Saturday, March 28, 2020

DIGITAL FORENSICS:Investigation using OSForensics

DIGITAL FORENSICS: Investigation using OSForensics (Part1)

 

Step 1 - Download USB Drive Images

In this task, you will download the USB drive images from a local intranet site.
These USB drive images were collected from digitalcorpora.org web site.
Right-click USB zip file and select Extract All

Step 2

Click Start charm to access the Start screen.
When Start screen opens, type: OSforensics  On the OSForensics welcome message box, click Continue Using Free Version.
DIGITAL FORENSICS:Investigation using OSForensics
OSForensics

Step 3

In the New Case dialog box, enter your name in the Investigator text box. In the Case Name text box, type CF-DFE-002 USB drive.
Investigation using OSForensics

Investigation using OSForensics
CF-DFE-002

Step4

Click the Add Device button to open the “Select device to add” dialog box, and then click the Image File option button. Click the browse button, navigate to the folder you copied images to, and click  work-usb-2009-12-11.E01. Click Open.

Investigation using OSForensics
Image File
Investigation using OSForensics
work-usb-2009-12-11.E01

Step 5

Click the  work-usb-2009-12-11.E01 filename at the lower right, and then click the Open button to the left to open the File System Browser window.


Investigation using OSForensics

Step 6

In the Select a partition in the image dialog box asking which partition to use, leave the default setting use entire image file, and then click OK.


Step 7

Click the File Name Search icon in the File System Browser window or the left pane of the main window. In the Search String text box, type Charlie*. On the far right, click the Search button.

 
Investigation using OSForensics
File Name Search

Step 8

On the Browse for Folder dialog box, ensure that Devices in case refers to  work-usb-2009-12-11.
Click OK. Back on File Name Search window, click Search.

Investigation using OSForensics

 

Step 9

After a few moments a list of files found in USB drive is displayed.
Investigation using OSForensics

Step 10

The files displayed in Thumbnails view.
Click Timeline tab.

Investigation using OSForensics
Timeline

Create Index

To create an index of files found in the user’s USB drive image, perform the following steps:

Step 11

Click the Create Index button in the left pane. (Note: You might have to click New Index if the window is showing the results from the index of  USB drive.) In the Step  click the Pre-determined File Types option button, click all the file types listed, and then click Next.

Investigation using OSForensics


Step 12

 click the Add button.

Step 13

On the Add Start Location dialog box, verify that Whole drive option is selected and  work-usb-2009-12-11.E01 is listed.
Click OK.
Investigation using OSForensics
Add Start Location

Step 14

In the Step 3 of 5 window, in the Index Title text box, type: All File Type
Click Start Indexing.

Investigation using OSForensics

Index Title

Step 15

When the indexing is finished, click OK in the message box informing you that some errors might have occurred in the indexing process.

 
Investigation using OSForensics

Step 16

The window that opens shows you the files that were indexed, any errors that occurred, and a summary of what was done. After examining the summary, close the window.
Investigation using OSForensics
Investigation using OSForensics

You should now be able to create a case, add it to your inventory, scan the files, and perform indexing, which will be useful later for searching.   

Case Management: Cases are used to group together findings within OSForensics that can be exported or saved for later analysis.

 

ref:

osforensics

hackingarticles

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

 

Thursday, March 26, 2020

DIGITAL FORENSICS: CertMaster Learn for IT Fundamentals (ITF+) free

DIGITAL FORENSICS: CertMaster Learn for IT Fundamentals (ITF+)

free

 

To access the free CompTIA CertMaster Learn for IT Fundamentals (ITF+) course visit 

https://certs.comptia.org/means_more/

 


Lesson 1: Common Computing Device

CertMaster Learn for IT Fundamentals (ITF+)

CompTIA IT Fundamentals

Welcome to CompTIA CertMaster Learn for IT Fundamentals+!


  1. Go to the CompTIA CertMaster Learn Registration Page.
  2. Enter the access code and click continue.
  3. If you have previously used CertMaster Learn or CertMaster CE and have a user account, select Log In.  If you do not have a user account, enter Full Name, Email, and Password as directed. 
  4. Now that your access code has been redeemed, access the new course at any time from the CertMaster Learn Log-In page.







