Please before look to Evil Twin
We need to dump the process with PID 5448
python2 vol.py -f mem.raw --profile=Win10x64_15063 procdump -p 5448 -D dump
It will produce an exe in dump folder. We calculate the md5 of file
If we search for the md5 hash in the viriustotal
we find the flag at url
Flag: flag{h4cktober_ctf_2020_nc}