BelkaCTF#6 - [9] Crypto(Warmup, 286)

BelkaCTF#6 - [9] Crypto(Warmup, 286)

작성자
d2n0s4urd2n0s4ur
카테고리
CTF
태그
BelkaCTF
BelkaSoft
작성일
Apr 9, 2024 12:07 PM
notion image
Now it was my turn to smirk, and the Chief noticed it, although I tried to conceal the grin. Apparently, I didn't have enough cigar smoke. The Chief waved his hand angrily.
—What are you grinning at? As if you didn't get extra work.
—Yeah, Chief. Sorry, couldn't help it.
Thanks to the Chief's idea, we found that restaurant, but... the camera footage miraculously disappeared!
—Any ideas on what to do next?
—Chief, my gut tells me that guy's computer isn't squeaky clean. I'll look again for some encrypted storage. The file might be drifting in an undercurrent, hidden from plain sight.
 
Q. Which file does the guy keep his encrypted container in? Format: full path, e.g. C:\VeraCrypt\MyContainer.vc

Solve

Used Tool
  • Autopsy
  • gkape
  • FullEventLogView
 
Recent documents say that phorger using vault as encrypted container.
notion image
(By checking BitLocker & Y:\\ )
 
So, I need to find a vhdx file or realted files.
using gkape, I extracted windows event log.
 
 
By using FullEventLogView, I can filter vault related logs.
notion image
 
The location of encrypted container is “C:\Users\phorger\Documents\desktop.ini:vault.vhdx”, also you can see the vault at Autopsy.
notion image
 
Answer: C:\Users\phorger\Documents\desktop.ini:vault.vhdx