2023美亚杯团体赛

密码

团队赛容器密码

#Zfa2w^t88vDk%VSi2CxT5*nBmbWN3W2gosfqFR#4@gj48Gfc$4bCME$mu5$G8foubAy6zFgs5KzMLX9mt^&UoNdBxDnFjV6wz@Fv#oWu#ZQVgB9F%oh57vYiSEGEkbv

附加資料容器密码

RSTq3p%#vxQ6Ckq^LmYS$%RRj8xv#HDR97ofE#LMp2KimG*5bgE5cYpbvZBLEM4%cA8i#^5$^NFEcjpW!YeQQrWsHckKvCoGkm!7kyY$#x3%x#!*q2R4h$4r3B%ewe@X

参考

https://www.cnblogs.com/WXjzc/p/17852716.html

https://mp.weixin.qq.com/s/CbUtF4xEuZ66GSRXOWnS3w

https://blog.csdn.net/Tummyiii/article/details/135638789

https://mp.weixin.qq.com/s/DJApiAccdrJ3u0DOyJDGRQ

https://forensics.xidian.edu.cn/git/NoahTie/Wiki/src/branch/master/docs/MeiyaCup2023Group.md

官方答案

https://www.meiyacup.com/Mo_index_gci_36.html

镜像分布

1.李哲圖的安卓手机镜像文件 (李哲圖的手機鏡像.zip)

2.李哲圖的车辆录像文件(李哲圖的車輛錄像.zip)

3.李哲圖的航拍机系统文件(李哲圖的航拍機.zip)

4.李哲圖的Windows计算机镜像文件(李哲圖的電腦鏡像.zip)

5.来自李哲圖的计算机网络封包文件(packet.pcapng)

6.李佩妍的iOS手机系统文件(李佩妍的手機鏡像.zip)

7.李佩妍的Windows计算机镜像文件(李佩妍的計算機鏡像.zip)

8.陳大昆的iOS手机系统文件(陳大昆的手機.zip)

9.陳大昆的Windows计算机镜像文件(陳大昆的計算機鏡像.zip)

10.陳大昆的macOS计算机镜像文件(陳大昆的MacBook.zip)

11.潘志輝的NAS盘镜像文件(潘志輝的NAS.zip)

12.潘志輝的U盘镜像文件(潘志輝的U盤.zip)

13.潘志輝的Windows计算机镜像文件(潘志輝的計算機鏡像.zip)

14.潘志輝的安卓手机系统文件(潘志輝的手機.zip)

15.陳好的Windows笔记本电脑镜像文件(陳好的計算機.zip)

16.陳好的安卓手机系统文件(陳好的手機.zip)

image-20240510094419195

Pasted image 20231117230955.png

题目

1. [填空题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question
死者手机中的一个智能家居应用程序中的帐号是什么?
What is the user ID of the Deceased’s account in a smart home app?
提示:请以阿拉伯数字填写答案
Tips: Please answer in arabic number (1分)

image-20240510090539945

1826082897

2. [单选题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question
死者手机中的智能家居应用程序内的智能门铃发送的最后一次通知消息的本地时间?
what is the local time of the last notification message sent by a smart doorbell in this smart home app?
(1分)
A.2023-09-25 07:51:18
B.2023-09-26 07:51:18
C.2023-09-26 15:51:18
D.2023-09-26 23:51:18
E.2023-09-28 01:11:11

image-20240510090604490

E

3. [单选题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question
死者在「Carousell」应用程序中首先接触的卖家是售卖什么类型产品的?
What is the type of product the Deceased first to approach the seller in the App of “Carousell”?
(2分)
A.无人机 (Drones)
B.运动鞋 (Sneakers)
C.电子游戏 (Video Games)
D.桌上计算机 (Desktops)
E.饮料 (Beverages)

image-20240510090902747

在/data/com.thecarousell.Carousell/databases/carousell_room.db的chat_messages表可以找到聊天记录

按照时间排序:

image-20240510091425192

image-20240510091534641

B

4. [填空题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question
死者在「Facebook Messenger」应用程序中最后联系人的使用者的名字?
What is the user name of someone whom the Deceased last contacted in the app of “Facebook Messenger”?
提示:请用简体中文填写答案。
Please anser the question in Chinese
(2分)

思路1:

image-20240510091721301

blk0_sda.bin/分区24/data/com.facebook.orca/databases

导出msys_database_100095371293642

image-20240510092009632

sender_id为100092463798036

image-20240510092338928

定位到contacts表中对应id的用户名为杨漫漫

思路2:

image-20240510092429663

杨漫漫

5. [单选题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question
死者曾经用「Fitbit」应用程序记录一次跑步的数据,该次跑步是由何时开始?
What time of the Deceased started a run which recorded by the app of “Fitbit”?
(1分)
A.2023-09-13 12:36
B.2023-09-13 12:37
C.2023-09-13 12:38
D.2023-09-13 12:39
E.2023-09-13 12:40

image-20240510092453267

blk0_sda.bin/分区24/data/com.fitbit.FitbitMobile/databases

image-20240510092623314

image-20240510092934185

image-20240510092945770

B

6. [单选题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question
死者除曾经用「Fitbit」应用程序记录一次跑步的数据外,他也用哪一个应用程序记录同一次跑步?
Which of the following APPs used to record the same run? (1分)
A.My Run Tracker
B.FITAPP
C.Fitnesskeeper
D.Nike Run Club
E.Runkeeper

在应用列表中搜索选项给出的运动应用软件找到了com.fitnesskeeper.runkeeper.pro和Nike Run Club

在/data/com.fitnesskeeper.runkeeper.pro/databases/RunKeeper.sqlite的trips表中找到一次跑步记录,开始时间几乎吻合(两个软件的秒数不同是合理误差)

image-20240510093853610

image-20240510094032992

image-20240510094013811

E

7. [单选题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question

死者跑步起点的经纬度是多少?
What is the longitude and latitude of the starting point of the run?
(1分)
A.114.16869, 22.282452
B.114.16851, 22.281998
C.114.16847, 22.28182
D.114.16773, 22.280827
E.114.16867, 22.280434

image-20240510094056596

E

8. [填空题]参考 ' blk0_sda.bin ' 回答以下题目

With reference to ' blk0_sda' to answer below question
无人机卖家的电话号码是多少?
What is the telephone number of the drone seller?
提示: 答案包括没有任何空格的国际电话代码,例如0085261231234
Tips: The answer should include the International Calling Code without any space, i.e. 0085261231234)
(2分)

image-20240510094236364

image-20240510094326605

0085257352259

9. [填空题]参考李佩妍的手机镜像回答以下题目

With reference to Peggy's mobile phone image to answer below question
李佩妍在Facebook 建立了一个群组, 该群组的名称是什么?
Peggy created a group on Facebook. What is the name of the group?
提示:请用大写英文作答, 不用留空白
Tips: Please answer the question in capital letters, leave no spaces
(1分)

image-20240510094639724

image-20240510094611899

image-20240510094710050

跳转到源文件,定位数据库

image-20240510095135713

10. [单选题]参考李佩妍的手机镜像回答以下题目

With reference to Peggy's mobile phone image to answer below question
李佩妍第一次用计算机登入Facebook帐户的日期和时间?
What day and time did Peggy first log in to her Facebook account using a computer?
(2分)
A.2023-07-26 14:37:40
B.2023-09-06 18:32:07
C.2023-07-26 06:34:40
D.2023-09-06 18:34:09

image-20240510095734339

1693996327

image-20240510095802166

B

11. [填空题]题目内容请看题目描述。(11) (2分)

参考李佩妍的手机镜像回答以下题目
With reference to Peggy's mobile phone image to answer below question
李佩妍在2023年9月3日曾经操作航拍机,请问起飞地点的经纬度是多少? 
On September 3, 2023, Li Peiyan operated a drone. What are the latitude and longitude coordinates of the takeoff location?
提示: 以经纬度坐标回答有关答案,答案如 Lat: 22.2846135, Lon: 114.1739116,请用以下格式作答,22.2846135,114.1739116。
For example: Lat: 22.2846135, Lon: 114.1739116, please answer 22.2846135,114.1739116.

image-20240510095959297

image-20240510100058030

image-20240510100212197

找到FlightRecords,

1.用物联网分析工具

2.大疆记录读取工具csvview

3.用网站:https://app.airdata.com/

分析网站解析飞行记录

image-20240510103340971

image-20240510103527273

22.3565578,114.0939622

12. [多选题]参考李哲图的手机镜像回答以下题目

With reference to Chris' mobile phone image to answer below question
李哲图手机内安装了什么恶意软件?
What malicious program packages are installed on Chris's mobile phone?
(1分)
A.com.instagram.android
B.com.whatsapp
C.org.telegram.messenger
D.com.xiaomi.smarthome
E.com.metasploit.stage
F.com.taobao.taobao
G.com.cad_epuas_reactnative

image-20240510103916846

在李哲图手机中的自带浏览器下载记录中可以看到其在http://218.255.242.114这个网站下载了三个apk,极有可能是犯罪分子搭建的虚假的下载平台,用于下载恶意软件

安装这两个

image-20240510104754677

image-20240510104815262

EG

13. [填空题]参考李哲图的手机镜像回答以下题目

With reference to Chris' mobile phone image to answer below question
李哲图手机内package “com.cad_epuas_reactnative”的app 名是什么?
What is the app name of the the package "com.cad_epuas_reactnative" installed on Chris's mobile phone in Hong Kong.
提示: 请以中文和全英文大写填写答案
Tips: Please answer in Chinese and English
(1分)

jadx反编译搜app_name

image-20240510105814465

SUA一站通

14. [单选题]参考李哲图的手机镜像回答以下题目

With reference to Chris' mobile phone image to answer below question
“com.cad_epuas_reactnative”拆包后, 内有哪一个“类(class)”能找到黑客IP有关的线索?
After decompiling "com.cad_epuas_reactnative", which class can find clues related to hacker IP?
(2分)
A.Nhnov
B.Olyg
C.Ywnvt
D.MainActivity

image-20240510110031303

参考:

img

C

15. [填空题]参考李佩妍的计算机镜像回答以下题目

With reference to Peggy's computer image to answer below question
李哲图计算机的外部IP是多少?
What is the external IP of Chris's computer?
提示: 用IPV4格式回答
Hint: Combine the IP address into a single answer. For example, if the IP address is 123.123.123.123, the answer should be 123123123123.
(1分)

发现桌面有AnyDesk图标

image-20240510111457078

仿真后打开AnyDesk查看最近的连接记录

image-20240510140242957

到/Windows/Users/Peggy Li/AppData/Roaming/AnyDesk/ad.trace记录文件中搜索关键词

image-20240510141458251

59.152.211.13

16. [填空题]参考李佩妍的计算机镜像回答以下题目

With reference to Peggy's computer image to answer below question
李佩妍计算机内的Kali虚拟机时区是多少?
What is the time zone of the Kali virtual machine on Peggy's computer?
提示: 不要输入符号及空白,以全大写英文回答
Tips: Answer in uppercase English without symbols or spaces
(1分)

虚拟机里不能打开虚拟机

尝试了用火眼导出该镜像,时间太长了;挂载为新检材,卡在了自动识别证据类型

虚拟机磁盘文件在/Windows/Program Files/Oracle/Peggy Li/kali-linux-2023.3-virtualbox-amd64.vdi

使用ufs挂载又快又简单

image-20240510142753506

直接搜索timezone,就能看到

*17. [填空题]参考李哲图的计算机镜像回答以下题目

With reference to Chirs's computer image to answer below question
在李哲图的计算机上,有一个文件内藏有木马病毒,请问该文件的名称是什么?
On Chris's computer, there is a file containing a Trojan virus. What is the name of the file?
提示: 以全大写英文字母回答,不包含符号或空格,例如, "ABC.TXT"
Tips: Answer in uppercase English without symbols or spaces. For example ABC.TXT
(1分)

