Saturday, June 13, 2020

DIGITAL FORENSICS:Hack the Box - MarketDump

DIGITAL FORENSICS:Hack the Box - MarketDump

Forensics Challenges

ทำการสมัครสมาชิก  https://www.hackthebox.eu/
 เลือกหัวข้อ  MarketDump

We have got informed that a hacker managed to get into our internal network after pivoiting through the web platform that runs in public internet. He managed to bypass our small product stocks logging platform and then he got our costumer database file. We believe that only one of our costumers was targeted. Can you find out who the customer was?

 เราได้รับแจ้งว่า hacker สามารถเข้าไปในเครือข่ายภายในของเราหลังจากผ่านแพลตฟอร์มเว็บที่ทำงานในอินเทอร์เน็ต  เขาจัดการเพื่อข้ามแพลตฟอร์มการบันทึกสต็อคผลิตภัณฑ์ขนาดเล็กของเราจากนั้นเขาได้รับไฟล์ฐานข้อมูลลูกค้าของเรา เราเชื่อว่ามีลูกค้าเป้าหมายเพียงรายเดียวเท่านั้น คุณจะรู้ว่าลูกค้าเป็นใคร?

Step 1. ทำการ download ไฟล์ MarketDump.zip  และแตกไฟล์

Step 2. ได้ไฟล์  MarketDump.pcapng  ใช้โปรแกรม wireshark

Step 3.  เลือกคำสั่ง Follow TCP Stream
ตรวจสอบ Stream 1055    nc.traditional -lvp 9999



  Step 4. ตรวจสอบไปจนถึง  Stream 1056
 CardNumber , American Express
  Step 5. ตรวจสอบหมายเลขบัตรเครดิต ท้้งหมด
 Step 6. นำข้อมูลที่ได้ ไปแปลงค่าโดยใช้  Use CyberChef Magic  decode the flag.



Ref:

Thedigitalforensics



หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

Thursday, June 11, 2020

DIGITAL FORENSICS:$USNJRNL

DIGITAL FORENSICS:$USNJRNL

$UsnJrnl เป็นไฟล์ที่บันทึกเมื่อมีการเปลี่ยนแปลงไฟล์และไดเรกทอรี  เป็นคุณลักษณะของระบบไฟล์ Windows  (NT file system (NTFS) ซึ่งเก็บบันทึกการเปลี่ยนแปลงที่เกิดขึ้นกับ volume   ข้อมูลนี้มีประโยชน์ในการระบุไฟล์ที่สงสัย (เช่นมัลแวร์) ที่มีอยู่ในระบบไฟล์หรือ $ MFT 

Introduction
The NTFS change journal ($UsnJrnl) is an operating system file that records when changes are made to files and directories. The change journal is located at $Extend\$UsnJrnl. The journal contains two alternate data streams:
 $UsnJrnl:$J - Contains the actual journal entries
 $UsnJrnl:$MAX - contains metadata about the $UsnJrnl

The $UsnJrnl:$J contains useful information for the forensic investigator as detailed below:

 File/directory name
 File/directory attributes
 USN Reason
 Time of activity
 USN reference number
 MFT reference number
 MFT parent reference number
 Security ID

 Source info

ทดสอบวิเคราะห์ข้อมูลใน $UsnJrnl
- Re-loader Activator
- OSForensics
- NTFS Journal Viewer
- Virus total 
- Windows Defender

 Step 1. ทำการ Re-loader Activator เพื่อ activate windows
Step 2. กด Activate  และวิเคราะห์ดูว่ามีเหตุการณ์อะไรขึ้นบน Windows
Step 3. ใช้ Windows defender scan พบว่า KMS-R@1nHook.exe เป็นมัลแวร์ ติดตั้งอยู่ใน Windows
 Step 4. นำไฟล์ KMS-R@1nHook.exe  upload ไปที่เว็บ Virus-total  เพื่อความแน่ใจว่าพบมัลแวร์


