Thanks Andrew. That confirms it's a raw file.
>>> addrspace().base
<volatility.plugins.addrspaces.standard.FileAddressSpace object at 0xafd2dcc>
I corrected the yarascan commandline, but there were no hits for the "Copyright (c) 1992-2004" string. So I switched to a more specific string in the output, "licensed by Dinkumware," and got the following:
Owner: (Unknown Kernel Memory)
0xf8a0051f40ae 6c 69 63 65 6e 73 65 64 20 62 79 20 44 69 6e 6b licensed.by.Dink
0xf8a0051f40be 75 6d 77 61 72 65 00 00 00 00 00 00 00 00 00 00 umware..........
0xf8a0051f40ce 00 00 04 01 09 03 53 61 46 41 00 00 00 00 00 00 ......SaFA......
0xf8a0051f40de 00 00 78 e3 2c 03 80 f8 ff ff 01 00 00 00 00 00 ..x.,...........
0xf8a0051f40ee 00 00 c5 db 02 00 00 00 02 00 20 c8 22 00 a0 f8 ............"...
0xf8a0051f40fe ff ff 70 41 1f 05 a0 f8 ff ff 20 c8 22 00 a0 f8 ..pA........"...
0xf8a0051f410e ff ff c5 db 02 00 00 00 02 00 01 08 20 00 00 00 ................
0xf8a0051f411e 00 00 d8 6a ac 9b 02 00 00 00 00 00 00 00 00 00 ...j............
0xf8a0051f412e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xf8a0051f413e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
0xf8a0051f414e 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 00 00 ................
0xf8a0051f415e 00 00 09 01 09 03 53 61 46 41 00 00 00 00 00 00 ......SaFA......
0xf8a0051f416e 00 00 78 e3 2c 03 80 f8 ff ff 01 00 00 00 00 00 ..x.,...........
0xf8a0051f417e 00 00 dc c1 02 00 00 00 05 00 20 c8 22 00 a0 f8 ............"...
0xf8a0051f418e ff ff 00 42 1f 05 a0 f8 ff ff 20 c8 22 00 a0 f8 ...B........"...
0xf8a0051f419e ff ff dc c1 02 00 00 00 05 00 01 08 20 00 00 00 ................
And 3 more similar hits:
Owner: (Unknown Kernel Memory)
0xf8a0051f50ae 6c 69 63 65 6e 73 65 64 20 62 79 20 44 69 6e 6b licensed.by.Dink
Owner: (Unknown Kernel Memory)
0xf8a0051f40ae 6c 69 63 65 6e 73 65 64 20 62 79 20 44 69 6e 6b licensed.by.Dink
Owner: (Unknown Kernel Memory)
0xf8a0051f50ae 6c 69 63 65 6e 73 65 64 20 62 79 20 44 69 6e 6b licensed.by.Dink
Then, if I go into volshell, I can find this, as expected:
>>> db(0xf8a0051f40ae)
0xf8a0051f40ae 6c 69 63 65 6e 73 65 64 20 62 79 20 44 69 6e 6b licensed.by.Dink
0xf8a0051f40be 75 6d 77 61 72 65 00 00 00 00 00 00 00 00 00 00 umware..........
0xf8a0051f40ce 00 00 04 01 09 03 53 61 46 41 00 00 00 00 00 00 ......SaFA......
0xf8a0051f40de 00 00 78 e3 2c 03 80 f8 ff ff 01 00 00 00 00 00 ..x.,...........
0xf8a0051f40ee 00 00 c5 db 02 00 00 00 02 00 20 c8 22 00 a0 f8 ............"...
0xf8a0051f40fe ff ff 70 41 1f 05 a0 f8 ff ff 20 c8 22 00 a0 f8 ..pA........"...
0xf8a0051f410e ff ff c5 db 02 00 00 00 02 00 01 08 20 00 00 00 ................
0xf8a0051f411e 00 00 d8 6a ac 9b 02 00 00 00 00 00 00 00 00 00 ...j............
>>>
So it seems there was something awry with the 'strings' input or output, perhaps? None of the addresses provided by 'strings' seem to match up with what 'yarascan' found. Here are the addresses provided by 'strings':
4397692928 [kernel:f9805ba44800] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
4401204576 [kernel:f8a021c19d60] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
4410548688 [kernel:f9803f62c1d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
4563104208 [kernel:f9806300e1d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
4727559968 [kernel:f9804181a720] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
4738933200 [kernel:f9808a5001d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
4740919640 [kernel:fa8015ea9158] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
4952543696 [kernel:fa8015f731d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
5138492960 [kernel:f8a01eb17e20] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
5161845080 [kernel:f9805917a158] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
5258514896 [kernel:f8a001b3b1d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
5799964000 [kernel:f8a01f767d60] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
5881786832 [kernel:f8a01f1601d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
6197270888 [kernel:f8801a9c1968] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
6350540128 [kernel:f8a022444d60] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
6356414928 [kernel:f880137cc1d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
6517550432 [kernel:f8a01f4b6d60] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
6542855408 [kernel:f8a02e933cf0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
6754533720 [kernel:f980647a7158] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
6924487016 [kernel:f8a018420968] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7018662704 [kernel:f8801361db30] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7037142816 [kernel:f88018c32720] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7465709912 [kernel:f88007966158] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7467875312 [kernel:f88007513bf0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7469826392 [kernel:f88006f6b158] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7476650448 [kernel:f880156391d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7517348304 [kernel:f7ffefe1a1d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7517924704 [kernel:f7ffefea6d60] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
7775407456 [kernel:f880026c7d60] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
8967958992 [kernel:f880109c61d0] Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
Greg