1- we will unzip the folder we will notice that the extension of the extracted file is monaliza.mem
2- what is .mem extension ? it’s image of memory dump , so we will use this awesome tool Volatility to investigate it.
but wait don’t forget that the name of the challenge is Monaliza , so we will just see mspaint.exe
6- then we will use Gimp tool to open it but first we need to change the extension to .data to open the raw data with Gimp. after playing with the offset too much time :(.
then i find it
then we will rotate the image and we will get the flag :), i’ll not write the flag to try it and learn without just copying it :).
Hope You Enjoy This.