在李佩妍的kali虚拟机中可以看到曾经使用过PowerShell Empire和Metasploit

image-20240510150630352

/var/lib/powershell-empire/是与PowerShell Empire入侵有关的目录,在这个目录翻找

image-20240510152113906

在/var/lib/powershell-empire/server/downloads/8LDZVBKP目录中可以找到,李佩妍获取了李哲图的电脑截图,其中显示在音乐文件夹下有一个goal.doc文件

image-20240510152129591

image-20240510164959943

image-20240510170003468

goal.doc

18. [填空题]题目内容请看题目描述。(18) (1分)

参考李佩妍的计算机镜像回答以下题目
With reference to Peggy's computer image to answer below question
在2023-09-26 10:00 (UTC+8)至 2023-09-26 11:00 (UTC+8)时间内, 李佩妍在李哲图的计算机下载了一个文件,请问文件名是什么?
From 2023-09-26 10:00 (UTC+8) to 2023-09-26 11:00 (UTC+8), Peggy downloaded a file on Chris's computer. What is the name of the file?
提示: 不要输入符号及空白,以大写英文回答。如,ABC.TXT
Tips:  Answer in uppercase English without symbols or spaces. For example,ABC.TXT

查看powershell-empire后门的客户端日志文件/var/lib/powershell-empire/empire/client/downloads/logs/empire_client.log

image-20240510144050184

在2023-09-25 22:05:52从李哲图电脑下载了BHB record by David.xls文件

前面提到在李佩妍的kali中时区为US/Eastern也就是美国东部时间,9月处于夏令时,为UTC-4,所以换算成北京时间需要+12小时,也就是2023-09-05 10:05:52从李哲图的电脑下载了BHB record by David.xls

19. [填空题]题目内容请看题目描述。(19) (1分)

参考李佩妍的计算机镜像回答以下题目
With reference to Peggy's computer image to answer below question
在2023-09-26 11:22 (UTC+8)时间, 李哲图当时所在地方的经纬度是多少?
On 2023-09-26 at 11:22 (UTC+8), where was Chris located?
提示: 将经纬度合并回答。如 22.2846135(Latitude) 114.1739116(Longitude),需回答 22.2846135,114.1739116
Tips: Combine the latitude and longitude coordinates. For example, if the latitude is 22.2846135 and the longitude is 114.1739116, the answer should be  22.2846135,114.1739116.

msf的历史记录/root/.msf4/history

image-20240510153023726

曾经监听过一个Android的反向tcp连接

在/root/.msf4/logs/sessions目录找到两个会话的日志,日志中记录了被植入后门的设备的经纬度

image-20240510153137534

Latitude: 22.280348572601053

Longitude: 114.16910499580993

20. [填空题]参考陈好计算机的镜像回答以下题

With reference to Leo's computer to answer below question
从目标服务器窃取数据要执行哪一个文件?(包括文件名的扩展名)
What is the file to be executed for stealing the data from a targeted server? (Including the file extension))
提示: 以大写英文字母回答,如,ABC.TXT
Tips: Answer in uppercase English For example,ABC.TXT
(1分)

image-20240510164959943

李哲图pc上的文件反推的,木马word文档同路径下还有个启动server的python文件

推测陈好的计算机是用python控制窃取数据

/Windows/Users/Ho328/AppData/Local/Programs/Python/Python311 目录下安装了 Python. 在最近访问的项目中可以看到近期访问过 Python311 文件夹及其中的 Scripts 文件夹.

image-20240510172235962

跳转对应目录:

image-20240510172356040

在result里发现大量被窃取的信息,文件名为extracted_customer_data.txt

全局搜索这个关键字

image-20240510173614243

main.py

21. [填空题]参考陈好计算机的镜像回答以下题目

With reference to Leo's computer to answer below question
用在执行「从目标服务器窃取数据要执行的文件」的软件是什么?(包括文件扩展名)"
What is the software used to execute the file? (including the file extension)
提示: 以大写英文字母回答, ABC.TXT
Tips: Answer in uppercase English. For example, ABC.TXT
(1分)

9月18日的时间线里,有多次启动IDLE的记录

img

由于前面一直用的IDLE,所以执行的软件应该是IDLE,而这个程序指向的实际上是idle.pyw,会调用pythonw.exe来执行

结果为PTYTHONW.EXE

PTYTHONW.EXE

*22. [填空题]参考陈好计算机的镜像回答以下题目

With reference to Leo's computer to answer below question
存储该「从目标服务器窃取数据要执行的文件」的原始路径是什么?
What is the original path of the file stored?
提示:以大写英文字母与以下格式填写答案
Please answer in uppercase English and answer as below format
(例如: \USERS\HO328\APPDATA\LOCAL\PROGRAMS\TESTING.TXT)
(2分)

\USERS\HO328\DESKTOP\MAIN.PY

23. [多选题]参考陈好计算机的镜像回答以下题目

With reference to Leo's computer to answer below question
执行该「从目标服务器窃取数据要执行的文件」后将创建哪些文件?(包括文件扩展名)
What file(s) will be created after the execution of the file? (including the file extension)
(1分)
A.extracted_customer_data.txt
B.data.txt
C.pair_device_result.txt
D.driver-signature.txt

with open("extracted_customer_data.txt", "a") as file:
	file.write(f"{id} ,{aa} \n")
	print({aa})
with open("pair_device_result.txt", "a") as file:
	file.write(f"{id} ,{profileid} ,{token}\n")

结果为extracted_customer_data.txtpair_device_result.txt

AC

24. [填空题]参考陈好计算机的镜像回答以下题目

With reference to Leo's computer to answer below question
目标服务器的IP地址及服务器的端口是多少?
what is the IP address and the port number of the target server?
提示: 将IP地址及服务器的端口合并回答。如 123.123.123.123:80。
Tips: Combine the IP address and the port number into a single answer. For example, 123.123.123.123:80.
(1分)

def get_customer_profile(token,token2):
    headers = {
        "Accept": "*/*",
        "Boss-Client-Token": token2,
        "Boss-User-Token": token,
        "User-Agent": "okhttp/4.9.3",
        "Host": "api.boss.abc.com",
        "Connection": "Keep-Alive",
        "Accept-Encoding": "gzip",
    }
    url = "http://59.152.211.13:5000/frontend/customer/profile"
    
    response = requests.get(url, headers=headers)

    json_obj = json.loads(response.text)
    
    aa=get_customer_info(json_obj,token)

    print(aa)
    with open("extracted_customer_data.txt", "a") as file:
        file.write(f"{id} ,{aa} \n")
        print({aa})
    
    
    return

59.152.211.13:5000

25. [单选题]参考陈好计算机的镜像回答以下题目

With reference to Chan Ho's computer to answer below question
通过执行"李佩妍在李哲图的计算机下载的文件"成功窃取了以下哪些数据?
Which following data were successfully stolen by executing the above file?
i) current_ui_customer_description
ii) email
iii) token
iv) customer_stage
(1分)
A.i, ii, iii
B.ii,iii,iv
C.i, ii, iv
D.i, iii, iv
E.i, ii, iii, iv

看看脚本内容,全都给拿了

def get_customer_info(json_str,token):   
    try:
        id_value =""
        customer_dict =  json_str['customer']
        print(customer_dict)
        current_ui_customer_description = customer_dict['plan']
        vip = customer_dict['vip']
        status = customer_dict['status']
        email = customer_dict['email']
        customer_stage = customer_dict['customer_stage']
        sales_channel = customer_dict['sales_channel']
        remarks = customer_dict['remarks']
        id_value = customer_dict['id_value']

E

26. [填空题]参考陈好计算机的镜像回答以下题目

With reference to Chan Ho's computer to answer below question
有多少条客户信息被盗取?(包括首尾项目)
How many entries of the customer information have been stolen? (included both numbers)
提示:请以阿拉伯数字作答
Tips:Please answer in arabic number (1分)

image-20240510175400127

1000

27. [填空题]参考'TeslaCam.e01'回答以下题目

With reference to TeslaCam.e01 to answer below question
当哨兵模式运作时,共有多少个镜头将会进行记录?(第三方安装的电子狗不计在内)
How many cameras on the car will be operated during the sentry mode enabled? (3rd party camera not included)
提示:请以阿拉伯数字作答
Tips:Please answer in arabic number (1分)

image-20240510193215564

4

28. [填空题]参考"https://www.tesla.com/support/videos/watch/live-camera"回答以下题目

With reference to https://www.tesla.com/support/videos/watch/live-camera to answer below question
当车主利用手机查阅车辆实时影像时共有多少个镜头正在运作以供查阅?
How many cameras will be on when we are browsing the Live camera?
提示:请以阿拉伯数字作答
Tips:Please answer in arabic number (1分)

???????

29. [单选题]参考'TeslaCam.e01'回答以下题目

With reference to TeslaCam.e01 to answer below question
当哨兵模式运作时,系统会自动记录多长时间的影像?
How long will the video be taken when suspicious activity was found around the vehicle under the sentry mode enabled? (2分)
A.5 分钟
B.7 分钟
C.10分钟
D.15分钟
E.20分钟

在目录 \TeslaCam\SavedClips\2023-09-30_16-53-06\ 中查看即可.

image-20240510194239939

C

*30. [填空题]参考'TeslaCam.e01'回答以下题目

With reference to TeslaCam.e01 to answer below question
在2023年10月2日上午11时51分,到底发出了什么事件令哨兵模式被触发?
At around 1151 hrs on 2023-10-02, the sentry mode of the car was alerted. What is the reason to explain the alarm enabled?
请用小写英文字母与以下格式作答
xxx_xxx_xxx_xxx (2分)

镜像损失

*31. [单选题]参考'TeslaCam.e01'回答以下题目

With reference to TeslaCam.e01 to answer below question
男死者李哲图死在9月末,但是其车辆的哨兵模式在2023年10月02日的上午被启动,从Sentry Clips Folder内找出有关片段,确认有什么事件引发录制。
At late Septeber, the deceased was dead. However, the alarm was enabled at the morning on 2023-10-02. Please find out the cause in the clip at Sentry Clips Folder. (3分)
A.有车辆从前方驶过
B.有动物从前方走过
C.有人从前方走过
D.有人从后方走过
E.有车辆从后方驶过

*32. [填空题]题目内容请看题目描述。(32) (3分)

参考'TeslaCam.e01'回答以下题目
With reference to TeslaCam.e01 to answer below question
按照Sentry Clips 内 '2023-10-02_11-51-40'的活页夹,请找出男死者李哲图私家车当日的停泊位置。
Based on the sentry clips on the folder "2023-10-02_11-51-40", Can you tell me the location of the car parking?
提示: 以经纬度坐标回答有关答案,答案如 Lat: 22.2846135, Lon: 114.1739116,请用以下格式作答,22.2846135,114.1739116。
For example: Lat: 22.2846135, Lon: 114.1739116, please answer 22.2846135,114.1739116.