Step 5. ใช้โปรแกรม  OSForensics 7.1 > $UsnJrnl Viewer 

OSForensics™ includes an $UsnJrnl viewer that parses and displays the log records stored in the NTFS $UsnJrnl volume change journal. This information is useful for identifying suspect files (eg. malware) that no longer exist in the file system or $MFT. The USN journal is updated whenever changes to files and directories are made to a volume including:

OSForensics รวมเครื่องมือสำหรับวิเคราะห์ไฟล์ $UsnJrnl ที่แสดงบันทึกที่จัดเก็บไว้ใน การเปลี่ยนแปลง volume ของ NTFS $UsnJrnl ข้อมูลนี้มีประโยชน์ในการระบุไฟล์ที่สงสัย (เช่นมัลแวร์) ที่ไม่มีอยู่ในระบบไฟล์หรือ $ MFT      USN ได้รับการปรับปรุงทุกครั้งที่มีการเปลี่ยนแปลงไฟล์และไดเรกทอรีที่ทำกับไดรฟ์รวมถึง:



Step 6. ค้นหา  KMS-R@1nHook.exe  ใน $UsnJrnl  พบว่าถูกสร้าง 20-02-2020 13:46  Create ,  USN 66266856, MFT Record 74950  และไฟล์อื่นๆที่เกี่ยวข้อง

สรุป ผลทดสอบวิเคราะห์ข้อมูลใน $UsnJrnl

   - พบว่าเมื่อมีการติดตั้งโปรแกรมลงใน Windows จะมีการบันทึก ชื่อวันเวลาลงใน $UsnJrnl
   - สามารถนำเรื่อง $UsnJrnl  ในการการวิเคราะห์  incident response 

 เราอาจใช้เครื่องมืออื่นนำ $UsnJrnl ไฟล์ออกมาได้

NTFS Journal Viewer (JV) เป็นเครื่องมือที่ช่วยในการดึงข้อมูล และวิเคราะห์ log $UsnJrnl:$J ซึ่งมีขนาดใหญ่ โดยใช้เวลาไม่นาน นอกจากนี้โปรแกรมยังสามารถกรองข้อมูล (filter) หรือค้นหา (Search) ข้อความที่สนใจได้ และผูู้ใช้สามารถบันทึกเป็นไฟล์นามสกุล .CSV สำหรับเครื่องมือที่ช่วยในการดึงข้อมูล หรือ Extract UsnJrnl นี้ ถูกคิดค้นโดย Joakim Schicht (https://github.com/jschicht) 
NTFS Journal Viewer
NTFS Journal Viewer สามารถดึง UsnJrnl ออกมาได้
$UsnJrnl_$J.bin

Download: NTFS-Journal

NTFS Journal Forensics



Digital Forensics:How to export Master File Table to csv



Ref:


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD #MOBILEFORENSICS #$USNJRNL  

Digital Forensics:Seized Forensic data collection

Digital Forensics:Seized Forensic data collection


Step by Step Checklist สำหรับเตรียมอุปกรณ์เก็บหลักฐานดิจิทัล

เตรียมความพร้อมก่อนไป Onsite

Data Collection

Digital forensic Checklist

Phase 1 Initial preparation

  •         ตั้งชื่อ Case name + Evidence  + ชื่อเจ้าของเครื่อง   > มีชื่อซ่้ำทำอย่างไร John wick  CF-205-JW01
  • เตรียม เอกสารใบรับ-ส่ง ของ (Log),Exhibit Reference ,Property Receipt ,Mobile Phone Consent Form, Description 
  • Forensic equipment , Faraday bag
    Faraday bag

    TD2 + Write blocker

  • TD2 + Write blocker + Adapter m.2 ,nvme ,usb
    TD2 + Write blocker
    TD2 + Write blocker


  •         Wipe a Hard Drive   for disk image 
    Digital Forensics Seized Forensic data collection


