n>> What should I do next?\n\n1) Download and install Tor Browser from: https://torproject.org/\n2) Navigate to: http://gbxbwicx3x35kn7n73opnpp4kkzjcra42iv2akoo2dcjinf6jf6qbuyd.onion/?access-key=${ACCESS_KEY}","note_short_text":"Important files on your network was DOWNLOADED and ENCRYPTED.\nSee \"${NOTE_FILE_NAME}\" file to get further instructions.","default_file_mode":"Auto","default_file_cipher":"Best","credentials":[],"kill_services":["mepocs","memtas","veeam","svc$","backup","sql","vss","msexchange","sql$","mysql","mysql$","sophos","MSExchange","MSExchange$","WSBExchange","PDVFSService","BackupExecVSSProvider","BackupExecAgentAccelerator","BackupExecAgentBrowser","BackupExecDiveciMediaService","BackupExecJobEngine","BackupExecManagementService","BackupExecRPCService","GxBlr","GxVss","GxClMgrS","GxCVD","GxCIMgr","GXMMM","GxVssHWProv","GxFWD","SAPService","SAP","SAP$","SAPD$","SAPHostControl","SAPHostExec","QBCFMonitorService","QBDBMgrN","QBIDPService","AcronisAgent","VeeamNFSSvc","VeeamDeploymentService","VeeamTransportSvc","MVArmor","MVarmor64","VSNAPVSS","AcrSch2Svc"],"kill_processes":["agntsvc","dbeng50","dbsnmp","encsvc","excel","firefox","infopath","isqlplussvc","msaccess","mspub","mydesktopqos","mydesktopservice","notepad","ocautoupds","ocomm","ocssd","onenote","oracle","outlook","powerpnt","sqbcoreservice","sql","steam","synctime","tbirdconfig","thebat","thunderbird","visio","winword","wordpad","xfssvccon","*sql*","bedbh","vxmon","benetns","bengien","pvlsvr","beserver","raw_agent_svc","vsnapvss","CagService","QBIDPService","QBDBMgrN","QBCFMonitorService","SAP","TeamViewer_Service","TeamViewer","tv_w32","tv_x64","CVMountd","cvd","cvfwd","CVODS","saphostexec","saposcol","sapstartsrv","avagent","avscc","DellSystemDetect","EnterpriseClient","VeeamNFSSvc","VeeamTransportSvc","VeeamDeploymentSvc"],"exclude_directory_names":["system volume information","intel","$windows.~ws","application data","$recycle.bin","mozilla","$windows.~bt","public","msocache","windows","default","all users","tor browser","programdata","boot","config.msi","google","perflogs","appdata","windows.old"],"exclude_file_names":["desktop.ini","autorun.inf","ntldr","bootsect.bak","thumbs.db","boot.ini","ntuser.dat","GASS_SYS.sys","bootfont.bin","ntuser.ini","ntuser.dat.log"],"exclude_file_extensions":["themepack","nls","diagpkg","msi","lnk","exe","cab","scr","bat","drv","rtp","msp","prf","msc","ico","key","ocx","diagcab","diagcfg","pdb","wpx","hlp","icns","rom","dll","msstyles","mod","ps1","ics","hta","bin","cmd","ani","386","lock","cur","idx","sys","com","deskthemepack","shs","ldf","theme","mpa","nomedia","spl","cpl","adv","icl","msu"],"exclude_file_path_wildcard":[],"enable_network_discovery":true,"enable_self_propagation":true,"enable_set_wallpaper":true,"enable_esxi_vm_kill":true,"enable_esxi_vm_snapshot_kill":true,"strict_include_paths":[],"esxi_vm_kill_exclude":[]}

image-20250502223037914

image-20250502223315636

猜一下

checkpoints-core_code.c.cvz8n37

6.该程序在提权过程中会申请多项Windows权限,请写出尝试申请的第三项权限名。(答案格式:答案格式需与实际一致) (4.0分)

7.该程序运行过程中获取UUID时的完整命令为?(答案格式:"D:\xxx...\xxx.exe" xx "xxx xxx xxx xxx" (4.0分)

image-20250502221948470

"C:\Windows\system32\cmd.exe" /c "wmic csproduct get UUID"

8.该程序存在着默认配置文件,在该配置文件中默认不加密且文件后缀为sys的文件名是?(答案格式:包含后缀名,如xxxx.sys) (4.0分)

image-20250502223207052

GASS_SYS.sys

9.请写出该程序加密文件过程中,生成私钥函数返回值内"chipher"键对应的值。 (6.0分)

image-20250502223833949

猜的

55C3-5171-4C53-0439

请根据数据分析检材,回答以下问题: (6道题,共18.0分)

1.分析数据库检材,请分别计算该数据库中每个用户审核通过的提现总金额,写出审核通过的提现总金额最大值; (2.0分)

2.数据库中用户真实名称为“祝钦”的有效银行卡号是多少; (2.0分)

3.请计算数据库中地址在江苏省的启用用户数量; (2.0分)

4.请计算手机号字段中的号码数字“8”的数量大于等于3的用户数量; (4.0分)

5.计算每个用户审核通过的总提现金额与其总消费金额的比值,该比值大于等于0.5的用户数量是多少? (4.0分)

6.计算uid为“20257”的用户的下线最大层级数是多少(自己为第1层,若用户A是自己的直接下线,那么此时用户A所在层级=2); (4.0分)

posted @ 2026-05-25 20:57  Cava1i  阅读(19)  评论(0)    收藏  举报