33. [单选题]参考'TeslaCam.e01'回答以下题目

With reference to TeslaCam.e01 to answer below question
在'event.json'文件,我们发现有一栏显示为"Camera:6",这是什么意思?
When we take a look on the event.json file from the TeslaCam.e01, we can see the row "camera:6". What is the meaning of 6?
提示: 请浏览特斯拉有关的网站或讨论区。
Tips: Please conduct an online chechking from Tesla's website or Tesla Forum. (3分)
A.前镜头
B.后镜头
C.右边镜头
D.左边镜头

D

34. [填空题]题目内容请看题目描述。(34) (3分)

参考'TeslaCam.e01'回答以下题目
With reference to TeslaCam.e01 to answer below question
有人曾驾驶男死者李哲图的车辆前往香港迪斯尼乐园,期间有车辆从男死者的车辆后方驶走,请找出在"2023-09-30_alerted"照片中有关车牌号码?
In between 1518 hrs and 1528 hrs on 2023-09-30, the car was parked at Disneyland and a car was driving out from the parking park. Please find out the photos "2023-09-30_alerted" and tried to find out the Car Plate Number of the car. 
请以大写英文与以下格式作答XX_XXX 
Please answer in below format XX_XX,如:AB_123

image-20240510194815502

image-20240510194900087

JV_820

35. [单选题]参考'dji.go.v5'回答以下题目

With reference to dji.go.v5 to answer below question
按照WhatsApp聊天记录,得知Chris曾与Peggy在2023年09月07日外出玩无人机。飞行记录"DJIFlightRecord_2023-09-07_[17-33-52]"的文件路径?
Based on the WhatsApp Conversation Records, we known that Chris dated Peggy to go play drone on 2023-09-07. What is the file path of Flight Log Record "DJIFlightRecord_2023-09-07_[17-33-52]"? (1分)
A.DCIM\media\1\Android\data\dji.go.v5\files\FlightRecord
B.\media\0\Android\data\dji.go.v4\files\FlightRecord
C.\media\0\Android\data\dji.go.v5\files\FlightRecord
D.\media\0\Android\dji.go.v5\files\FlightRecord

飞行记录位于李哲图的安卓手机内. 与无人机检材中的 dji.go.v5\files\FlightRecord 一致.

image-20240510200155414

C

36. [填空题]参考'dji.go.v5'回答以下题目

With reference to dji.go.v5 to answer below question
在李哲图的LG手机内2023年10月7日内有多少次飞行记录?
How manyt flight record you can find from Chris's mobile phone on 2023-09-07?
提示:请用阿拉伯数字作答
Tips: Please answer in arabic number
(2分)

image-20240510200525566

$

37. [多选题]参考'dji.go.v5'回答以下题目

With reference to dji.go.v5 to answer below question
尝试找出與原点最远的距离,并从日志文件中找出所有有关区域的经纬度坐标。
Try to find out the exact longest distance from Home point and named the location of this area.
(3分)
A.3,064.3 ft
B.3,100.1 ft
C.3,201.6 ft
D.Lat: 22.2855113649764, Lon: 114.111954829708
E.Lat: 22.2855161086729, Lon: 114.111957385297
F.Lat: 22.2855211183398, Lon: 114.111960153012

思路1:

在线工具https://app.airdata.com/main?a=upload

image-20240510200744133

image-20240510200837738

image-20240510201002068

image-20240510201059904

思路2:

在线工具 https://www.phantomhelp.com/LogViewer 来处理 v5 版本的 txt log 文件

DJIFlightRecord_2023-09-07_[17-42-32].txt中的飞行记录到达了距离起点最远的位置, 为 3064.3 ft.

image-20240510201634325

导出 csv 后可以看到经纬度信息

导出后对应位置为这三

image-20240510203303810

ADEF

38. [填空题]参考'dji.go.v5'回答以下题目

With reference to dji.go.v5 to answer below question
在2023年09月07日,Chirs和Peggy曾经外出玩无人机, 并用无人机拍摄一张照片"dji_fly_20230907_172136_63_1694078794485_photo_optimized.jpg", 请问拍摄照片时,无人机的高度值是多少?
Chris dated Peggy to go play drone on 2023-09-07 and taken a photo "dji_fly_20230907_172136_63_1694078794485_photo_optimized.jpg". What is the attitude of the drone when they take the photo? (2分)

照片在手机里,有文件名就过滤

image-20240510203456090

116.781

39. [填空题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to Leo's computer to answer below question
陈好用了云端运算来构建钓鱼网站,这网站的IP 地址是多少?
Chan Ho used the cloud computing to build a plishing website. What is the IP address of this website?
提示: 以IPV4 格式回答,如123.123.123.123
Answer: Please answer in IPV4 format.
(1分)

在 Edge 的历史记录中可以看到登陆了 Azure 云服务.

image-20240510203923143

在最新的历史记录中可以看到备份存储盘的操作.

image-20240510204053380

在历史记录中还可以看到多次访问一个 IP 地址的 URL, 并且网站标题与虚拟货币有关. 访问的资源包括 creditcard.php 并且曾被识别为"不安全的页面". 推测为陈好测试自己搭建的钓鱼网站.

image-20240510204151588

可以在 Downloads 文件夹中找到 abcd 文件, 为 Azure 云服务的硬盘镜像, 可作为新检材直接挂载.

20.187.91.234

40. [填空题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to Leo's computer to answer below question
陈好在云端运算建立了linux 的系统,请问这系统的使用者ID 是什么?
Chan Ho used a Linux operating system on cloud computing. What is the user ID for this system?
提示:请全部用英文小写作答,例子:tommychan
(1分)

把abcd挂载

image-20240510204429036

image-20240510204755498

foradmin

41. [多选题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to Leo's computer to answer below question
在2023年8月25日至2023年9月05日期间,下列哪些IP地址成功登录云端运算?
Between 25th August 2023 and 5th September 2023, which of the following IP addresses successfully logged into cloud computing?
(2分)
A.203.198.117.194
B.203.181.6.82
C.210.3.89.98
D.61.92.200.176
E.201.198.115.194

image-20240510204944138

ACD

42. [填空题]题目内容请看题目描述。(42) (2分)

参考 '陈好的计算机镜像 ' 回答以下题目
With reference to Leo's computer to answer below question
在2023年9月10日至2023年9月16日期间,哪个IP地址透过SSH 连接,不断密码攻击陈好所使用的云端计算的linux系统? (只计最高值)
Between 10th September, 2023 and 16th September, 2023, which IP address continuously attempted SSH connections, launching password attacks against Chan Ho's Linux system that built on the cloud computing? (Considering the highest frequency)
提示: 以 IPV4 格式回答
Answer: Please answer in IPV4 format.

image-20240510205345825

登录失败的地方查询不到

ssh认证日志,已经归档的/var/log/auth.log.2.gz,比一下

image-20240510205534464

结果为170.64.177.67

170.64.177.67

43. [单选题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to Leo's computer to answer below question
陈好所用的云端运算,所用的linux系统,内有安装Mysql, 请问哪个是他的密码?
There was MYSQL installed in the Linux system on the cloud computing. What is the password he is using?
(2分)
A.qwert!@34
B.4rfv%TGB6yhn
C.3edc%TGB7ujm
D.1qaz@WSX3edc
E.2wsx$RFV6yhn

image-20240514083732819

D

44. [单选题]参考 ' Meiya_StaffB_laptop.e01 ' 回答以下题目

With reference to 'Meiya_StaffB_laptop.e01' to answer below question?
陈好所使用的手机中,用了云端运算来构建钓鱼网站,这网站的主题是什么?
In Chan Ho's mobile mobile phone, he used cloud computing to build a phishing website. What is the theme of this website?
(1分)
A.征友
B.股票投资
C.购物网
D.求职网
E.加密货币投资

image-20240514084006703

这个网站模仿网飞

image-20240514084215491

模仿虚拟货币交易平台

E

45. [填空题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to Leo's computer to answr below question
陈好在云端运算上用的Linux系统, 请问这个镜像文件的主文件名?
What is the forensic image name of the linux system used on cloud computing?
提示:请用大写字母与阿拉伯数字作答,并不需要扩展名
Tips: Please answer in capital letters and arabic numbers, and no need to fill in the file extension.
(1分)

abcd

46. [填空题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to Leo's computer to answr below question
陈好构建的钓鱼网站最终偷取了多少位客户的密码?
How many customers' password did Chan Ho phishing website steal?
请以阿拉数字作答
Tips: Please answer in arabic number (3分)

对 Azure 云镜像中的mysql数据库进行重建

image-20240514084837659

24

47. [单选题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to 'Meiya_StaffB_laptop.e01' to answer below question?
陈好用了"MAMP"的程序在本地主机测试构建的钓鱼网站,请问他测试时用了哪个网络服务器和用了什么通讯端口?
Chan Ho used the "MAMP" program to test the phishing website that he built on his local host. What web server and port did he use for testing?
(2分)
A.Nginx, 通讯端口是7888
B.Nginx, 通讯端口是8888
C..Apache, 通讯端口是7888
D..Apache, 通讯端口是8888

陈好计算机中的 MAMP 位于 /Windows/MAMP/ 目录下. 在 logs 文件夹中可以看到 apache_error.logaccess.log 文件.

image-20240514085607685

查看 conf 目录中的 apache/httpd.conf 可以看到 apache 监听的端口为 8888.

image-20240514090445002

这个没有

image-20240514090305486

这个有8888

通过查看 conf 目录中的 nginx/nginx.conf 也可以注意到, nginx 的配置文件中开启了 log, 并且储存在 C:/MAMP/logs/nginx_access.log 中. 由此也可以判断 MAMP 未开启 nginx 组件.

image-20240514090541800

D

48. [填空题]参考 ' 陈好的计算机镜像 ' 回答以下题目

With reference to Leo's computer to answer below question
陈好构建的钓鱼网站,最终成功盗取了几张信用卡的资料?
How many customers' credit card data did Chan Ho phishing website steal?
提示:请用阿拉伯数字作答
Tips: Please answer in arabic number (3分)

Azure 云中的 mysql 数据库中存储信用卡数据的表 creditcard 已被清空.

image-20240514090642947

历史命令里面有相关操作

image-20240514090716858

/home/foradmin/tmp/dump.sql

去该目录找到备份的sql文件

image-20240514090958597

25

49. [填空题]题目内容请看题目描述。(49) (1分)

参考' 陈好的计算机镜像 ' 回答以下题目
With reference to Leo's computer to answer below question
陈好所用的云端运算中,内装有Microsoft Azure Linux VM 代理程序,这个程序的功能包含配置,资源扩展,通信,安全性,诊断数据等等,请问个程序的名字是什么?
There is a program called the "Microsoft Azure Linux VM Agent." in Chan Ho's cloud computing.  This program has various functions, like setting, expanding resources, communication, security, and diagnostic. What is the name of this program?

image-20240514091216949

image-20240514091252095

waagent

50. [单选题]题目内容请看题目描述。(50) (2分)

A.i),ii),iii)
B.i),iii),iv)
C.ii),iii),iv)
D.i),ii),iv)
E.i),ii),iii),iv)
参考  ' 陈好的计算机镜像 '  回答以下题目
With reference to Leo's computer to answer below question
陈好所用的云端运算,以下描述是正确的:
i) 订用账户标识符: 99b1a232-105e-4852-afds-54a74f75668
ii) 虚拟机的计算机名称: Netinvestment
iii) 资源组名: Netinvestmentmeiya_group
iv) 公钥:

AAAAB3NzaC1yc2EAAAADAQABAAABgQDS/GbG00y/3DbUI0Q8MrrsvcGTKOad3hYRgApBWlALq48y9bHHmM3DaxM460cnAfz5aDMfVghyX+sevI7PP0UwhevgVUVJ5NZyc98Yi0XDEcPF9nxQOBp49yzwBpy/KwCbMJxBvLNuEtazw+TU6k6bXn62g42f1ljyWZP3vbMGmYnJUjpTE0uhXTqr8PYDKVZrEQWpB2v53IegCXI4La2rScJNKmAIo9pXvdyJkDda74k1vKPj7zUMCsUbpVN/CwZUAZazARyILbz7GK/PvsRp/jWmyo2gbhxk6SoyvRYT8uDK3ifeHcg89jlM6qXS4tGBu2JH+fY/G6WVUJFBjrU9/yyI+i9g9mr+zq5e4D1fWZ/TpLK3RK5JMFUf/L+qQRLoysY6APHZ+WrmM5dJsLgIC9PUmdM3arQGLM6KHQ0+R03phHaK+lo+5QDyVIktJ4wMMfhFSaR6ozHjCzzh8h0Ka+eV6aken1XVs0wIvHYokweRx3W//+N3ZvF9q7cmNuE= generated-by-azure

