Sunday, July 24, 2022

Digital Forensics: TryHackMe Forensics writeup.

Digital Forensics: TryHackMe Forensics writeup.

This challenge is based on Memory Forensics
This is a memory dump of compromised system, do some forensics kung-fu to explore the inside.
This is a memory dump of compromised system, do some forensics kung-fu to explore the inside.
Task 1: Information gather
TryHackMe Room Forensics writeup.

#volatility imageinfo -f Desktop/victim.raw 
TryHackMe Memory Forensics writeup.
Looking for ‘SearchIndexer’ PID 
#volatility -f Desktop/victim.raw  --profile=Win7SP1x64 pslist | grep SearchIndexer
TryHackMe Memory Forensics writeup.

This information is stored by Windows using two registry keys called ShellBags.
#volatility -f victim.raw --profile=Win7SP1x64 shellbags
TryHackMe Memory Forensics writeup.
Last accessed directory
The ‘deleted_file’ is the last directory accessed by the user.
TryHackMe Memory Forensics writeup.

Task 2: Search for malicious processes
TryHackMe Room Forensics writeup.

Let ‘s scan the open port using the following command
First we need to find a suspicious open port. Use netscan to find out open ports:
#volatility -f Desktop/victim.raw --profile=Win7SP1x64 netscan

TryHackMe Memory Forensics writeup.
PID  1368,2464  with multiple ports which look suspicious
TryHackMe Memory Forensics writeup.

TryHackMe Memory Forensics writeup.

How about dump the process and check with Virus total?
1820.dmp   1820 shows malicious sign. 2 security vendors and no sandboxes flagged this file as malicious

How about dump the process and check with Virus total

How about dump the process and check with Virus total


Task 3: Indicators of compromise (IOC)
TryHackMe Room Forensics writeup.

We can dump the memory using the following command.
#volatility -f victim.raw -p <malicious PID> --profile=Win7SP1x64 memdump <Directory to save the file>
TryHackMe Memory Forensics writeup.

TryHackMe Memory Forensics writeup.

# strings Desktop/malware/1820.dmp | grep '\<www\.go....\.ru\>'
TryHackMe Memory Forensics writeup.

# strings Desktop/malware/1820.dmp | grep '\<www\.i....\.com\>'
TryHackMe Room Forensics writeup.

# strings Desktop/malware/1820.dmp | grep '\<www\.ic......\.com\>'
TryHackMe Memory Forensics writeup.

# strings Desktop/malware/1820.dmp | grep '\<202\....\.233\....\>'
TryHackMe Room Forensics writeup.

# strings Desktop/malware/1820.dmp | grep '\<...\.200\...\.164\>'
TryHackMe Memory Forensics writeup.

# strings Desktop/malware/1820.dmp | grep '\<209\.190\....\....\>'
TryHackMe Room Forensics writeup.

To check with the environment variable from the memory image
#volatility Desktop/victim.raw -p 2464 --profile=Win7SP1x64 envars

TryHackMe Room Forensics writeup.

You've completed the room! 
TryHackMe Memory Forensics writeup.



อ่านเพิ่ม Memory Forensics


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น


* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics
#digitalforensics #investigation #cybercrime #fraud

Tuesday, July 12, 2022

DIGITAL FORENSICS:CCTV Forensics Disk-to-Disk (clone) duplication

DIGITAL FORENSICS:CCTV Forensics  Disk-to-Disk (clone) duplication

·         Dissembling HD from CCTV machine and Duplicate to the Blank HD by TD2 

CCTV Forensics  Disk-to-Disk (clone) duplication


Tableau Forensic Duplicator Disk-to-Disk (clone)

CCTV Forensics  Disk-to-Disk (clone) duplication



Disk-to-Disk (clone) save log


·      Save Log for Hash and none errors confirmation. 