 หลักสูตรอบรมออนไลน์ 

 Ref:

https://learn.comptia.org


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Monday, March 16, 2020

DIGITAL FORENSICS:Network Evidence Collection.

DIGITAL FORENSICS:Network Evidence Collection.

Tools
- NetworkMiner_2-0
- Wireshark-win32-2.6.1
- Windows 7 forensic workstation

Evidence Collection.


In order to conduct a proper examination of log files and other network data such as packet

captures, they often have to be moved from the log source and examined offline. As with

any source of evidence, the log files or packet captures have to be handled with due care to

ensure that they are not corrupted or modified during the transfer. One simple solution is to

transfer the evidence immediately to a USB drive or similar removable medium. From
there, a hash can be created for the evidence prior to any examination

Wireshark can be used for capturing packets.
packet captures

The log entry captures the necessary information:

File Name: Each log file or packet capture should have its own unique name.
Within the procedures in use by the IR should be a naming convention for
different types of evidence files.
Description: A brief description of the file. There does not need to be too much
detail unless it is a unique file and a detailed description is called for.
Location: The location is important. In this case, the packet capture was obtained
on the switch located at 192.168.245.141
Date and time: Record the date and time the file was transferred to the medium.
Note: Prior to an incident, it is important to identify what type of time
zone will be in use. From an evidentiary standpoint, the time zone does
not really matter as long as it is consistent among the entire incident
investigation.
Collected by: Initials are sufficient for the log file.
MD5 hash:


packet captures "CF-Image01.pcap"

Source




Machine name : ForensicEx01
Hardware: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz (with SSE4.2)
OS: 32-bit Windows 7 Service Pack 1, build 7601
Application: Dumpcap (Wireshark) 2.6.1 (v2.6.1-0-g860a78b3)
IP: 192.168.245.141
Mac address: 00-0C-29-58-F1-EA

Time
First packet: 2012-10-27 03:19:42
Last packet: 2012-10-27 03:24:02
Elapsed: 00:04:20


Import CF-Image01.pcap



NetworkMiner 

extract image file


Summary
Packet captures provide details into the
exact nature of network traffic. Finally, analysts have to be prepared to acquire these
sources of evidence is a forensically sound manner. The next chapter will take the analyst
off the network into acquiring the volatile data from host based systems.


How to Install Network Miner Packet Analysis Tool



Ref:

Digital Forensic and Incident Reponse Gerard Johansen

https://www.netresec.com/

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Saturday, March 14, 2020

Digital Forensics: Encode

Digital Forensics: Encode

 
Spammimic
 Step 1 Encode as spam with a password

 Step 2 Insert short secret message and Encode
  Step 3
 Step 4 Copy message
 Step 5 Sent a message to Email

 Step 6 Paste in a encoded message to Decoded
Decode


Endcode with Passeord

Encoded


Decode



Encode as Fake PGP

Ref:
http://www.spammimic.com

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Thursday, March 12, 2020

DIGITAL FORENSICS:การดำเนินคดีและร่างฟ้อง กรณี ฟิชชิ่ง (Phishing)

DIGITAL FORENSICS:การดำเนินคดีและร่างฟ้อง กรณี ฟิชชิ่ง (Phishing)

 
ขออนุญาตแชร์เพื่อการศึกษา  Facebook ท่าน Pakorn Dharmaroj

 12 มีนาคม 2563
  การดำเนินคดีและร่างฟ้อง กรณี ฟิชชิ่ง (Phishing)


การดำเนินคดีและร่างฟ้อง กรณี ฟิชชิ่ง (Phishing) รหัสผ่าน (Password) บัญชีอินสตาแกรม (instagram.com) ของผู้เสียหาย + ใช้ชื่อและรหัสผ่าน ซึ่งเป็นบัตรอิเล็กทรอนิกส์ Hack instragram เข้าบัญชีผุ้เสียหาย + แล้วประกาศขายสินค้าฉ้อโกงประชาชนโดยแสดงตนเป็นคนอื่่น
 