Which descriptions are correct for the cloud computing used by Chan Ho :
i) Subscription ID: 99b1a232-105e-4852-afds-54a74f75668
ii) Virtual Machine Computer Name: Netinvestment
iii) Resource Group: Netinvestmentmeiya_group
iv) SSH RSA:

AAAAB3NzaC1yc2EAAAADAQABAAABgQDS/GbG00y/3DbUI0Q8MrrsvcGTKOad3hYRgApBWlALq48y9bHHmM3DaxM460cnAfz5aDMfVghyX+sevI7PP0UwhevgVUVJ5NZyc98Yi0XDEcPF9nxQOBp49yzwBpy/KwCbMJxBvLNuEtazw+TU6k6bXn62g42f1ljyWZP3vbMGmYnJUjpTE0uhXTqr8PYDKVZrEQWpB2v53IegCXI4La2rScJNKmAIo9pXvdyJkDda74k1vKPj7zUMCsUbpVN/CwZUAZazARyILbz7GK/PvsRp/jWmyo2gbhxk6SoyvRYT8uDK3ifeHcg89jlM6qXS4tGBu2JH+fY/G6WVUJFBjrU9/yyI+i9g9mr+zq5e4D1fWZ/TpLK3RK5JMFUf/L+qQRLoysY6APHZ+WrmM5dJsLgIC9PUmdM3arQGLM6KHQ0+R03phHaK+lo+5QDyVIktJ4wMMfhFSaR6ozHjCzzh8h0Ka+eV6aken1XVs0wIvHYokweRx3W//+N3ZvF9q7cmNuE= generated-by-azure

计算机名称存储在 /etc/hostname

image-20240514091710773
Netinvestment

公钥存储在 /root/.ssh/authorized_keys

image-20240514092108360

AAAAB3NzaC1yc2EAAAADAQABAAABgQDS/GbG00y/3DbUI0Q8MrrsvcGTKOad3hYRgApBWlALq48y9bHHmM3DaxM460cnAfz5aDMfVghyX+sevI7PP0UwhevgVUVJ5NZyc98Yi0XDEcPF9nxQOBp49yzwBpy/KwCbMJxBvLNuEtazw+TU6k6bXn62g42f1ljyWZP3vbMGmYnJUjpTE0uhXTqr8PYDKVZrEQWpB2v53IegCXI4La2rScJNKmAIo9pXvdyJkDda74k1vKPj7zUMCsUbpVN/CwZUAZazARyILbz7GK/PvsRp/jWmyo2gbhxk6SoyvRYT8uDK3ifeHcg89jlM6qXS4tGBu2JH+fY/G6WVUJFBjrU9/yyI+i9g9mr+zq5e4D1fWZ/TpLK3RK5JMFUf/L+qQRLoysY6APHZ+WrmM5dJsLgIC9PUmdM3arQGLM6KHQ0+R03phHaK+lo+5QDyVIktJ4wMMfhFSaR6ozHjCzzh8h0Ka+eV6aken1XVs0wIvHYokweRx3W//+N3ZvF9q7cmNuE= generated-by-azure

i) 和 iii) 均与 Azure 云相关, 猜测可能与先前问到过的 WaAgent 监控服务有关.

/var/lib/waagent/Microsoft.Azure.Diagnostics.LinuxDiagnostic-3.0.141/config/ 目录下可以找到 WaAgent 的配置文件, 部分内容如下:

image-20240514092748078

ID为98b1a343-105e-4972-afba-540b74f75f68

C

51. [单选题]请参考陈大昆MacBook镜像文件回答以下题目:

这台MacBook创建了多少个访客账户? (1分)
A.0
B.1
C.2
D.3

/Library/Preferences/com.apple.loginwindow.plist 中可以看到访客用户已关闭, 且用户列表中不存在 Guest 用户.'

image-20240514093332817

A

52. [填空题]请参考陈大昆MacBook镜像文件回答以下题目:

这MacBook的用户名称是什么?
(名称包括所有英文字母、数字和符号,区分大小写,不需要空格) (1分)

image-20240514093510792

BEN

53. [单选题]请参考陈大昆MacBook镜像文件回答以下题目:

这台MacBook中曾连接了多少个WIFI(WIFI SSID)? (1分)
A.1
B.2
C.3
D.4

image-20240514093540643

C

54. [单选题]参考 ' 陈大昆的计算机镜像 ' 回答以下题目

With reference to Ben's computer to answer below question
在这个取证镜像文件中有多少用户配置文件具有浏览历史?
How many setup document in the website browser was found (1分)
A.1
B.2
C.3
D.4

How many setup document in the website browser was found

从Safari浏览器查看

image-20240514093912197

A

55. [填空题]请参考陈大昆MacBook镜像文件回答以下题目:

请提供以下文件的内容:“f.rtf”、“a.rtf”、“f1.txt” 和 “a1.txt”。
(填写文件内容所有英文字母、数字和符号,区分大小写,不需要空格)
请按照以下格式回答: xxx_xxx_xxx_xxx
例子:如(1)的内容是abc,(2)的内容是123,(3)的内容是DEF,(4)的内容是8.8
请填写: abc_123_DEF_8.8
(2分)

在 shell 历史中可以看到 zsh 的部分与题目中提及的文件相关的指令:

image-20240514094211007

image-20240514094336638

结果会生成:

  • key-a.txt: 内容为 Base64("f.rtf")
  • key-b.txt: 内容为 Base64("a.rtf")
  • key-c.txt: 内容为 Base64(Content(f1.rtf))
  • key-d.txt: 内容为 Base64(Content(a1.rtf))

image-20240514094525026

分别用base64解密后

f.rtf_a.rtf_funnystuff_autogpt

56. [填空题]请参考陈大昆MacBook镜像文件回答以下题目:

有两个加密的 .dmg 文件在取证镜像文件内。按照.dmg 文件的创建时间先后,请填写下面的空白:文件名称包括扩展名(如adcd.dmg)第一个创建 .dmg 文件的名称是:,密码是:____
第二个创建 .dmg 文件的名称是:
,密码是:____
请按照以下格式回答: xxx_xxx_xxx_xxx,例子: 如(1)的内容是abc、(2)的内容是123、(3)的内容是DEF、(4)的内容是8.8,答案为:abc_123_DEF_8.8 (2分)

在 shell 历史中搜索 .dmg 可以找到 2 条指令:

image-20240514095955719

hdiutil create -encryption -stdinpass -fs ExFAT -volname funnystuff -o funnystuff.dmg -size 100M
hdiutil create -encryption -stdinpass -fs ExFAT -volname auto -o auto.dmg -size 256M

文件位置在 /Users/ben/Image 目录中

image-20240514100101795

dmg 文件解密

hdiutil 是 MacOS 提供的用于创建磁盘镜像的工具

创建了名字分别为 funnystuffauto 的带有加密的虚拟磁盘, 密码通过 stdin 输入..

这两个虚拟磁盘可以在 /Users/ben/Images/Users/ben/.Image目录中找到.

.zsh_history 中稍后的位置可以看到以下内容:

textutil -convert txt -stdout f1.rtf | base64 > key-c.txt
textutil -convert txt -stdout a1.rtf | base64 > key-d.txt

读取了文件 f1.rtf 的内容, 并 Base64 编码之后输出到 key-c.txt 中.

根据输出文件名可以猜测, 文件内容为密钥(key); 根据原始文件名可以猜测, f1.rtf 中存储了 funnystaff 虚拟磁盘的密码. a1.rtfauto 虚拟磁盘同理.

key-c.txtkey-d.txt 位于 /Users/ben/Documents/ 目录下, 对内容进行解密即可得到虚拟硬盘的密码分别为 funnystuffautogpt

通过 hdiutil 创建的 dmg 文件可以通过以下方式解析:

检材中的磁盘镜像由于文件系统为 exFAT, 不能使用 hfs explorer. 以下使用 encryteddmg 为例.

python readencrcdsa.py -p funnystuff -s funnystuff.dmg
python readencrcdsa.py -p autogpt -s auto.dmg

image-20240514101705017

导出的 funnystuff-decrypted.dmg 可以使用镜像访问工具(X-ways, FTK Imager, Disk Genius, etc...)打开

image-20240514102819155

funnystuff.dmg_funnystuff_auto.dmg_autogpt

57. [填空题]请参考陈大昆MacBook镜像文件回答以下题目:

有一个应用程序托管在.dmg文件中,该程序需要一个密钥才能启用,请填写以下空格:
(文件名称包括所有英文字母、数字和符号,区分大小写,不需要空格)
存有密钥的文件名称是:________
密钥的值是:________
请按照以下格式回答: xxx_xxx,例子: 密钥文件名称是:abc.def,密钥的值是:123,答案为:abc.def_123 (2分)

auto.dmg里面:

image-20240514102140997

首先打开run.sh

image-20240514103651953

运行了 autogpt 目录下的 __main__.py, 部分内容如下:

image-20240514103727304

调用了 autogpt.app.cli.main() 的部分内容如下:

image-20240514104032194

可见是调用了run_auto_gpt()

继续跟进

image-20240514104222377

找到了配置文件位置!

image-20240514104503808

调用的run_auto_gpt()函数里,可以判断程序配置由工作路径加载, 即启动脚本所在的目录

image-20240514104327000

目录下的 .env 文件内容如下:

image-20240514104632524

.env_sk-Px1cCE5XZsXWYXij0K3BT3BlbkFJ4jVGVQ7eUpOmewvth1ep

58. [填空题]参考'陈大昆的计算机镜像' 回答以下题目

With reference to Ben's computer to answer below question
按照相关记录,该应用程序使用了哪个版本的引擎?
According to record, What enginee was used by the process? (2分)

/logs/activity.log 中存在关于模型版本的信息:

image-20240514111029122

gpt-3.5-turbo

59. [多选题]参考 ' 陈大昆的计算机镜像 ' 回答以下题目

With reference to Ben's computer to answer below question
按照您的检验,以下哪个陈述(或多个陈述)在描述路径“~/Desktop/.Spotlight-V100/”下的文件是正确的?
Accordning to your examination,which of the following statement (or statements) correctly describe the documents under the path “~/Desktop/.Spotlight-V100/” (3分)
A."coins1.jpg alias"是一个档案捷径(alias)
B."coins.jpg alias"和"coins1.jpg alias"都是符号链接(Symlink)文件
C."CryptoWallet-link1"是一个档案捷径(alias)
D."CryptoWallet-link1"和"CryptoWallet-link2"链接相同的文件
E."CryptoWallet-link2"是一个硬链接(Hard Link)

image-20240514112054135

CryptoWallet-link1CryptoWallet-link2哈希都相同,查看历史命令

image-20240514112142708

在 shell 中可以看到相关指令:

ln ~/Pictures/Crypto-Wallet.jpg CryptoWallet-link1
ln ~/Pictures/Crypto-Wallet.jpg CryptoWallet-link2
ln -s ~/Pictures/Crypto-Wallet.jpg CryptoWallet-link3
ln -s /Volumes/funnystuff/maya_quiz.7z CryptoWallet-link4

CryptoWallet-link1CryptoWallet-link2 为链接至相同文件的硬链接

符号链接即为软链接(CryptoWallet-link3 & CryptoWallet-link4)

coins.jpg alias 则类似于 windows 的快捷方式

image-20240514112440960

ADE

60. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
在换脸软件的“源视频转图片”程序中,不支持下列哪一类文件 ?
In the face exchange software, what file was not supported in the "source video exchange"? (1分)
A.data_src.flv
B.data_src.mpeg
C.data_scr.mp4
D.以上文件都可以支持

D

61. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
目标视频转换了多少张图片?
How many picture was changed to the target video ? (1分)
A.897
B.316
C.1794
D.1580

image-20240514140109850

316

62. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
已换脸的图片储存在哪个路径?
What path stored the face-exchanged picture ? (1分)
A.(省略) \workspace\data_src
B.(省略) \workspace\data_dst\merged_mask
C.(省略) \workspace\data_dst\merged
D.(省略) \workspace\data_dst\aligned

C

63. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
在这案件中,使用了哪个程序将图片换脸 ?
In this case, what process was used to change the face? (1分)
A.train AMP.bat
B.train SAEHD.bat
C.train Quick96.bat
D.train AMP SRC-SRC.bat

%WORKSPACE%/model/ 目录下的 *_SAEHD_summary.txt 中可以看到使用的模型为 DianPian_SAEHD4live_SAEHD.

image-20240514140435149

B

64. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
实时换脸软件可使用多少个模型?
How many models can the face exchange software use? (1分)
A.14
B.15
C.16
D.17

image-20240514140522923

C

65. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
实时换脸软件用了哪一个模型 ?
What model did the face exchange software use ? (1分)
A.Joker.dfm
B.Jackie_Chan.dfm
C.DianPian_SAEHD_model.dfm
D.4live_SAEHD_model.dfm

image-20240514140607029

D

66. [填空题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
在这案件中,换脸软件训练了哪些模型 ? (答案不用副文件名, 例如Jackie_Chan.dfm只需输入 Jackie_Chan)
In this case, what model did the face exchange software train? (2分)

%WORKSPACE%/model/ 目录下的 *_SAEHD_summary.txt 中可以看到使用的模型为 DianPian_SAEHD4live_SAEHD.