--- The scenario shows that we can use this method to clone the source and then acquire the hash log for integrity purposes. -- --- Hence, following the practice above, we can extract the video content from CCTV evidence. However, it is essential to gain requirements from the client because it helps to shorten the process. -- --- If we can bring the CCTV machine along with the evidence source, we can produce a potential result. --

CCTV Forensics  Disk-to-Disk (clone) duplication

·         Put the Blank HD into CCTV machine and check, the result has shown that it can replay and record accordingly.

CCTV Forensics  Disk-to-Disk (clone) duplication

CCTV Forensics  Disk-to-Disk (clone) duplication

--- The scenario shows that we can use this method to clone the source and then acquire the hash log for integrity purposes. --


--- Hence, following the practice above, we can extract the video content from CCTV evidence. However, it is essential to gain requirements from the client because it helps to shorten the process. --
--- If we can bring the CCTV machine along with the evidence source, we can produce a potential result. --


อ่านเพิ่มเติม  Tableau Forensic Duplicator.

Credit: Examiner Opal (Digital Forensic Technician)

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 

Saturday, July 2, 2022

Digital Forensics:การเก็บพยานหลักฐานทางดิจิทัล (Digital Evidence Collection)

Digital Forensics:การเก็บพยานหลักฐานทางดิจิทัล (Digital Evidence Collection)

การเก็บพยานหลักฐานพยานหลักฐานทางดิจิทัลอื่นๆ

การเก็บพยานหลักฐานพยานหลักฐานทางดิจิทัลอื่นๆ

ข้อแนะนำเกี่ยวกับการนำส่งพยานหลักฐานเพื่อตรวจพิสูจน์

ข้อแนะนำเกี่ยวกับการนำส่งพยานหลักฐานเพื่อตรวจพิสูจน์

ตัวอย่างประเด็นคำถามในการตรวจพิสูจน์พยานหลักฐานทางดิจิทัล 

  • มีไฟล์ภาพ รูปถ่าย หรือไฟล์วิดีโอที่มีลักษณะลามกอนาจาร/ลามกอนาจารตรงตาม ไฟล์ภาพหรือไฟล์วิดีโอที่ส่งมาด้วยนี้ ในวัตถุพยานหรือไม่ (อาจระบุค่าแฮซ (HashValue) ที่ต้องการ หรือภาพประกอบมาด้วย)
  • มีไฟล์ภาพ การทำธุรกรรมทางการเงินในวัตถุพยานหรือไม่
  • มีไฟล์ประเภท doc(x), xls(x), pdf ในวัตถุพยานหรือไม่
  • มีไฟล์ที่ที่ปรากฏข้อความ “…” ในวัตถุพยานหรือไม่ (ระบุคำสำคัญที่ต้องการ)
  • มีไฟล์ที่มีค่า Hash ตรงตามรายการที่ส่งมาด้วยนี้หรือไม่
  • มีประวัติการเข้าถึงเว็บไซต์ ในวัตถุพยานหรือไม่ (ควรระบุ URLs หรือวันเวลาที่ต้องการ)
  • มีประวัติการสนทนาผ่านโปรแกรม Messenger หรือ LINE หรือไม่ (อาจระบุชื่อที่ต้องการ)
  • ข้อมูลการรับ-ส่งอีเมล ในวัตถุพยาน (อาจระบุชื่อผู้รับ-ส่ง หรือ ชื่ออีเมลที่ต้องการ)
  • มีข้อมูลรายชื่อและเบอร์โทรศัพท์ในวัตถุพยานหรือไม่ (อาจระบุชื่อบุคคล หรือ เบอร์โทรศัพท์ที่ต้องการ)
  • มีข้อมูลการโทรศัพท์ของวัตถุพยานหรือไม่ ข้อมูล การรับส่งข้อความสั้น (SMS) หรือ ข้อความสื่อผสม (MMS) ในวัตถุพยาน (อาจระบุชื่อบุคคล หรือ เบอร์โทรศัพท์ที่ต้องการ)
  • สามารถกู้คืนไฟล์วิดีโอจากของกลางได้หรือไม่ (อาจระบุวันที่ เวลาที่ต้องการ)