การดำเนินคดีและร่างฟ้อง กรณี ฟิชชิ่ง (Phishing)


ข้อ 1. ก่อนและขณะเกิดเหตุคดีนี้ นางสาว ส. ผู้เสียหายที่ 1 เป็นผู้ใช้บริการเว็บไซต์ www.instagram.com หรือเรียกเป็นการทั่วไปว่า อินสตาแกรม หรือ IG ซึ่งผู้ให้บริการเว็บไซต์อินสตาแกรม (instagram.com) ให้บริการจัดเก็บข้อมูลภาพถ่ายและข้อความในรูปแบบข้อมูลคอมพิวเตอร์ สำหรับเผยแพร่แก่ประชาชนทั่วไป ด้วยระบบคอมพิวเตอร์ที่ใช้โปรแกรมประยุกต์ (Content and Application Service Provider) โดยเปิดให้บุคคลทั่วไปสามารถสมัครใช้งาน เป็นสมาชิก โดยการสร้างบัญชีผู้ใช้งาน สำหรับจัดเก็บข้อมูลภาพถ่ายและข้อความ เผยแพร่ให้ประชาชนทั่วไปสามารถเข้าถึงข้อมูลคอมพิวเตอร์ดังกล่าว เพื่อการโฆษณา ประชาสัมพันธ์ หรือเพื่อการอื่นใดตามความประสงค์ของผู้ใช้บริการ และเปิดให้ประชาชนทั่วไปเข้าถึงหรือเรียกดูข้อมูลคอมพิวเตอร์ที่จัดเก็บไว้สำหรับเผยแพร่ได้

การใช้บริการเว็บไซต์อินสตาแกรม (instagram.com) สำหรับจัดเก็บข้อมูลภาพถ่ายและข้อความ เพื่อเผยแพร่แก่ประชาชนทั่วไป ผู้สมัครใช้บริการรวมถึงผู้เสียหายที่ 1 จะทำการกรอกข้อมูลส่วนบุคคล รวมถึงชื่อบัญชีอีเมล (Electronic Mail Account หรือ ชื่อบัญชีผู้ใช้ไปรษณีย์อิเล็กทรอนิกส์) หรือหมายเลขโทรศัพท์ และข้อมูลอื่นตามที่ผู้ให้บริการกำหนด แล้วได้รับชื่อบัญชีผู้ใช้งาน (Username Account) พร้อมรหัสผ่าน (Password) สำหรับการเข้าใช้บริการของสมาชิกแต่ละราย โดยการเข้าใช้บริการเว็บไซต์อินสตาแกรม (instagram.com) แต่ละครั้ง สมาชิกผู้สมัครใช้บริการจะต้องกรอกข้อมูล ชื่อบัญชีอีเมล หรือหมายเลขโทรศัพท์ พร้อมรหัสผ่าน (Password) ตามที่ผู้ให้บริการเว็บไซต์อินสตาแกรม (instagram.com) กำหนด เพื่อเข้าใช้บริการแก้ไข เพิ่มเติม ข้อมูลภาพถ่ายและข้อความในรูปแบบข้อมูลคอมพิวเตอร์ ในบัญชีผู้ใช้งาน (Username Account) ของตนได้ โดยผู้เสียหายที่ 1 ใช้ชื่อบัญชีอีเมล fxxx@gmail.com และหมายเลขโทรศัพท์ 098 496 xxxx ในการสมัครสมาชิกและใช้ในการระบุตัวตน (Identification) และพิสูจน์ตัวตน (Authentication) ในการเข้าใช้บริการ และใช้ชื่อบัญชีผู้ใช้งาน (Username Account) เว็บไซต์อินสตาแกรม (instagram.com) ว่า fahxxxxx