训练的模型为 DianPian_SAEHD_model4live_SAEHD_model

DianPian_SAEHD_model,4live_SAEHD_model

67. [填空题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
4live_SAEHD_model 训练了多少迭代次数
How many times did 4live_SAEHD_model train ? (1分)

image-20240514140835384

1253447

68. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
换脸软件输出的文件名是什么?
What is the name of output of face exhange software (1分)
A.录制_2023_09_19_16_55_20_786.mp4
B.result.mp4
C.data_src.mp4
D.data_dst.mp4

image-20240514140950301

B

69. [多选题]题目内容请看题目描述。(69) (2分)

A.teamviewer
B.rustdesk
C.totalcontrol
D.Pushbullet
参考 ' 潘志辉的计算机镜像 ' 回答以下题目
With reference to Peter's computer image to answer below question
分析潘志辉计算机的镜像后,相信他曾使用不同的遥距控制软件控制3部设备。请选择他曾使用的遥距控制软件。
提示1: 软件1显示Samsung Galaxy S7的设备编号(Device ID): 1062919330 & 潘志辉的计算机设备编号: 228758166
Tips1: In software1, Samsung Galaxy S7 ID is 1062919330 & Peter's computer ID is 228758166
提示2:软件2显示LM-G710EAW 5的ID: LM-G710EAW1f703895
Tips3: In software2, LM-G710EAW 5 ID is LM-G710EAW1f703895
提示3: 软件2显示LG-D855的ID: LGE- LG-D855
Tips4: In software2,  LG-D855 ID is LGE- LG-D855

提示1: 软件1显示Samsung Galaxy S7的设备编号(Device ID): 1062919330 & 潘志辉的计算机设备编号: 228758166
提示2: 软件2显示LM-G710EAW 5的ID: LM-G710EAW1f703895
提示3: 软件2显示LG-D855的ID: LGE- LG-D855

C:\Users\DFRNC - C59204\AppData\Roaming\RustDesk\config可以找到 RustDesk 的配置文件

image-20240514141403538

image-20240514141634469

log里面也有

image-20240514141741835

C:\Users\DFRNC - C59204\AppData\Roaming\Sigma-RT\Total Control\log

image-20240514142023910 image-20240514142412299

连过6台设备

image-20240514142153863

BC

70. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,可推论潘志辉用哪一个软件作一站式管理所有涉及的电子设备
According toPeter's computer,what software was used to control all involved devices by one platform (1分)
A.RustDesk
B.Total Control
C.Pushbullet
D.Teamviewer

image-20240514142627061

可以在 /Users/DFRNC - C59204/AppData/Local/Pushbullet/ 找到 PushBullet 的配置文件. 其中 devices.json.gz 中的 devices.json 中存储了所有设备的信息, 共计 7 台设备.

image-20240514142734872

C

71. [单选题]参考 ' 潘志辉的计算机与手机镜像 ' 回答以下题目

With reference to Peter's computer image and mobile phone images to answer below question
按照潘志辉的计算机与手机镜像可推论潘志辉正进行以下哪种犯罪
According to Peter's computer and mobile phome images, what crime was being comitted (1分)
A.网上求职骗案 (Online employment fraud)
B.钓鱼攻击 (Phishing Attack)
C.luoliao勒索 (Naked Chat Blackmail)
D.信用卡盗用 (Credit Card Fraud)

B

72. [填空题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,总共有多少个电子设备登入Pushbullet?
According to Peter's computer image, how many devices logined into Pushbullet ?
提示:请用阿拉伯数目字作答
Tips: Please answer in arabic number
(2分)

同上题

image-20240514142627061

7

73. [填空题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,潘志辉只有一个电子邮件账户,哪一天是该账户第一次登入Pushbullet?
According to Peter's computer image,Peter only had one email account. When was the first login in time in the email account
提示:请用YYYY_MM_DD的格式作答。
Tips: Please answer in YYYY_MM_DD format
(2分)

image-20240514143041466

image-20240514143238035

1689824898.213773
image-20240514143613742

2023-7-20

74. [填空题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,潘志辉发送大量SMS信息的文件名是甚么?
According to Peter's computer image, what is the name of file that Peter used to send abundant SMS?
提示: 需包括扩展名称如ABC_123.doc
Tips: Please include file extension such as ABC_123.doc (2分)

在用户桌面上存在一个文件 SMS_Pushbullet.xlsm, 是一个具有宏的 xlsm 文件, 运行宏之后会调用 PushBullet 发送短信.

image-20240514144023603

SMS_Pushbullet.xlsm

75. [填空题]题目内容请看题目描述。(75) (2分)

参考 ' 潘志辉的计算机镜像 ' 回答以下题目
With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,Pushbullet与 "发送大量SMS信息的文件"应用了哪一个技术交换信息
According to Peter's computer image, what did Pushbullet and "the file that Peter used to send abundant SMS" use to communicate with each other
提示:请用小写英文全名并以下例子格式答题。例子:graphic_user_interface
Tips: Please use lowercase English full name and the example to answer the question.

xlsm 中的宏通过 http 请求本地 Pushbullet 建立的内网接口.

API 的全称是 application-programming-interface.

application_programming_interface

76. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,哪一个设备曾经在Pushbullet内向Galaxy S7发送 “生财工具” 的信息?
According to Peter's computer image, what device sent the message of "Money making tool" to Galaxy in Pushbullet
(1分)
A.手提电话Galaxy S7
B.计算机C59204
C.手提电话Galaxy S4
D.手提电话P30 Pro

pushed.json 中存在文件上传下载记录, 与"生财工具"有关的项目如下:

image-20240514144310947

发送者(source_device_iden)为ujB228gobeusjD2R9nBgpU

接收者(target_device_iden)为 ujB228gobeusjCU2aNERr2

image-20240514144653454

B

77. [填空题]题目内容请看题目描述。(77) (2分)

参考 ' 潘志辉的计算机镜像 ' 回答以下题目
With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,开启VMware内ubuntu 的密码是多少?
According to Peter's computer image, what is the password to open the ubuntu VM
提示1(Tips 1):相关的Ubuntu文件在(Relevant file is situated at)Program Files(x86)\Vmware\VM Player
Ubuntu的路径为(Ubuntu path is) C:\Program Files (x86)\Vmware\Vmware Player\Ubuntu VM
提示2(Tips 2): 请以小写英文与附号作答
Please answer in lowercase enligsh and symbol 
提示3(Tips): 可考虑使用Kali Linux 、网上平台与ubuntupassword.txt内所有的数据协助找出密码
You can consider to use all content of Kali Linux, online platform and ubuntupassword.txt to find the password

密码不对

image-20240514145017770

NTFS流隐写

image-20240514144857219

0c822f043cfc65dc0f2712819d6955f9
image-20240514150856923

(newpassword2)

78. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,潘志辉应用了哪一个技术把true-ubuntupassword.txt隐藏在ubuntupassword.txt中。
According to Peter's computer image,what technique did Peter use to hide the true password
(1分)
A.日志记录 (Log record)
B.数据压缩 (Data Compression)
C.数据加密 (Data Encryption)
D.备用数据流 (Alternate data stream)

D

79. [单选题]参考 ' 潘志辉的计算机镜像 ' 回答以下题目

With reference to Peter's computer image to answer below question
true-ubuntupassword.txt内有一组哈希值,该哈希值是下列哪一种?
What is the type of hash of true-ubuntupassword.txt (2分)
A.MD5
B.SHA1
C.SHA256
D.SHA512

A

80. [单选题]题目内容请看题目描述。(80) (2分)

A.i&ii
B.iii&iv
C.i&iii
D.ii&iv
参考 ' 潘志辉的计算机镜像 ' 回答以下题目
With reference to Peter's computer image to answer below question
按照Peter计算机.e01的文件,在Ubuntu VM在内执行Tor Browser时,在命令提示字符(Command Prompt)执行netstat指令输出网络数据,以下为部份内容。
According to Peter's computer image,Tor Browser was executed under Ubuntu VM.  A netstat command was executed in the command prompt to output network information.  A part of the output is listed below.
i: 192.168.145.128:47312
ii: 127.0.0.1:9150
iii: 192.168.145.128:60994
iv: 127.0.0.1:9151
上述哪一个数据可以推论潘志辉曾经使用Tor Browser
What information in above content can be used to infer the use of TorBrowser

把Ubuntu VM添加为新检材

Tor日志分析

在 syslog 中可以看到关于 Tor 的日志, 其中包括了 127.0.0.1:9050

image-20240514152020708

在 Tor 的配置文件 /etc/tor/torsocks.conf 也可以看到端口的配置信息:

image-20240514153137906

仿真后启动执行start-tor-browser.desktop启动Tor浏览器查看网络连接信息

image-20240514154601378

D

81. [填空题]题目内容请看题目描述。(81) (3分)

参考 ' 潘志辉的计算机镜像 ' 回答以下题目
With reference to Peter's computer image to answer below question
按照Peter计算机.e01的档案,潘志辉想把Tor Browser的entry 与 exit node 修改为澳洲进入,美国离开,但以下A-D 项的空白位置潘志辉不懂如何填上内容。
According to Peter's computer image,Peter wanted to change the entry node as Australia and exit node as USA.  However, he didn't know how to file A-D area 
EntryNodes {A} Strictnodes B
ExitNodes {C} Strictnodes D
请把A-D的资料填上 Please fill information in A-D
提示: 请以以下格式作答
Tips: Please answer like below format,例子(example): A:us,B:1,C:uk,D:0
EntryNodes {us} Strictnodes 1
ExitNodes {uk} Strictnodes 0

参考

https://communitydocs.accessnow.org/147-Tor_force_exit_nodes.html

EntryNodes{au}Strictnodes1
ExitNodes{us}Strictnodes1

82. [填空题]参考 ' 潘志辉的手机镜像HUAWEI P30 pro ' 回答以下题目

With reference to Peter's HUAWEI P30 Pro image to answer below question
在潘志辉手机华为P30 Pro 的WhatsApp与华为NOVA 5T 的WhatsApp的对话中,曾被修改过的对话,请找出修改前的内容。
In the whatsapp conversation between P30 Pro and NOVA 5T, what is the original content of the modified conversations?
提示:请用中文与小写字母作答
Tips:Please answer in Chinese and lower letter (2分)

火眼在解析文件集合时会出现无法解密的问题. 但实际上整个检材并没有任何加密, 怀疑是软件出现了 BUG.

