First, let’s take a look at these files :

I think this two files are the SAM and SYSTEM file. So I unpacked them with samdump2 :

samdump2 -o test.txt 2 1

These are some windows password hashes !!! Let’s try to decode them :

Using Crackstation.net

Flag : r4inb0w


TheFlagIsNotHere

CTF team