| ID: | 10833 |
|---|---|
| 标题: | [OtterCTF 2018]Hide And Seek |
| 描述: | The reason that we took rick's PC memory dump is because there was a malware infection. Please find the malware process name (including the extension) 得到的答案使用NSSCTF{}格式提交。 |
| 类型: | 内存取证 |
| 网站: | NSSCTF |
| 题目链接: | https://www.nssctf.cn/problem/2464 |
| 赛事: | OtterCTF |
| 年度: | 2018 |
| Flag值: | vmware-tray.exe |
| writeup: | https://www.cnblogs.com/carefree669/p/16499784.html |