换软件就可以解决问题. 或者可以将检材复制一份, 删除其中的 *_backup 文件夹, 打成 tar 包之后当做镜像添加, 坏处是解析出来的结果会缺少基本信息.

其余华为手机检材存在相同问题.

HUAWEI P30 pro发现这个消息

image-20240514160015227

查看nova5

image-20240514160112493

根据时间,定位出发给nova的信息,是最晚的那条

分析huawei的数据库

image-20240514160308802

过滤”換“这个字

message_ftsv2_content 表中, 可以找到原始消息内容. docid 字段与表 message_id 字段相对应.

image-20240514160411664

image-20240514160449643

再換busd

83. [填空题]参考 ' 潘志辉的手机镜像HUAWEI NOVA 5T ' 回答以下题目

With reference to Peter's HUAWEI NOVA 5T image to answer below question
潘志辉的手机华为 Nova 5T中曾使用哪一个文件以一部激光雕刻机打印了一个QR code,这个文件名称的扩展名是什么?
Peter used HUAWEI Nova 5T and connected the laser printer to print a QR code. What is the file name and file extension. (1分)

打印机应用存储历史记录的数据库位于 /data/com.hingin.l1.hiprint/databases/hiPrint

QRcode是二维码的意思

用这个打开

image-20240514180625862

image-20240514180649354

image-20240514180709662

print_history_data表中得到文件名为1697018528072fileName.bmp

print_parameters表中得到文件名为1697018528074.jpg

image-20240514180912916

1697018471188.jpg

84. [多选题]参考 ' 陈好的手机镜像 ' 回答以下题目

With reference to Leo's mobile phone image to answer below question
陈好手机的相片20230821_144459在安卓的其中一个数据库中,显示该相片可包含哪个主体?(多选)
Leo's mobile phone contained a photo 20230821_144459 in one of the Android database. How many item did the photo contain (1分)
A.食物(Food)
B.饮品(Drink)
C.拉面(Ramen)
D.桌子(Table)

image-20240514184028447

AC

85. [填空题]参考 ' 陈大昆的手机镜像 ' 回答以下题

With reference to Ben's mobile phone image to answer below question
陈大昆的手机被一个itune backup密码加密保护,这个密码是什么?
What is the itune backup password that Ben used to protect his home
提示:请用阿拉伯数字作答
Tips: Please answer in arabic number (1分)

passwarekit跑Manifest.plist

image-20240514184832312

123456

86. [单选题]参考 ' 潘志辉的手机镜像HUAWEI P30 pro ' 回答以下题目

With reference to Peter's HUAWEI P30 pro mobile phone image to answer below question
潘志辉手机华为P30 pro的WhatsApp 社群” 香港商品交易群组 Hong Kong Trading”,是什么时候建立的 (UTC+8)?
When was the WhatsApp group 香港商品交易群组 Hong Kong Trading in P30 pro was created (2分)
A.2023-02-22 06:16:50
B.2023-02-22 14:16:50
C.2023-02-16 10:06:50
D.2023-02-16 18:06:50

image-20240514184927054

B

87. [单选题]参考 ' 潘志辉的手机镜像HUAWEI P30 pro ' 回答以下题目

With reference to Peter's HUAWEI P30 pro mobile phone image to answer below question
潘志辉手机华为P30 Pro的 WhatsApp 的有多少个对话群组包含对话讯息记录(系统自行发出的不作计算)?
How many WhatsApp group in P30 Pro contain message (excluding system message group) (2分)
A.1
B.2
C.3
D.4

推测包含对话讯息的群指的是本机用户和其他用户都有发言的群组,翻看群组聊天记录,

只有在發財精英、SMS A、SMS B这三个群中有对话讯息记录

C

88. [多选题]参考李哲图的计算机镜像回答以下题目

With reference to Chris computer to answer below question
在李哲图传送给Ben的电邮中有2个附加文件,文件的名称是?
Chris sent 2 attachments to Ben. What are the names of the files? (1分)
A.New Target.rar
B.Key.jpg
C.use_this.png
D.name.txt

李哲图使用的电子邮箱应用为 Thunderbird, 但火眼无法正常解析发送邮件.

从Thunderbird 收件箱跳转到源文件

Thunderbird 的邮件存储路径为 /Users/chris/AppData/Roaming/Thunderbird/Profiles/911ah109.default-release/Mail/pop.gmail.com/.

其中的 Sent 文件中存储着 eml 格式的已发送邮件:

image-20240514190013724

A

89. [填空题]参考陈大昆的计算机镜像回答以下题目

With reference to Ben computer to answer below question
在陈大昆电脑中,他收到李哲图的电邮,当中有一个加密的压缩文件,该文件的开启密码是?
Ben's computer, he received an email from Chi To that included an encrypted compressed file. What is the password to open that file? (Capital Letter)
提示: 请用全大写字母作答
Tips: Please answer in capital letter
(2分)

提取其中 Base64 编码的附件, 保存.

content = open("content.txt", "rb").read()
import base64
content_d = base64.b64decode(content)
with open("New Target.rar", "wb") as fout:
   fout.write(content_d)

image-20240514190337875

陈大昆的计算机的下载中,有两个文件

image-20240514191236013

对比两个文件的 NTFS 流 <filename>^Zone.Identifier, 可以发现两个文件均来自于谷歌邮箱, 可以判断这两个文件是一同被下载的邮箱附件

image-20240514191426035

image-20240514191302612

是一张 Playfair 古典加密的密文生成图和密文,

参考https://www.geeksforgeeks.org/playfair-cipher-with-examples/

解密网站http://www.atoolbox.net/Tool.php?Id=912

image-20240514191820349

FOOTBALL

90. [填空题]题目内容请看题目描述。(90) (2分)

参考陈大昆的计算机镜像回答以下题目
With reference to Ben computer to answer below question
在陈大昆的电脑中,加密的压缩文件New Target.rar中有2个文件,一个是加密的Word文件,另一个是图片文件。已知Chi To曾处理图片以隐藏一段文字,那段文字是? 
On Ben's computer, within the encrypted compressed file "New Target.rar," there are 2 files. One is an encrypted Word document, and the other is an image file. It is known that Chi To has manipulated images to hide a piece of text. What is that piece of text?
提示: 请用英文与标点符号作答
Please answer in english and symbols

image-20240514192346506 image-20240514192519992

生成了data.txt

P@ssw0rd

P@ssw0rd

91. [单选题]参考李哲图的计算机镜像回答以下题目

With reference to Chris computer to answer below question
李哲图曾执行一个程序在"key.bmp"的图片文件中隐藏一段文字,請問他是用哪一个程序?
Which program did Chris use to hide the data from the file "key.bmp"? (1分)
A.Steganography Studio
B.OpenStego
C.Steghide
D.S-Tools

B

92. [单选题]题目内容请看题目描述。(92) (3分)

A.26
B.25
C.24
D.23
参考陈大昆的计算机镜像回答以下题目
With reference to Ben computer to answer below question
在陈大昆的电脑中,加密的压缩文件New Target.rar中有2个文件,一个是加密的Word文件,另一个是图片文件。已知图片的隐藏文字为加密的Word文件的Salt(为一个AES 256 加密)。在加密的Word文件中,李美玲的年龄为?
 In Ben's computer, there are 2 files in the encrypted compressed file "New Target.rar." One is an encrypted Word file, and the other is an image file. It is known that the hidden text in the image is the salt (AES 256 encryption) for the encrypted Word file. In the encrypted Word file, what is the age of 李美玲 ?

李哲图电脑中,在powershell历史命令中可以看到用openssl进行加密

image-20240514193357134

解密命令

openssl enc -aes-256-cbc -d -a -in encrypted.docx -out decrypted.docx

参数说明

  • enc:表示使用加密功能。
  • -aes-256-cbc:指定加密算法(AES-256-CBC)。
  • -d:表示解密模式。
  • -a:表示输入和输出为Base64编码。
  • -in encrypted.docx:指定输入文件,这里是加密的文件。
  • -out decrypted.docx:指定解密后的输出文件。

image-20240514193934043

25

93. [单选题]题目内容请看题目描述。(93) (3分)

A.TWchun111@gmail.com
B.TWchun1110@gmail.com
C.TWchun111@yahoo.com
D.ChunTW111@yahoo.com
参考陈大昆的计算机镜像回答以下题目
With reference to Ben computer to answer below question
在陈大昆的电脑中,加密的压缩文件New Target.rar中有2个文件,一个是加密的Word文件,另一个是图片文件。已知图片的隐藏文字为加密的Word文件的Salt (为一个AES 256 加密)。在加密的Word文件中,钟翠华的电邮为? 
 In Ben's computer, there are 2 files in the encrypted compressed file "New Target.rar." One is an encrypted Word file, and the other is an image file. It is known that the hidden text in the image is the salt (AES 256 encryption) for the encrypted Word file. In the encrypted Word file, what is the email of 钟翠华 ?

image-20240514193953256

A

94. [多选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
在Ben电脑中,他在Opensea.io中使用了哪些区块链制造NFT?
On Ben's computer, which blockchain(s) did he use to create NFTs on Opensea.io?
(2分)
A.Ethereum
B.Polygon PoS Chain
C.Arbitrum
D.Base

Ethereum:

image-20240514201119169

matic是Polygon PoS Chain前身,Matic Network现更名为Polygon

image-20240514201138059

从Q100的补充材料截图中也可以得到

image-20240514201035165

AB

95. [填空题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
在Ben电脑在Opensea.io中所创建的NFT(s)的Collection ID是?
The Collection ID of the NFT(s) created by Ben’s computer in Opensea.io is?
需以下例子的格式作答:Collection ID/Number of NFT(s) sold,例: 4561313456
Pplease answer as the format of below example:Collection ID/Number of NFT(s) sold (e.g.: 例: 4561313456) (2分)

image-20240514201234022

4346577817

96. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
这个Opensea.io中的Collection ID一共卖出了多少个NFT(s)?
How many NFTs were sold in total for the Collection ID on Opensea.io?
提示:请参阅附加资料
Tips: Please refer to additional information (1分)
A.0
B.1
C.2
D.3

image-20240514195234533

C

97. [填空题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
购买上述在Opensea.io中NFT(s)的加密货币地址是?
What is the cryptocurrency address used to purchase the NFT(s) on Opensea.io mentioned above?
提示:请参阅附加资料與请用大写字母作答
Tips: Please refer to additional information and answer in capital letters.
例子: 0X1234567ABCDEF (1分)

image-20240514195349457

0xA2adc0bF0106d1247aF272C444cFe39264c57f25

98. [多选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
哪些是购买上述Collection ID内的NFT(s)的交易哈希(Transaction Hash)?
Which of the following are the Transaction Hashes for the purchase of the above-mentioned NFT(s) from the Collection ID?
提示:请参阅附加资料
Tips: Please refer to additional information
(2分)
A.0x1c0ab817c6dcd48b065ba66affd5b9fa827a11fee9ae0fb865d3aecd60b7aae1
B.0xcbf3523d199efd2f61fdbc3d7debf706f8eb42c0dbe4a07d0d9472ab7e04c566
C.0xdc7f2e5362faf3b5ddc9ae0be83d3da7222b34f06e86862b9c0af1cc14e3c3e3
D.0xaaa011a6b6af54b11f97217d63dfa5f13aef160ebf672b1476de0460ef5b043f

image-20240514195448385

A

99. [填空题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
在Opensea.io中铸造上述NFT(s)的加密货币地址是?
What is the cryptocurrency address used to mint the above-mentioned NFT(s) on Opensea.io?
提示:请参阅附加资料与请用大写字母作答
Tips: Please refer to additional information and answer in capital letters.
例子(example): 0X1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ0123 (1分)

