by choartex on Tue Nov 08, 2016 7:58 pm
([msg=93084]see Re: Forensic Mission 3[/msg])
I've been stuck on this mission for quite some time now...
Finished the other 2 without much trouble but I can't figure out what to do...
I'd like some help or being pointed towards the right direction
So here is what I got and my theory:
the answer lies within the siggies.txt, this contains headers for the files, so I manually checked the files for their headers containing anything relating to mail-stuff
also checked their headers within a hexeditor next to the siggies file to see if the files where indeed the right file types.
Now I also found it strange that the shh.jpg image has this abnormal size, there must be something up with that, but I can't open it in any other program without getting nonsense... The other files seem legit, somewhere has to be a bitcoin wallet tho, because there is obvious hints pointing towards it.
So if anyone could tell me how to tie these finding together or at least tell me what I should examine again or should lok up online then I'd be extremely gratefull because this is driving me insane :')
Thanks in advance!
-- Wed Nov 09, 2016 3:27 pm --
Alright, I managed to figure it out by a tip given from a classmate. I'll give the same tip and partly my assumption above here where right.
A good thing to do is looking how files are saved in hex, they have signatures and with that a header/footer. figure that out for the files, look at the existing ones and compare.
You are trying to untangle a giant file into multiple files.
goodluck I suppose, if you need more help feel free to pm me, I won't give you the answer but I'll point you in the right direction, be sure to tell me what you already tried and found so that I do not spoil to much!