基于环境
C:\Users\Administrator\Desktop\mem\volatility3-develop>python volshell.py -f C:\Users\Administrator\Desktop\mem\pc_mem -w
Volshell (Volatility 3 Framework) 2.8.0
Progress: 100.00 PDB scanning finished
Call help() to see available functions
Volshell mode : Windows
Current Layer : layer_name
Current Symbol Table : symbol_table_name1
Current Kernel Name : kernel
(layer_name) >>> cp(7304)
查找微信密钥地址,在查找过程中发现密钥指针实际在内存地址在0x7ffe0c437c10,但通常密钥指针内存地址为WeChatWin.dll基址+偏移量,根据WeChatWin.dll基址为0x7ffe06b00000,该微信版本的偏移量为0x5937718,理论上密钥指针内存地址应该是0x7ffe06b00000+0x5937718=7ffe0c437718,但与实际的0x7ffe0c437c10相差4f8,是什么原因
Volatility3基本分析信息:
CheatEngine基本分析信息:(反推过来WeChatWin.dll基址也为0x7ffe06b00000)