image-20240514195622675

image-20240514195905317

对应了商品ID

100. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
在Opensea.io中,由上述加密货币地址所铸造没有Collection ID的NFT找到什么资讯?
On Opensea.io, what information can be found about the NFT(s) without a Collection ID that were minted by the above-mentioned cryptocurrency address?
提示:请参阅附加资料
Tips: Please refer to additional information (1分)
A.Uniswap V3 BHB-WETH pool
B.0xa071e23fdbdfc23011a28977e102038747373575
C.Token ID: 561068
D.以上皆是

image-20240514200040958

D

101. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
合约地址(Contract Address):0xa071e23fdbdfc23011a28977e102038747373575所使用的是哪一个区块链?
The contract address 0xa071e23fdbdfc23011a28977e102038747373575 is associated with which blockchain?
提示:请参阅附加资料
Tips: Please refer to additional information (1分)
A.Ethereum
B.BNB Smart Chain
C.Polygon PoS Chain
D.Shibarium

image-20240514200130901

A

102. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
合约地址(Contract Address):0xa071e23fdbdfc23011a28977e102038747373575的加密货币名称(Name)及简写(Symbol)是?
What is the cryptocurrency name and symbol for the contract address 0xa071e23fdbdfc23011a28977e102038747373575?
提示:请参阅附加资料
Tips: Please refer to additional information (1分)
A.Binance (BNB)
B.Bihaibi (BHB)
C.BHB(BHB)
D.Binince (BHB)

image-20240514200235076

D

103. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
加密货币合约地址(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575在区块链的创建日期时间是?
The creation date and time of the cryptocurrency contract address 0xa071e23fdbdfc23011a28977e102038747373575 on the blockchain is?
提示:请参阅附加资料
Tips: Please refer to additional information (1分)
A.2023-09-06 16:58:11时
B.2023-09-07 14:50:35时
C.2023-09-15 12:18:47时
D.2023-09-19 10:22:11时

image-20240514200328567

A

104. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
加密货币合约址(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575的总铸造数量是?
The total supply of the cryptocurrency contract address 0xa071e23fdbdfc23011a28977e102038747373575 is?
提示:请参阅附加资料
Tips: Please refer to additional information (1分)
A.10,000
B.100,000,000
C.300,000,000
D.500,000,000

image-20240514200418002

C

105. [填空题]题目内容请看题目描述。(105) (1分)

参考 ' benckwindow10.e01 ' 回答以下题目
With reference to 'benckwindow10.e01' to answer below question
第一个储存加密货币合约(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575的地址是?
What is the first address to store cryptocurrency contract address (Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575?
提示:请参阅附加资料與请用大写字母作答
Tips: Please refer to additional information and answer in capital letters. 
例子(example): 0X1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ0123

image-20240514200456161

0xeb3c02f1bf7a6e700950f39e4876762f8a44426f

106. [填空题]题目内容请看题目描述。(106) (1分)

参考 ' benckwindow10.e01 ' 回答以下题目
With reference to 'benckwindow10.e01' to answer below question
铸造加密货币合约地址(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575的交易哈希(Transaction Hash)是?
The transaction hash for minting the tokens of the cryptocurrency contract address 0xa071e23fdbdfc23011a28977e102038747373575 is?
提示:请参阅附加资料與请用大写字母作答
Tips: Please refer to additional information and answer in capital letters. 
例子(example): 0X1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ0123

image-20240514200722815

0x267c8e68e3a9769261c7da8257bb80d800af3d222fb98a63d3c19d5fab6eb84c

107. [填空题]题目内容请看题目描述。(107) (3分)

参考 ' benckwindow10.e01 ' 回答以下题目
With reference to 'benckwindow10.e01' to answer below question
承上題,请根据铸造加密货币合约地址(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575的交易哈希(Transaction Hash),在Ben电脑中,找出比在以太坊 (Ethereum)上确认验证的日期时间早的文件名?
Please find the file name on Ben's computer that is earlier than the confirmed verification date and time on Ethereum blockchain based on the transaction hash for minting the tokens of the cryptocurrency contract address 0xa071e23fdbdfc23011a28977e102038747373575.
提示:请参阅附加资料与请用大写字母作答
Tips: Please refer to additional information and answer in capital letters.

image-20240514201804201

火眼时间线先筛选一下2023-09-06 16:58:00到2023-09-06 17:00:00之间创建的文件

image-20240514202148411

发现大多都是在C:\Users\benck168\AppData\Local\Mozilla\Firefox\Profiles\adc969fg.default-release\cache2\entries这个目录

image-20240514202221893

在这些文件中,使用FileLocator Pro批量搜索交易哈希

image-20240514203725728

9758501C07A1C4A010D029CA1862B8BD98C1E029

108. [多选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
承上題,按照在以太坊 (Ethereum)上确认验证的日期时间的文件的创建日期时间、路径及数据,下列哪些推论是正确的?
Based on the creation date and time, path, and data of the file, which of the following inferences are correct?
(2分)
A.Ben电脑内发现的交易哈希,比写上以太坊 (Ethereum)被确认验证的交易哈希早出现
B.此档案与Firefox浏览器有关
C.此档案与Chrome浏览器有关
D.此档案是由陈大昆电脑的用户benck168创建的

image-20240514204535080

ABD

109. [单选题]题目内容请看题目描述。(109) (1分)

A.Pancake Swap
B.Uniswap
C.Shibaswap
D.1inch.io
参考 ' benckwindow10.e01 ' 回答以下题目
With reference to 'benckwindow10.e01' to answer below question
以下哪个去中心化交易中心(Dex) 能够成功兑换加密货币合约地址(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575?
Which decentralized exchange (Dex) is capable of successfully exchanging the cryptocurrency contract address 0xa071e23fdbdfc23011a28977e102038747373575?
提示:请参阅附加资料
Tips: Please refer to additional information

image-20240514204711107

B

110. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
截至2023-09-07 1511时,加密货币合约地址(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575对美元(USD)的市场价格是?
The market price of the cryptocurrency contract address 0xa071e23fdbdfc23011a28977e102038747373575 in USD as of September 7, 2023, 15:11 is?
提示:请参阅附加资料
Tips: Please refer to additional information (1分)
A.0.01636
B.0.01638
C.0.000009995
D.0.00001019

答案里没有

在这个网站上是0.01647

image-20240514205354169

别的网站dextools.io

img

0.01647

111. [填空题]题目内容请看题目描述。(111) (1分)

参考 ' benckwindow10.e01 ' 回答以下题目
With reference to 'benckwindow10.e01' to answer below question
截至2023-09-20,持有50,000,000个加密货币合约地址(Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575的加密货币地址是?
As of 2023-09-20, what is the cryptocurrency address holding 50,000,000 cryptocurrency contract addresses (Contract Address): 0xa071e23fdbdfc23011a28977e102038747373575?
提示:请参阅附加资料與请用大写字母作答
Tips: Please refer to additional information and answer in capital letters.

image-20240514205611208

0x08b57d253lac4cd18bc785b9deb688ffe61a4e8e

112. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
按照时间线分析Ben电脑活动,在2023-09-06 16:58:10时及2023-09-06 16:58:21时,在”Access-Control-Allow-Origin”中显示了哪一个网站?
Analyzing Ben's computer activities according to the timeline, which website was displayed in "Access-Control-Allow-Origin" at 2023-09-06 16:58:10 and 2023-09-06 16:58:21 ? (2分)
A.https://www.google.com
B.https://remix.ethereum.org
C.https://ethereumfoundation.matomo.cloud
D.https://www.etherscan.io

根据题目中给出的时间, 结合浏览器历史记录, 找到网址为 remix.ethereum.org:

image-20240514205955793

image-20240515143425865

113. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
承上題,在2023-09-06 16:58:10时及2023-09-06 16:58:21时,在”Access-Control-Allow-Origin”中显示的网站有什么功能?
What are the functions of the above website?
(1分)
A.太坊区块链上的交易、地址、合约、代币等信息查询
B.太坊基金会的网站分析工具,用于跟踪和分析网站访问者的行为和活动
C.以太坊官方的在线IDE(集成开发环境),可用于编写、测试和部署智能合约
D.网上搜索引擎

image-20240515143636968

C

114. [单选题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
哪一个扩展名与创建加密货币有关?
Which file extension is related to creating a cryptocurrency?
(1分)
A.png
B.sol
C.mp4
D.jpeg

image-20240515143714241

B

115. [多选题]题目内容请看题目描述。(115) (3分)

A.png
B.txt
C.mp4
D.jpeg
参考 ' benckwindow10.e01 ' 回答以下题目
With reference to 'benckwindow10.e01' to answer below question
陈大昆被捕后拒绝提供虚疑货币钱包密码及恢复种子,并以挑战口吻响应:「重要信息已经放好在桌面上,难道你没看见吗?」。在Ben电脑内与恢复种子有关的两个文件的扩展名是?
After being arrested, Ben Chen refused to provide the password and recovery seed of the cryptocurrency wallet, and responded in a challenging tone: "The important information has been placed on the desktop, didn't you see it?". What are the file extensions of the two files related to the recovery seed in Ben's computer?

语句不通顺的图片,对应解密的txt

image-20240515143959931

image-20240515144024710

BD

116. [填空题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
承上題,在陈大昆电脑内恢复种子的第八个英文单字是?
What is the eighth word for the above-mentioned recovery seed? (Answer in all capital letters)
提示:请用大写字母作答
Tips: Please answer in capital letter
(3分)

对应解密为:

stable arrange expect popular train oak harsh grant quality mimic genre eternal
image-20240515144205691

grant

117. [填空题]题目内容请看题目描述。(117) (3分)

参考 ' benckwindow10.e01 ' 回答以下题目
With reference to 'benckwindow10.e01' to answer below question
按照上述恢复种子,请计算出在以太坊(Ethereum)其BIP-44 derivation address = m/44'/60'/0'/0/0的公钥?
Based on the above recovery seed, please calculate the public key of its BIP-44 derivation address = m/44'/60'/0'/0/0 in Ethereum?
提示:请用大写字母作答
Tips: Please answer in capital letters. 
例子: 0X1234567890ABCDEFGHIJKLMNOPQRSTUVWXYZ0123

使用 Mnemonic-Code-Converter 工具进行恢复.

https://iancoleman.io/bip39/#chinese_simplified

image-20240515144450526

image-20240515144530660

0x02adbbc484e52e921b2678305c092fc794a97c7552ba86b5f3362b892c660e4cce

118. [填空题]参考 ' benckwindow10.e01 ' 回答以下题目

With reference to 'benckwindow10.e01' to answer below question
按照上述恢复种子,请计算出在波场网络(Tron Network)其BIP-44 derivation address = m/44'/195'/0'/0/2的私钥?
Based on the above recovery seed, please calculate the private key of its BIP-44 derivation address = m/44'/195'/0'/0/2 on Tron Network?
提示:请用大写字母与阿拉伯数字作答
Tips: Please answer in capital letters and arabic number
(3分)

TRX币(波场币)是一种基于区块链技术的数字货币,它是波场网络(Tron Network)的本地加密货币

image-20240515144740580

image-20240515144825461

4883c816b7154dd4c66a5674e98564febd17cac51dcb1ad349932177982fa2df

*NAS重组

使用ftk Imager挂载3个镜像

image-20240515153739064

自动重组后的raid设备是SG7:2,右键选择查看raid参数

image-20240515153839213

正确识别出来RAID

导出来重组后的镜像,再用火眼分析导入

image-20240515154923732

119. [填空题]参考 ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' 回答以下题目

With reference to ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' to answer below question
案中所使用的 NAS 是哪个品牌?
What brand of NAS was used in the case?
提示:请用小写字母作答
Tips: Please answr in lower letter.
(2分)

ufs加载镜像,自动重组raid

image-20240515145812398

/etc/synoinfo.conf 中可以看到关于公司的信息

image-20240515150245938

显示公司为 Synology (群晖).

