# HireMe CyberDefenders

Analyze the provided disk image and answer the questions based on your understanding of the cases she was assigned to investigate.

<figure><img src="/files/76ZZWlTcSQEJIDtvwsjW" alt=""><figcaption></figcaption></figure>

**Link  :** [**https://cyberdefenders.org/blueteam-ctf-challenges/62**](https://cyberdefenders.org/blueteam-ctf-challenges/62)

\
1\. What is the administrator's username?
-----------------------------------------

The fastest way is to list the Users directory of the Second Partition

<figure><img src="/files/vPi7ui08ECNyFxoMKqny" alt=""><figcaption></figcaption></figure>

you can also check **Registry hives which are located under "\Windows\System32\config"**&#x20;

**and Check the "SAM\Domains\Account\Users"**

\
**Ans : Karen**

### 2. What is the OS's build number?

Registry hives are located under "\Windows\System32\config"

Export Software hive&#x20;

Then Check "Microsoft\Windows NT\CurrentVersion" .

click export files

<figure><img src="/files/z8cSNXmdYm5GLPxGiLaD" alt=""><figcaption></figcaption></figure>

Then import it at registry editor

<figure><img src="/files/5JNRRQZ4D5hEoocxLnRF" alt=""><figcaption><p><br></p></figcaption></figure>

Check "Microsoft\Windows NT\CurrentVersion"&#x20;

<figure><img src="/files/tCysOSQxYljGR8O3Rokn" alt=""><figcaption></figcaption></figure>

**Ans : 16299**

## 3. What is the hostname of the computer?

we have to export the **System** registry from FTK Imager & upload it in the Registry editor just like the Software registry\ <br>

<figure><img src="/files/KtDM9Fe24bos2TBkaNmu" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/WA0K2CShgKwaTuhNGlmu" alt=""><figcaption></figcaption></figure>

**then  Check "ControlSet001\Control\ComputerName\ComputerName"**

<figure><img src="/files/6VaSTTc8nKevQdOke8UQ" alt=""><figcaption></figcaption></figure>

**Ans : TOTALLYNOTAHACK**

### 4. A messaging application was used to communicate with a fellow Alpaca enthusiest. What is the name of the software?

in FTK Imager we find out that the messaging application

<figure><img src="/files/0J8vY6QWhVcGEGBDiVI0" alt=""><figcaption></figcaption></figure>

another way to find it we can **Analyze SOFTWARE registry by loading it in registory editor .**

لإhen Check keys listed under the "Microsoft\Windows\CurrentVersion\App Paths" which stores informations about all the installed applications.

<figure><img src="/files/ga2AoNdrzwazGGvSW982" alt=""><figcaption></figcaption></figure>

**Ans : skype**

### 5. What is the zip code of the administrator's post?

To get this informations we have to check the file which stores Browser data and history .&#x20;

The location of this file is “**\[root]\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Web Data**”.

<figure><img src="/files/jInghJ1LYNiiVKWMppUC" alt=""><figcaption></figcaption></figure>

**Ans : 19709**

### 6. What are the initials of the person who contacted the admin user from TAAUSAI?

**To get it we can Check outlook artifacts.**&#x20;

**in  "\[root]\Users\Karen\AppData\Local\Microsoft\Outlook\\<klovespizza@outlook.com.ost>"**&#x20;

<figure><img src="/files/UTPtKEQlQtuPXc9pw34C" alt=""><figcaption></figcaption></figure>

**Export & and open it in Ost veiwer**

<figure><img src="/files/CqyvCJ8XMKG1E2HeP9zz" alt=""><figcaption></figcaption></figure>

Micheal Scotch

**Ans : MS**

### 7. How much money was TAAUSAI willing to pay upfront?

check more mails

<figure><img src="/files/pJ8dkyAKtXzBQgzr4PtZ" alt=""><figcaption></figcaption></figure>

**Ans : 150000**

### 8. What country is the admin user meeting the hacker group in?

After check more mails&#x20;

I found that&#x20;

<figure><img src="/files/srRS6pSyzqyIT5n3yP0a" alt=""><figcaption></figcaption></figure>

The location is “**27**°**22**'**50.10**″**N**, **33**°**37**'**54.62**″**E** ”