  •         Hard Drive Enclosure
    Hard Drive Enclosure

    Hard Drive Enclosure

  • USB Boot Imager ,Deft ,Paladin + Caine-live , Windows To Go
    USB Boot Imager
    USB Boot  recon imager

    Deft,GUYMAGER Acquisition Toot


  • Update forensics workstation software
    Digital Forensics Seized Forensic data collection

  • ปลั๊กไฟฟ้า+ถุงพลาสติก +label + ปากกา + กรรไกร ,Tamper-proof stickers ,Permanent markers
  •         USB dongle key
    Encase USB dongle key

  • เครื่อง Notebook สำหรับ ทำ Forensic workstation
  • กล้องถ่ายรูป Camera, video recorder + ฺCamera Batteries

  •         ชุดไขขวง (Screwdrivers) &Toolkit
    Digital Forensics:Seized Forensic data collection

  • รายละเอียดของงาน (case requirements)  รุ่นคอมพิวเตอร์ + จำนวนเครื่องและขนาด HDD  ,เบอร์ติดต่อ Contact ,แผนที่ , วันเวลา
  • กรณี Onsite  Forensic Imager ประมาณเวลาที่ใช้ทำ Imager  ใน 1 วัน และเสร็จสิ้น   เช่น เริ่มงาน 9.00 เสร็จ 17.00  อยู่ได้ถึงกี่โมง สถานที่-ปิดกี่โมง  

Phase 2 Onsite

  • ลำดับหลักฐานที่สำคัญ    เครื่องคอมพิวเตอร์+โทรศัทพ์เคลื่อนที่ ทำก่อน
  • ถ่ายรูปหลักฐานอุปกรณ์  อะไรบ้าง + บันทึกวันเวลา
    • Serial number +Label name
    • Model +Label name
    • Notebook +Label name
    • อุปกรณ์ที่นำกลับ    เช่น Notebook + Adapter + mouse +Label name
    • State  On  or Off    + Time
  • Check Username  + Password   สอบถามเรื่อง Encryption and data protection & MDM

  • Document แต่ละเครื่อง + Document รวม + Chain of custody form
  •  หากไม่สามารถเก็บข้อมูลโทรศัพท์ได้ จำเป็นต้องใช้วิธีการ ถ่ายรูป (Chat Capture)
    Chat Capture

    อุปกรณ์   กล้องถ่ายรูป + ถุงมือ  , พลาสติกซีลของ +สำรอง ,กระดาษโน๊ต , Marker + กรรไกร
  • Digital Forensics:Seized Forensic data collection
  • โฟมใส่ โทรศัพท์ ป้องกันจอแตก
    Digital Forensics:Seized Forensic data collection

    Digital Forensics:Seized Forensic data collection
  • รถเข็น และลังใส่ของ หรือถุงหิ้ว ,ถุงพลาสติกใส่หลักฐาน
    Digital Forensics:Seized Forensic data collection
    Digital Forensics:Seized Forensic data collection
  • ตรวจสอบรอยแตก หรือรอยขีดข่วน ของหลักฐาน และบันทึก ก่อน seize 

  • ตรวจสอบ เอกสาร  เอกสารใบรับ-ส่ง ของ (Log),Exhibit Reference ,Property Receipt ,Mobile Phone Consent Form ลายเซ็นใบรับของ  ความครบถ้วน
    Digital Forensics:Seized Forensic data collection