/etc.defaults/hostname看一眼hostname

image-20240515150133517

Synology

120. [填空题]参考 ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' 回答以下题目

With reference to ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' to answer below question
NAS 所使用的是哪个容错式磁盘阵列的层级(RAID LEVEL) ?
What RAID Level does the NAS use ?
提示:请用阿拉伯数字作答
Please answer in arabic number
(1分)

image-20240515153339698

5

121. [填空题]参考 ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' 回答以下题目

With reference to ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' to answer below question
NAS 所使用的容错式磁盘阵列是那种数据分布方式(Layout) ?
What is the layout of NAS?
提示:请用小写字母作答,如: abc-def
Please answer in lower case (2分)

看右边是左同步

image-20240515153401428

left-symmetric

122. [填空题]参考 ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' 回答以下题目

With reference to ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' to answer below question
试列出 NAS 容错式磁盘阵列里面的所有逻辑巻名称(Logical Volume Name)
Please list out all logicalvolume name
提示:请用小写英文以及在空格或标点符号位置用以_作答
Please answer in lowercase english and use _ to expres the blank area.例子(example) :abcd_efgh_123
(3分)

image-20240515154045739

syno_vg_reservesd_area_volume_1

123. [填空题]参考 ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' 回答以下题目

With reference to ' NAS-DISK1.e01, NAS-DISK2.e01, NAS-DISK3.e01 ' to answer below question
NAS 安装了哪个版本的 MariaDB ?
What version of Maria DB did NAS use?
提示:请以以下格式作答
Please answer in below format,例子(example): 21.22.23
(3分)

image-20240515154158663

10.3.32

124. [填空题]参考 ' DiskImage.e01 ' 回答以下题目

With reference to DiskImage.e01 to answer below question
试列出数据库内所有表(Table)的名称 ?
Please list out all tables in database
因为涉及多在1个项目,请把英文前缀较前的项目放先,并依以下例子的格式作答
正确例子:brand&serialnumber
错误例子:serialnumber&brand
(3分)

再FTP文件夹里有一个sql文件

image-20240515155415409

image-20240515155512965

image-20240515155540154

两个表名creditcard,和users

creditcard&users

125. [填空题]参考 ' DiskImage.e01 ' 回答以下题目

With reference to DiskImage.e01 to answer below question
数据库是那一天被保存?
When was the database preserved
提示:请用YYYY_MM_DD的格式作答
Please answer in below format YYYY_MM_DD
例子(example):1986_01_23 (1分)

image-20240515155652556

2023_09_20

126. [填空题]参考 '陈大昆的MacBook映象档"中的"0c1c.7z"档案回答以下题目:

With reference to 0c1c.7z of Ben's Macbook image to answer below question
Can you find out what compiler was used to generate this binary?
你可以找出生成"0c1c.bin"这个二进制文件所使用的编译器吗?
(编译器名称包括所有英文字母、数字,符号,区分大小阶,不需要空格) (2分)

文件在funnystuff.dwg

image-20240515155841516

查壳,发现是upx壳

image-20240515161553303

先脱壳

image-20240515161535268

再检测

image-20240515161654723

GCC:(Alpine9.3.0)9.3.0

127. [填空题]参考 '陈大昆的MacBook映象档"中的"0c1c.7z"文件回答以下题目:

With reference to 0c1c.7z of Ben's Macbook image to answer below question
How many initialization function entry points does the malware have?
这个恶意软件具有多少个初始化函数入口点?
(请以阿拉伯数字回答,例如:100)
(2分)

不会

128. [填空题]参考 '陈大昆的MacBook映象档"中的"0c1c.7z"档案回答以下题目:

With reference to 0c1c.7z of Ben's Macbook image to answer below question
What is the entry point of the binary?
这个二进制文件"0c1c.bin"的入口点是什么?
(注意: 不同检验工具可能会以不同位移值开始,如: 0x00000000或0x00100000,但所有回答请以0x00000000开始)
(请以16进制回答,"0x"后的英文字母需大阶,例如:0x0123ABEF) (2分)

image-20240515161859440

0x00068347

129. [填空题]参考 '陈大昆的MacBook映象档"中的"0c1c.7z"文件回答以下题目:

With reference to 0c1c.7z of Ben's Macbook image to answer below question
The malware should contain a section named '.rodata'.
What is the size of this section ? State the answer in decimal place.
恶意软件应该包含一个名为 '.rodata' 的部分,请提供这个'.rodata'部分的文件大小(单位为byte),以十进制方式回答您的问题。
(请以阿拉伯数字回答,例如:100) (2分)

IDA64打开0c1c.bin,在导航栏选择view>Open Subviews>Segments打开段视图

image-20240515162126167

用end减去start再转为10进制

image-20240515162243521

831408

130. [填空题]参考 '陈大昆的MacBook映象档"中的"0c1c.7z"档案回答以下题目:

With reference to 0c1c.7z of Ben's Macbook image to answer below question
The malware contains two strings related to the name of two well-known crytocurrencies. What are they?
这个恶意软件包含两个与两种知名加密货币名称相关的字符串。它们是什么?
(如有英文字母需大阶,并以前缀英文字母由小至大次序回答)
请按照以下格式回答:
例子:如两种知名加密货币名称分分别是Cat及Apple
请填写: APPLE+CAT
(2分)

IDA64中shift+F12查看字符串,搜索coin关键词

image-20240515163707965

这里有个问题,IDA字符串加载一段时间以后,Kevacoin就没有了

image-20240515164605616

image-20240515164659261

手动合并一下:

image-20240515164805610

Kevacoin+Ravencoin

131. [填空题]题目内容请看题目描述。(131) (3分)

参考 '陈大昆的MacBook映象档"中的"0c1c.7z"文件回答以下题目:

With reference to 0c1c.7z of Ben's Macbook image to answer below question
Which function contained below instructuion which appear to be used for loading memoery addresses of instruction operandss related CPU binding.
--▶ [ lea rdx, str.cpubind.set_thisproc_cpubind ]

以下指令似乎用在加载与 CPU 绑定相关的指令操作数的内存地址,哪个函数包含了这些指令,请回答该函数的位移值。

--▶ [ lea rdx, str.cpubind.set_thisproc_cpubind ]

(注意: 不同检验工具可能会以不同位移值开始,如: 0x00000000或0x00100000,但所有回答请以0x00000000开始)
(请以16进制回答,"0x"后的英文字母需大阶,例如:0x0123ABEF)

字符串搜cpubind.set_thisproc_cpubind

image-20240515164945069

image-20240515165048148

image-20240515165146772

该函数的位移值为4213A0

0x004213A0

132. [填空题]题目内容请看题目描述。(132) (3分)

参考 '陈大昆的MacBook映象档"中的"0c1c.7z"文件回答以下题目:

With reference to 0c1c.7z of Ben's Macbook image to answer below question
Which function contained below instruction which could likely be used to react with mining server for cryptocurrency?
--▶ [ lea rsi, str.___p____passPASSWORD___________password_for_mining_server_n ]

以下指令可能用在与加密货币挖矿服务器进行交互。哪个函数包含了这些指令?

--▶ [ lea rsi, str.___p____passPASSWORD___________password_for_mining_server_n ]

(注意: 不同检验工具可能会以不同位移值开始,如: 0x00000000或0x00100000,但所有回答请以0x00000000开始)
(请以16进制回答,"0x"后的英文字母需大阶,例如:0x0123ABEF)

image-20240515165517653

image-20240515165610266

image-20240515165642028

0x00AEAE0

133. [填空题]题目内容请看题目描述。(133) (3分)

参考 '陈大昆的MacBook映象档"中的"0c1c.7z"文件回答以下题目:
With reference to 0c1c.7z of Ben's Macbook image to answer below question
Which type of cryptocurrency is associated with this binary?  Please state its name and  the version.
这个二进制文件中,有一个加密货币相关联的应用程序,请提供应用程序名称、版本和相关加密货币名称。
(如有英文字母需大阶,应用程序版本请以阿拉伯数字及符号作答)

应用程序名称: ___(1)___
应用程序版本: ___(2)___
加密货币名称: ___(3)___

请按照以下格式回答: (1)+(2)+(3)
例子:如(1)的内容是abc、(2)的内容是123、(3)的内容是DEF
请填写: ABC+123+DEF

思路1:

字符串查看:

image-20240515170511311

XMRIG一个门罗币挖矿软件,门罗币(Monero,代号XMR)

版本是6.19.0

币种是MoneroOcean进一步验证

思路2:

发现是软件的使用方式

image-20240515171012084

image-20231115145216277.png

image-20231115145419656.png

XMRIG+6.19.0+Monero

134. [填空题]参考 '陈大昆的MacBook映象档"中的"35ea.7z"文件回答以下题目:

With reference to 35ea.7z of Ben's Macbook image to answer below question
Can you find out what compiler was used to generate this binary?
你可以找出生成"35ea.bin"这个二进制文件所使用的编译器吗?
(编译器名称包括所有英文字母、数字,符号,区分大小阶,不需要空格)
(3分)

image-20240515171118736

GCC:(Debian11.3.0-5)11.3.0

135. [填空题]参考 '陈大昆的MacBook映象档"中的"35ea.7z"文件回答以下题目:

With reference to 35ea.7z of Ben's Macbook image to answer below question
What is the entry point of the binary?
这个二进制文件的入口点是什么?
(注意: 不同检验工具可能会以不同位移值开始,如: 0x00000000或0x00100000,但所有回答请以0x00000000开始)
(请以16进制回答,"0x"后的英文字母需大阶,例如:0x0123ABEF) (3分)

0x000024F0

136. [填空题]参考 '陈大昆的MacBook映象档"中的"35ea.7z"文件回答以下题目:

With reference to 35ea.7z of Ben's Macbook image to answer below question
The binary contained a function called 'killVM'. What is the size of this function? State he answer in decimal.
这个二进制文件中包含一个名为 'killVM' 的函数。请提供这个函数的大小(单位为byte)并以十进制方式回答。
(请以阿拉伯数字回答,例如:100) (3分)

IDA64打开,View>Open subviews>Functions

image-20240515171444587

D0是大小

image-20240515171542476

208

137. [填空题]参考 '陈大昆的MacBook映象档"中的"35ea.7z"文件回答以下题目:

With Refernce to Ben's MacBook and 35ea.7z to answer below question
这个二进制文件应该包含一个名为 'EncrytFile' 的函数。请提供这个函数的大小以十进制方式回答您的问题。
The binary should contain a function called 'EncrytFile'. What is the size of this function? Give me the answer in decimal.
提示:请用阿拉伯数字作答
Tips: Please answer in arabic number (3分)

image-20240515174836139

十六进制255
image-20240515174943115

549

138. [填空题]參考 '陳大昆的MacBook映象檔"中的"35ea.7z"檔案回答以下題目:

How many functions in the binary are named with 'ECRYPT'?
这个二进制文件中有多少个函数的名称包含 'ECRYPT' 字串?
提示:请用阿拉伯数字作答
Tips: Please answer in arabic number (3分)

image-20240515175010929

7

139. [填空题]参考 '陈大昆的MacBook映象档"中的"35ea.7z"文件回答以下题目:

With Refernce to Ben's MacBook and 35ea.7z to answer below question
这个二进制文件与哪种勒索软件相关联?请提供其名称。
What kind of Ransomeware is associated with this binary? Please state its name.
提示:请用大写字母回答
Please answer in capital letter (3分)

image-20240515175133466

Conti

posted @ 2026-06-05 10:27  Cava1i  阅读(8)  评论(0)    收藏  举报