{"provider_name":"Hatena Blog","blog_url":"https://dakutenpura.hatenablog.com/","author_url":"https://blog.hatena.ne.jp/dakutenpura/","image_url":null,"title":"HITBXCTF 2018 Quals - boom","author_name":"dakutenpura","blog_title":"A box of chocolate","type":"rich","url":"https://dakutenpura.hatenablog.com/entry/2018/04/14/193129","published":"2018-04-14 19:31:29","height":"190","width":"100%","version":"1.0","categories":[],"provider_url":"https://hatena.blog","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fdakutenpura.hatenablog.com%2Fentry%2F2018%2F04%2F14%2F193129\" title=\"HITBXCTF 2018 Quals - boom - A box of chocolate\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","description":"We are given a .vmem file, which is a memory file generated by VMware. The problem description indicates that this VM might be infected with a malware, so let's use Volatility to analyze this memory dump. Let's check what OS this memory dump is running: $ volatility -f BOOM-6452e9b9.vmem imageinfo V\u2026"}