ทั้งนี้ การใช้ชื่อบัญชีอีเมล fxxx@gmail.com หรือหมายเลขโทรศัพท์ 098 496 xxxx และรหัสผ่าน (Password) ในการระบุตัวตน (Identification) และพิสูจน์ตัวตน (Authentication) ของสมาชิก เพื่อเข้าใช้บริการเว็บไซต์อินสตาแกรม (instagram.com) ถือเป็น ข้อมูล รหัส หมายเลขบัญชี หมายเลขชุดทางอิเล็กทรอนิกส์ หรือเครื่องมือทางตัวเลขใด ๆ ที่ผู้ให้บริการเว็บไซต์อินสตาแกรม (instagram.com) ผู้ออกได้ออกให้แก่ผู้เสียหายที่ 1 เป็นผู้มีสิทธิใช้ โดยมิได้มีการออกเอกสาร หรือวัตถุอื่นใดให้ และมีวิธีการใช้เพื่อแสดงตัวตนและพิสูจน์ตัวตนด้วยวิธีการทางอิเล็กทรอนิกส์ เช่นเดียวกับบัตรอิเล็กทรอนิกส์ที่มีการบันทึกข้อมูลลงในแถบแม่เหล็ก หรือไมโครชิป ซึ่งถือเป็นบัตรอิเล็กทรอนิกส์ประเภทที่ระบุไว้ในประมวลกฎหมายอาญา มาตรา 1 (14) (ข) ด้วย

  
ข้อ 2. จำเลยนี้ได้บังอาจกระทำผิดต่อกฎหมายเป็นความผิดหลายกรรมต่างกัน ดังนี้
2.1 เมื่อวันที่ 13 ธันวาคม 2562 เวลากลางวันและกลางคืนหลังเที่ยงต่อเนื่องกัน เวลาใดไม่ปรากฏชัด จำเลยนี้โดยทุจริตและโดยหลอกลวง ได้บังอาจใช้อุบายในลักษณะที่เรียกว่า ฟิชชิ่ง (Phi
shing) หลอกให้ผู้เสียหายที่ 1 กรอกข้อมูลในการระบุตัวตน (Identification) และพิสูจน์ตัวตน (Authentication) ของสมาชิก เพื่อเข้าใช้บริการเว็บไซต์อินสตาแกรม (instagram.com) ในช่องทางที่จำเลยกำหนด เพื่อให้จำเลยได้รับข้อมูลดังกล่าวของผู้เสียหายสำหรับนำไปใช้กระทำผิดต่อไป ด้วยการนำเข้าสู่ระบบคอมพิวเตอร์ ซึ่งข้อมูลคอมพิวเตอร์ปลอม และข้อมูลคอมพิวเตอร์อันเป็นเท็จ สร้างเป็นหน้าเว็บไซต์ (Web Page) ปลอม สำหรับกรอกข้อมูลชื่อบัญชีอีเมล หรือหมายเลขโทรศัพท์ พร้อมรหัสผ่าน (Password) ในการเข้าใช้บริการเว็บไซต์อินสตาแกรม (instagram.com) ส่งไปยังผู้เสียหายที่ 1 โดยประการที่น่าจะเกิดความเสียหายแก่ผู้เสียหายที่ 1 อันมิใช่การกระทำความผิดฐานหมิ่นประมาทตามประมวลกฎหมายอาญา และโดยการหลอกลวงดังว่านั้น เป็นเหตุให้ผู้เสียหายที่ 1 หลงเชื่อ กรอกข้อมูลชื่อบัญชีอีเมล หรือหมายเลขโทรศัพท์ พร้อมรหัสผ่าน (Password) ของผู้เสียหายที่ 1 ในการเข้าใช้บริการเว็บไซต์อินสตาแกรม (instagram.com) ลงในหน้าเว็บไซต์ (Web Page) ที่จำเลยทำปลอมขึ้น และจำเลยได้รับข้อมูลของผู้เสียหายที่ 1 ไป
(ส่วนนี้เป็นความผิดตาม พรบ.คอมพิวเตอร์ มาตรา 14 (1) ประกอบวรรคท้าย)