  • สรุปจำนวนหลักฐานที่ทำการตรวจยึดทั้งหมด และจัดทำรายงาน

Phase 3  On lab ,Analyze 

  • เตรียม Storage  เก็บ Image  หรือ HDD  ที่เราเก็บไว้สำหรับวิเคราะห์  ต้องซื้อเพิ่มหรือไม่
  • ใช้เวลา Acquisition  กี่วัน Forensic Image  + Time  ที่ใช้
  • ใช้เวลา Analyze   กี่วัน
  • ลำดับหลักฐานที่สำคัญ    เครื่องคอมพิวเตอร์+โทรศัทพ์ที่สำคัญ 
  • ต้องส่งเครื่องคอมพิวเตอร์+โทรศัทพ์คืนภายในกี่วัน 
  • ใช้วิธีการใดในการทำ Acquisition เช่น  TD2 ,USB Boot Deft ,Paladin ,FTK Imager with write blocker
  • เตรียม คำถามในที่ประชุม ?
  • ตรวจสอบรอยแตก หรือรอยขีดข่วน ของหลักฐาน และบันทึก (ในแบบฟอร์ม)
  • ใบส่งของ & ติดตามและUpdate สถานะ

CHECKLIST OF BASIC DFL EQUIPMENT
The following is a suggested list of basic equipment that a DFL should own. The reader should
note that the list is non-exhaustive and more may be required depending on the nature of cases
received.

1 Laptop    = 3  
2 Computer analysis software  = 3  
3 Data recovery software = 2
4 Mobile device analysis software = 1
5 Internet artefacts analysis software = 3
6 Virtual machine software = 2
virtualbox and  VMWare 
7 Imaging Hardware = 2
8 Write blocker = 1
9 Empty storage media – to store data extracted from electronic evidence in the short and long term:
  Pen drive  = ?
  External hard disk  = ?
  Hard disk  = ?
  Server = ?
10 Power cable extension =OK
11 Camera, video recorder =OK
12 Printer = OK
13 Document shredder = Not
14 Storage box or container for carrying equipment = ok
15 Tools
    glove
    Permanent markers
    Screwdrivers
    Magnifying glass = Not
    Evidence sealing or evidence bags
    Tamper-proof stickers
16 Monitor the lab environment regularly – temperature, humidity,cleanliness.= 
17 Network Switch = Not
18 Power Backup System (UPS) =? 
หมายเหตุ :  เป็นขั้นตอนการทำงาน และข้อควรระวัง

#WINDOWSFORENSIC #COMPUTERFORENSICS #DFIR #FORENSICS #DIGITALFORENSICS #COMPUTERFORENSIC #INVESTIGATION #CYBERCRIME #FRAUD 


หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น
* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

Saturday, June 6, 2020

DIGITAL FORENSICS:เครื่องมือตรวจพิสูจน์พยานหลักฐานดิจิทัล

DIGITAL FORENSICS:เครื่องมือตรวจพิสูจน์พยานหลักฐานดิจิทัล

DIGITAL FORENSICS:เครื่องมือตรวจพิสูจน์พยานหลักฐานดิจิทัล

เครื่องมือตรวจพิสูจน์พยานหลักฐานดิจิทัล

เครื่องมือคำอธิบาย
Database forensicsการพิสูจน์พยานหลักฐานในเรื่องฐานข้อมูล
Email analysisการวิเคราะห์จดหมายอิเล็กทรอนิกส์หรืออีเมล
Audio/video forensics การพิสูจน์พยานหลักฐานในเรื่องของสื่อที่เป็นไฟล์เสียงหรือ ภาพเคลื่อนไหว่
Internet browsing analysisการพิสูจน์พยานหลักฐานในเรื่องการเข้าถึงอินเทอร์เน็ต
Network forensicsการพิสูจน์พยานหลักฐานที่เกี่ยวข้องกับระบบเครือข่าย
Memory forensicsการพิสูจน์พยานหลักฐานข้อมูลในหน่วยความจำหลัก
File analysisการพิสูจน์พยานหลักฐานที่เกี่ยวกับไฟล์ต่างๆ
Disk and data captureการพิสูจน์พยานหลักฐานในสื่อบันทึกข้อมูลต่างๆ และการ จับข้อมูลทางดิจิทัล
Computer forensicsการพิสูจน์พยานหลักฐานของเครื่องคอมพิวเตอร์
Digital image forensicsการพิสูจน์พยานหลักฐานที่เป็นข้อมูลรูปภาพ


