Acquire the basic skills to analyze a memory dump in a practical scenario.
Task 2: Memory Forensics
2.1. What type of memory is analyzed during a forensic memory task?
RAM
2.2. In which phase will you create a memory dump of the target system?
Memory Acquisition
Task 3: Environment & Setup
3.1. Which plugin can help us to get information about the OS running on the target machine?
data:image/s3,"s3://crabby-images/518e9/518e9548b967cd5d1b75dc43d83a8c5ae130c360" alt=""
Windows.info
3.2. Which tool referenced above can help us take a memory dump on a Linux OS?
data:image/s3,"s3://crabby-images/1b88f/1b88f6119f42b0cb38a39e581c44b09f8c237d5d" alt=""
LIME
3.3. Which command will display the help menu using Volatility on the target machine?
vol -h
Task 4: Gathering Target Information
4.1. Is the architecture of the machine x64 (64bit) Y/N?
data:image/s3,"s3://crabby-images/c6849/c6849c6aaf2267a26f2e905d7716a09e957a25ca" alt=""
Y
4.2. What is the Verison of the Windows OS
data:image/s3,"s3://crabby-images/1c97d/1c97d53f4585e2942df960bc8eb2dce978bd9443" alt=""
10
4.3. What is the base address of the kernel?
data:image/s3,"s3://crabby-images/27c48/27c48ab43c4564bd479e7a643a26e349e869cf97" alt=""
0xf8066161b000
Task 5: Searching for Suspicious Activity
5.1. Using the plugin “windows.netscan” can you identify the IP address that establish a connection on port 80?
data:image/s3,"s3://crabby-images/e7e04/e7e04cdd4e72cd4f584a1af343823f2de8ffc5e1" alt=""
192.168.182.128
5.2. Using the plugin “windows.netscan,” can you identify the program (owner) used to access through port 80?
data:image/s3,"s3://crabby-images/8f6dd/8f6dd5abac6134ebf4f893738add29a20950e684" alt=""
msedge.exe
5.3. Analyzing the process present on the dump, what is the PID of the child process of critical_updat?
data:image/s3,"s3://crabby-images/13bd9/13bd9344a991ce9bef67fcd3276b611a2478eead" alt=""
1612
5.4. What is the time stamp time for the process with the truncated name critical_updat?
data:image/s3,"s3://crabby-images/642a8/642a8c5e1ecf929dbb575c5305e6804fb8ded748" alt=""
2024-02-24 22:51:50.000000
Task 6: Finding Interesting Data
6.1. Analyzing the “windows.filescan” output, what is the full path and name for critical_updat?
data:image/s3,"s3://crabby-images/9de75/9de752f1236f0eaf236cda0a128d91c72bcbfef2" alt=""
data:image/s3,"s3://crabby-images/fcf78/fcf789d49ecabfa3274d19ee534dd23bc06108fc" alt=""
\Users\user01\Documents\critical_update.exe
6.2. Analyzing the “windows.mftscan.MFTScan” what is the Timestamp for the created date of important_document.pdf?
data:image/s3,"s3://crabby-images/52f81/52f81051964c318502d3d8eb2860d3ed51f46c07" alt=""
2024-02-24 20:39:42.000000
6.3. Analyzing the updater.exe memory output, can you observe the HTTP request and determine the server used by the attacker?
SimpleHTTP/0.6 Python/3.10.4