2.2 ต่อมาเมื่อวันที่ 13 ธันวาคม 2562 เวลากลางคืนหลังเที่ยง ถึงวันที่ 14 ธันวาคม 2562 เวลากลางวัน ต่อเนื่องกัน ภายหลังจากที่จำเลยได้กระทำความผิดดังกล่าวในวรรคก่อน จำเลยได้บังอาจใช้ชื่อบัญชีอีเมล หรือหมายเลขโทรศัพท์ พร้อมรหัสผ่าน (Password) ของผู้เสียหายที่ 1 ในการเข้าใช้บริการเว็บไซต์อินสตาแกรม (instagram.com) อันเป็นบัตรอิเล็กทรอนิกส์ของผู้ให้บริการเว็บไซต์อินสตาแกรม (instagram.com) ที่ออกให้แก่ผู้เสียหายที่ 1 เป็นผู้มีสิทธิใช้ โดยมิชอบ ในประการที่น่าจะก่อให้เกิดความเสียหายแก่ผู้ให้บริการเว็บไซต์อินสตาแกรม (instagram.com) และผู้เสียหายที่ 1 ทำการเข้าถึงข้อมูลคอมพิวเตอร์ในบัญชีผู้ใช้งาน (Username Account) เว็บไซต์อินสตาแกรม (instagram.com) ชื่อ fahxxxxx ของผู้เสียหายที่ 1 แล้วได้บังอาจแก้ไข เปลี่ยนแปลง หรือเพิ่มเติมไม่ว่าทั้งหมดหรือบางส่วน ซึ่งข้อมูลคอมพิวเตอร์ของผู้ให้บริการเว็บไซต์อินสตาแกรม (instagram.com) และผู้เสียหายที่ 1 โดยมิชอบ โดยทำการเปลี่ยนแปลงข้อมูลคอมพิวเตอร์ ในส่วนของหมายเลขโทรศัพท์ 098 496 xxxx ของผู้เสียหายที่ 1 เป็นหมายเลข 064 348 xxxx แล้วเปลี่ยนเป็นหมายเลข 090 979 xxxx และทำการเปลี่ยนแปลงข้อมูลคอมพิวเตอร์ ในส่วนของใช้ชื่อบัญชีผู้ใช้งาน (Username Account) เว็บไซต์อินสตาแกรม (instagram.com) ชื่อ fahxxxxx ของผู้เสียหายที่ 1 เป็น fahsxxxx แต่ยังคงใช้ภาพถ่ายและข้อมูลส่วนตัวของผู้เสียหายที่ 1 สำหรับใช้หลอกลวงให้ประชาชนทั่วไป
(ส่วนนี้เป็นความผิดตาม พรบ.คอมพิวเตอร์ มาตรา 9 ประมวลกฎหมายอาญา มาตรา 269/5)

 
2.3 ต่อมาภายหลังกระทำความผิดดังกล่าวในคำฟ้องข้อ 2.2 จำเลยนี้โดยทุจริตและโดยหลอกลวง ได้บังอาจฉ้อโกงประชาชนโดยการแสดงตนเป็นผู้เสียหายที่ 1 ด้วยการนำเข้าสู่ระบบคอมพิวเตอร์ ของเว็บไซต์อินสตาแกรม (instagram.com) ในบัญชีผู้ใช้งาน (Username Account) ของผู้เสียหายที่ 1 และการแสดงข้อความอันเป็นเท็จในรูปแบบของข้อมูลคอมพิวเตอร์ปลอม และข้อมูลคอมพิวเตอร์อันเป็นเท็จ ประกาศขายโทรศัพท์เคลื่อนที่ (Mobile Phone) ในราคาถูก ให้ประชาชนทั่วไปสามารถพบเห็นข้อความหรือเข้าถึงข้อมูลคอมพิวเตอร์ดังกล่าวโดยให้ประชาชนเห็นว่าผู้เสียหายที่ 1 เป็นผู้แสดงข้อความอันเป็นเท็จได้ ทั้งที่ความจริงแล้ว จำเลยไม่มีเจตนาผูกนิติสัมพันธ์กับประชาชนที่หลงเชื่อสั่งซื้อสินค้า และไม่มีเจตนาที่จะส่งมอบสินค้าโทรศัพท์เคลื่อนที่ (Mobile Phone) ตามที่ได้ประกาศชักชวนโฆษณาไว้ แต่เป็นเพียงอุบายในการหลอกลวงให้ได้เงินจากประชาชนที่หลงเชื่อสั่งซื้อสินค้า โดยไม่จำกัดจำนวนคนและจำนวนเงิน ทั้งนี้ จำเลยได้นำเข้าสู่ระบบคอมพิวเตอร์ ซึ่งข้อมูลคอมพิวเตอร์ปลอมและข้อมูลคอมพิวเตอร์อันเป็นเท็จดังกล่าว โดยประการที่น่าจะเกิดความเสียหายแก่ผู้ให้บริการเว็บไซต์อินสตาแกรม (instagram.com) ผู้เสียหายที่ 1 และประชาชน อันมิใช่การกระทำความผิดฐานหมิ่นประมาท และโดยการหลอกลวงดังว่านั้น เป็นเหตุให้มีประชาชนหลงเชื่อ โอนเงินให้แก่จำเลยได้รับไปโดยทุจริต ได้แก่