5 แนวทาง ในการเลือกเครื่องมือตรวจพิสูจน์พยานหลักฐานด้านดิจิทัลให้เหมาะสม

การเลือกเครื่องมือที่ถูกต้อง ตรงความต้องการ ไม่ง่ายเสมอไป เพราะปัจจุบันมีเครื่องมือให้เลือกมากมาย ต่อไปนี้ เป็นแง่ มุมสำาหรับการพิจารณาตัดสินใจเลือก

DIGITAL FORENSICS:เครื่องมือตรวจพิสูจน์พยานหลักฐานดิจิทัล
DIGITAL FORENSICS:เครื่องมือตรวจพิสูจน์พยานหลักฐานดิจิทัล
Photo credit:Tistr.o.th

ที่มา: อ้างอิงจาก  (วิษณุ เรื่องวิทยานนท์ ,เครื่องมือตรวจพิสูจน์พยานหลักฐานดิจิทัล,วิทยาศาสตร์และเทศโนโลยี ปีที่  ฉบับ  มกราคม-มีนาคม 2563, หน้า 18-19.)



อ่านเพื่อเติม:

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud

DIGITAL FORENSICS:WINDOWS FORENSIC .LNK FILES-PART 2

DIGITAL FORENSICS:Windows Forensic .LNK files-Part 2


วันนี้เราลองมาทดลองทำ Lab  WINDOWS FORENSIC  LNK File โดยใช้ LECmd
Where LNK extension link files are stored varies depending on the operating system. These files :
Windows XP :
  • \Documents and Settings\UserName\Recent
Windows Vista and Windows 7 :
  • \Users\UserName\AppData\Roaming\Microsoft\Windows\Recent Items

LNK file signature 
Hex Signature 4C 00 00 00 01 14 02 00
ASCII  8 Bytes
File Extension LNK
Magic value     ‘L’  ,       L.......
 


เครื่องมือที่ใช้สำหรับทำ Lab 


 Download LECmd
ตัวอย่างคำสั่งที่ใช้

Examples:
วิเคราะห์ LNK file
          LECmd.exe -f "C:\Temp\foobar.lnk"
          LECmd.exe -f "C:\Temp\somelink.lnk" --json "D:\jsonOutput" --jsonpretty
         
Export CSV
          LECmd.exe -d "C:\Temp" --csv "c:\temp" --html c:\temp --xml c:\temp\xml -q
          LECmd.exe -d "C:\Temp" --all

1. ทดสอบเปิด Folder & File ใน External drive

The original path of the file
F:\18 Computer Forensics\CTF\dfchallenge.org\201 - Let_s dig new memories

F:\18 Computer Forensics\CTF
2. เปิด ตำแหน่งของ LNK File  ที่อยู่บนเครื่อง computer
"Users\UserName\AppData\Roaming\Microsoft\Windows\Recent Items"

\Users\UserName\AppData\Roaming\Microsoft\Windows\Recent Items
3. Run Commnad 

 .\LECmd.exe  -f "C:\Users\UserName\AppData\Roaming\Microsoft\Windows\Recent\201 - Let_s dig new memories.lnk"



- File size of the linked file = 25,314
- Working Directory: F:\18 Computer Forensics\CTF\dfchallenge.org\201 - Let_s dig new memories

Target ID information 


Link Information -- ระบุรายละเอียดตำแหน่งของไฟล์ต้นฉบับ
Volume name and serial number
Label:  2019_2T
Serial number: 0C5D7EA3
Local path: F:\18 Computer Forensics\CTF\dfchallenge.org\201 - Let_s dig new memories


เมื่อมีการ เปิดไฟล์ 201 - Let_s dig new memories.docx ครั้งที่ 1
Source File: C:\Users\UserName-\AppData\Roaming\Microsoft\Windows\Recent\201 - Let_s dig new memories.lnk