I searched for it

<figure><img src="/files/FAKsRGM7rOsbimNLj4n8" alt=""><figcaption></figcaption></figure>

**Ans : Egypt**

### 9. What is the machine's timezone? (Use the three-letter abbreviation)

We can check System hive again in registry editor

which store in store in the "**ControlSet001\Control\TimeZoneInfor**

&#x20;

<figure><img src="/files/vNXAmmZv13PuKSd3eGQe" alt=""><figcaption></figcaption></figure>

**Ans : UTC**

### 10. When was AlpacaCare.docx last accessed?

go to the docx file in FTK Imager then  From **File access properties**&#x20;

**Check the accessed date**&#x20;

<br>

<figure><img src="/files/svAQ4d06qOYjNiQpQtfp" alt=""><figcaption></figcaption></figure>

**Ans : 03/17/2019 09:52 PM**

### 11. There was a second partition on the drive. What is the letter assigned to it?

we find out that the second partition of the drive is store in the “**SYSTEM\MountedDevices”** registry.

<figure><img src="/files/yoWbFSlUQN8nem1c49Fo" alt=""><figcaption></figcaption></figure>

**Ans : A**<br>

### 12. What is the answer to the question Company's manager asked Karen?

we can back to mails list

<figure><img src="/files/kqukrcxAO2pqwkjXk9Mj" alt=""><figcaption></figcaption></figure>

by investigate the mails i found it&#x20;

**Ans : TheCardCriesNoMore**

### 13. What is the job position offered to Karen? (3 words, 2 spaces in between)

check the next mail<br>

<figure><img src="/files/uHknjJNO5E4YYqO5N4UU" alt=""><figcaption></figcaption></figure>

**Ans : cyber security analyst**

### 14. When was the admin user password last changed?

&#x20;That's stored in the SAM registry

&#x20;so we have to analyze the “**SAM**” registry. that

by saved it ,&#x20;

<figure><img src="/files/gWEqvVLGq4dx6LgLRXAr" alt=""><figcaption></figcaption></figure>

and export the SAM registry file in regripper

<figure><img src="/files/NbxtRSVP1NMmJEF4o5s2" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Syc21uzD6AvDWGKXWphB" alt=""><figcaption></figcaption></figure>

**Ans : 03/21/2019 19:13:09**

### 15. What version of Chrome is installed on the machine?

\
here we use Software hive&#x20;

&#x20;infoormations about last google chrome version is stored in "**SOFTWARE\WOW6432Node\Microsoft\Windows \CurrentVersion\Uninstall\Google Chrome"**.

<figure><img src="/files/Rwpnmsmxe7vWkANQnjU6" alt=""><figcaption></figcaption></figure>

**Ans** : **72.0.3626.121**

### &#x20;16 : What is the HostUrl of Skype?

location which store download URL is “**History**”. So, we extract History from the FTK imager&#x20;

Location of History is: "\[root]\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\History"

<figure><img src="/files/vcKc1yyHu8GDmjcgQFVW" alt=""><figcaption></figcaption></figure>

Then open it using SQLite3.<br>

<figure><img src="/files/qoan8cHmLsKPE61yzhNh" alt=""><figcaption></figcaption></figure>

**Ans :** [**https://download.skype.com/s4l/download/win/Skype-8.41.0.54.exe**](https://download.skype.com/s4l/download/win/Skype-8.41.0.54.exe)

### 17. What is the domain name of the website Karen browsed on Alpaca care that the file AlpacaCare.docx is based on?

&#x20;we can export the AlpacaCare.docx file  then analyze it.

<figure><img src="/files/hraCFXzproHTnjK2ajKe" alt=""><figcaption></figcaption></figure>

Then We can view the file with Libreoffice

<figure><img src="/files/pMLeOR1Xqsr0rZopFWtk" alt=""><figcaption></figcaption></figure>

The hyperlink used in website is  "palominoalapacafarm.com".

**Ans: palominoalpacafarm.com**

Thaaaaaannnnnkkkk UUUUUUU for reading 🥰

<br>

<br>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://0xmedhat.gitbook.io/whoami/writesup/hireme-cyberdefenders.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