เมื่อวันที่ 14 ธันวาคม 2562 เวลาใดไม่ปรากฏชัด นางสาว ช. ผู้เสียหายที่ 2 ใช้บัญชีผู้ใช้งาน (Username Account) เว็บไซต์อินสตาแกรม (instagram.com) ชื่อ j xxxx หลงเชื่อตามประกาศดังกล่าว โอนเงินค่าสั่งซื้อโทรศัพท์เคลื่อนที่ จำนวนเงิน 5,000 บาท เข้าบัญชีทรูวอลเลทหมายเลขโทรศัพท์ 090-979- xxxx ชื่อเจ้าของบัญชี นางสาว ธ. ให้จำเลยได้รับไปโดยทุจริต
เมื่อวันที่ 14 ธันวาคม 2562 เวลาใดไม่ปรากฏชัด นาย น. ผู้เสียหายที่ 3 ใช้บัญชีผู้ใช้งาน (Username Account) เว็บไซต์อินสตาแกรม (instagram.com) ชื่อ a xxxx หลงเชื่อตามประกาศดังกล่าว โอนเงินค่าสั่งซื้อโทรศัพท์เคลื่อนที่ จำนวนเงิน 14,000 บาท เข้าบัญชีทรูวอลเลทหมายเลขโทรศัพท์ 090-979- xxxx ชื่อเจ้าของบัญชี นางสาว ธ. ให้จำเลยได้รับไปโดยทุจริต
เมื่อวันที่ 14 ธันวาคม 2562 เวลาใดไม่ปรากฏชัด นางสาวอินธิรา เจริญทรัพย์ ผู้เสียหายที่ 4 ใช้บัญชีผู้ใช้งาน (Username Account) เว็บไซต์อินสตาแกรม (instagram.com) ชื่อ T xxxx หลงเชื่อตามประกาศดังกล่าว โอนเงินค่าสั่งซื้อโทรศัพท์เคลื่อนที่ จำนวนเงิน 11,000 บาท เข้าบัญชีทรูวอลเลทหมายเลขโทรศัพท์ 090-979- xxxx ชื่อเจ้าของบัญชี นางสาว ธ. ให้จำเลยได้รับไปโดยทุจริต

(ส่วนนี้เป็นความผิดตาม พรบ.คอมพิวเตอร์ มาตรา 14 (1) ประมวลกฎหมายอาญา มาตรา 341, 343)

เหตุตามคำฟ้องคดีนี้ เกิดที่ตำบล ... ตำบล... อำเภอเมือง จังหวัด ... และอีกหลายท้องที่ในประเทศไทยที่ประชาชนสามารถพบเห็นประกาศขายสินค้าอันเป็นวิธีการที่จำเลยใช้ฉ้อโกง เกี่ยวพันกัน



ที่มา Facebook ท่าน Pakorn Dharmaroj

 12 มีนาคม 2563  การดำเนินคดีและร่างฟ้อง กรณี ฟิชชิ่ง (Phishing) 


 
หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ


#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics

#computerforensic #investigation #cybercrime #fraud

Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...