Create Date    2020-06-26
Modified Date 2020-06-26  เมื่อมีการเปิดไฟล์ ค่า Modified จะมีการบันทึกค่าล่าสุด


เมื่อมีการ เปิดไฟล์ 201 - Let_s dig new memories.docx ครั้งที่ 2

Source File: C:\Users\UserName-\AppData\Roaming\Microsoft\Windows\Recent\201 - Let_s dig new memories.lnk

Create Date    2020-06-26
Modified Date 2020-07-13  เมื่อมีการ เปิดไฟล์อีกครั้ง ค่า Modified จะมีการบันทึกค่าล่าสุด
Computer name
Mac Address



4. Run Command Export to CSV File.
\LECmd.exe -d "C:\Users\Training-4\AppData\Roaming\Microsoft\Windows\Recent" --csv "c:\temp1"






Episode 19: “Quick Win” files #3 - .LNK files-Part 1

Episode 20: “Quick Win” files #3 - .LNK files-Part 2



WINDOWS FORENSIC .LNK FILES-PART 1


What are LNK Files?

LNK files are a relatively simple but valuable artifact for the forensics investigator. They are shortcut files that link to an application or file commonly found on a user’s desktop, or throughout a system and end with an .LNK extension. LNK files can be created by the user, or automatically by the Windows operating system. Each has their own value and meaning. Windows-created LNK files are generated when a user opens a local or remote file or document, giving investigators valuable information on a suspect’s activity.

Why are LNK Files Important to Your Digital Forensics Investigation?

LNK files are excellent artifacts for forensic investigators who are trying to find files that may no longer exist on the system they’re examining. The files might have been wiped or deleted, stored on a USB or network share, so although the file might no longer be there, the LNK files associated with the original file will still exist (and reveal valuable information as to what was executed on the system).
Credit :www.magnetforensics

Windows Shortcut File (LNK)

สรุป
       .LNK จะถูกสร้างขึ้นโดยอัตโนมัติเมื่อ User มีการเปิดไฟล์ (Open File) จะมีนามสกุล .LNK
       .LNK จะถูกสร้างขึ้นเมื่อ User สร้าง shortcut ของโปรแกรมหรือไฟล์ และจะมีนามสกุล LNK
       เมื่อมีการเปิดไฟล์ LNK File จะมีการ Update  ค่าวันเวลา Create ,Modify ,Access
       เมื่อมีการลบ File หรือ Folder ต้นฉบับ แต่ไฟล์ .LNK จะไม่ถูกลบไปด้วย
     
ที่มา:
https://medium.com/ctf-writeups/hack-the-box-access-write-up-33ab4cb7d9b3
https://medium.com/@snowshoe/ctf-secplayground-2018-write-up-a18e711341a1
https://nandynarwhals.org/codegate2012-forensics100/
https://or10nlabs.tech/defcon-dfir-ctf-2018/#file-server-basic
https://ericzimmerman.github.io/#!index.md
https://blog.nviso.eu/2017/04/04/tracking-threat-actors-through-lnk-files/
https://www.magnetforensics.com/blog/forensic-analysis-of-lnk-files

หมายเหตุ:เนื้อหาในเว็บไซต์นี้มีขึ้นเพื่อวัตถุประสงค์ในการให้ข้อมูลและเพื่อการศึกษาเท่านั้น

* หากมีข้อมูลข้อผิดพลาดประการใด ขออภัยมา ณ ที่นี้ด้วย  รบกวนแจ้ง Admin เพื่อแก้ไขต่อไป
ขอบคุณครับ

#WindowsForensic #ComputerForensics #dfir #forensics #digitalforensics #computerforensic #investigation #cybercrime #fraud


Volatility Lab

Volatility Lab  Image Wanna.vmem P.73 windows.info #python3  vol.py   -f '/home/kali/Desktop/Wanna/Wanna-MEM.vmem' windows.info     ...