การเก็บพยานหลักฐานจากเครื่องคอมพิวเตอร์


คอมพิวเตอร์ทำงานอยู่และหน้าจอเปิดใช้งานอยู่

คอมพิวเตอร์ทำงานอยู่แต่หน้าจอถูกปิด

ควรจัดเก็บสายต่อหรืออุปกรณ์ต่อพ่วงมาด้วย

  • ระบุรายละเอียดในเอกสารลำดับการครอบครองวัตถุพยาน
  • เอกสารข้อมูลและลำดับการครอบครองวัตถุพยาน
  • โดยบันทึกข้อมูลให้ครบถ้วน

การเก็บพยานหลักฐานจากโทรศัพท์

โทรศัพท์เปิดใช้งานอยู่ และสามารถเข้าใช้งานได้

โทรศัพท์เปิดใช้งานอยู่ แต่ติดล็อครหัสผ่าน

ห้ามถอดแบตเตอรี่ออกจากตัวเครื่อง

  •  ระบุรายละเอียดในเอกสารลำดับการครอบครองวัตถุพยาน
  • เอกสารข้อมูลและลำดับการครอบครองวัตถุพยาน
  • โดยบันทึกข้อมูลให้ครบถ้วน

Credit: 29 มิถุนายน 2565 ,กองคุ้มครองแรงงานนอกระบบ, คู่มือการดำเนินคดี สำหรับคดีแรงงานเด็กและแรงงานบังคับ


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น ช่วยเตือนความจำ

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 

Thursday, June 30, 2022

DIGITAL FORENSICS:FILE HASH CHECK WITH VIRUSTOTAL

DIGITAL FORENSICS:File Hash Check with VirusTotal

How to install Didier Stevens “virustotal-search.py” script

วันนี่มาตรวจสอบ malware โดยไฟล์แฮช (malware hash list) จำนวนมากด้วย VirusTotal คุณจะต้องใช้คีย์ VirusTotal API มีเครื่องมือมากมาย แต่ถ้าคุณต้องการใช้เครื่องมือที่จะนำเข้าคีย์ API จากบัญชีของคุณ ตรวจสอบให้แน่ใจว่าเครื่องมือนี้ได้  Didier Stevens “virustotal-search.py” script

ขั้นแรกคุณต้องมี Python

1. Download latest version of Python 3
2. Install it – check usage for PATH environment variable and for easier future updates install to the root of your C: drive. Example for Python 3.10:

C:\Python310\
FILE HASH CHECK WITH VIRUSTOTAL

และ Download virustotal-search.py

FILE HASH CHECK WITH VIRUSTOTAL

3. Navigate to Didier Stevens virustotal-search.py Github page

4. On top of the page Right Click the [Raw] button and [Save link as]. Save the file in the place that you will find it later, for example:

C:\tools\virustotal-search\virustotal-search.py
FILE HASH CHECK WITH VIRUSTOTAL

5. Sign up for VirusTotal for free.
6. After you login to VT, click your profile button, then [API Key]. Copy this API key so you can use it later, maybe save to text file.
* Free VirusTotal Public API key can be used for 4 hash requests per minute and 500 hashes per day. Same goes for the script itself, it will not send more than 4 requests per minute. It was scripted that way and if you have a premium account with bigger quota, the script will still send 4 requests per minute. Keep that in mind. After your reach your daily quota of 500 requests with free account – VT will send you an email and the script will fail to send new requests until the next day.

How to use Didier Stevens “virustotal-search.py” script to bulk file hash check with VirusTotal

* This guide is for virustotal-search.py script version 1.1.6 and above, which uses python 3. If you want to use older versions for python 2 you will need also to install “poster” package with command: pip install poster.

ทำการเตรียม Hash list ที่เราเตรียมไว้ หรือท่านสามารถเอาตัวอย่างจาก  virusshare

FILE HASH CHECK WITH VIRUSTOTAL

1. Save all your file hashes to text file, example path:

C:\tools\virustotal-search\VirusShare.txt

2. Command line usage example:

virustotal-search.py List.txt -k <YourAPIKey> -s , -o Output.csv
virustotal-search

Example with full paths from above:

"C:\tools\virustotal-search\virustotal-search.py" "C:\tools\virustotal-search\VirusShare.txt" -k <YourAPIKey> -s , -o "C:\tools\virustotal-search\Output.csv"

Command line Example if you did not select PATH variable usage and need to specify path to “python.exe”:

"C:\Python39\python.exe" "C:\tools\virustotal-search\virustotal-search.py" "C:\tools\virustotal-search\VirusShare.txt" -k <YourAPIKey> -s , -o "C:\tools\virustotal-search\Output.csv"

virustotal-search switches explanation

List.txt: The second argument for the script. Is any text file that holds the hash list.
-k: API key.
-s ,: Separator character between the columns. “,” (comma) is the character that is used in this case for regular CSV (comma separated values) document. The default setting without the “-s” switch is “;” (semicolon).
-o: Output csv file.

For help and more settings / switches you can use the -h switch.

FILE HASH CHECK WITH VIRUSTOTAL

virusshare lists of MD5 hashes

FILE HASH CHECK WITH VIRUSTOTAL


Output csv file.

FILE HASH CHECK WITH VIRUSTOTAL

FILE HASH CHECK WITH VIRUSTOTAL
สรุป
  •  ท่านสามารถ scan virus  หลายไฟล์พร้อมกัน โดยการสร้างค่า hash  list ไป scan โดยใช้ เครื่องมือจาก Virustotal ได้
 
อ่านเพิ่มเติม: vtlookup

Reference

Bulk File Hash Check with VirusTotal – Didier Stevens script



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #computerforensic #ComputerForensics #dfir #forensics
#digitalforensics #investigation #cybercrime #fraud

Friday, June 10, 2022

INCIDENT INVESTIGATIONS WITH BELKASOFT: TRAINING COURSE

INCIDENT INVESTIGATIONS WITH BELKASOFT: TRAINING COURSE

หลักสูตรอบรมการสอบสวนเหตุการณ์ในสภาพแวดล้อมบนระบบปฏิบัติการวินโดวส์


หลักสูตรนี้ออกแบบมาสำหรับผู้ที่มีประสบการณ์ใน DFIR แล้ว และต้องการยกระดับความรู้และรับประสบการณ์ตรงในการใช้ผลิตภัณฑ์ Belkasoft เพื่อแก้ไขกรณีสอบสวนเหตุการณ์ในสภาพแวดล้อม Windows

The course is designed for those who already have experience in DFIR and would like to level up their knowledge and gain hands-on experience in using Belkasoft products for solving an incident investigation case in the Windows environment.

INCIDENT INVESTIGATIONS WITH BELKASOFT:

How to activate your trial license.


Watch a short tutorial video on how to create a case.

Watch a short tutorial video on how to add a data source

Watch a short tutorial video on how to use mini-timeline, global, and local filters

Cyber Kill Chain and Belkasoft Incident Investigation Model


Cyber Kill Chain model by Lockheed Martin
Cyber Kill Chain model by Lockheed Martin

What is Belkasoft N and how to try it.


Check what incident response artifacts are supported by Belkasoft
incident response artifacts


 Watch a short video to learn more about uncovering persistence mechanisms

Watch a short video to learn more about execution traces


Watch a video where incident investigation case is reviewed and hints are provided


incident investigation certificate
INCIDENT INVESTIGATION CERTIFICATE


ที่มา: BELKASOFT.COM


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud 

Data Breach Check

Data Breach Check Data Breach Check EP.4 “คิด ก่อน Prompt” AI อาจช่วยคุณทำงานได้เร็วขึ้น แต่บางครั้ง…ข้อมูลสำคัญก็อาจ “หลุดออกไป” โดยไม่รู้...