解析メモ

マルウェア解析してみたり解析に役に立ちそうと思ったことをメモする場所。このサイトはGoogle Analyticsを利用しています。

4n6 Week 8 – 2023 - FORENSIC ANALYSIS

本エントリは This Week in 4n6 (FourAndSix=Forensics) で紹介された各記事の冒頭を表示し、チェックする記事をザッピングするために自動生成&投稿したものです。4n6 は こちら からご確認いただけます。

FORENSIC ANALYSIS

David Spreadborough at Amped

Welcome to this new Amped Software blog series on CCTV Acquisition. In this fortnightly series, we hope to break down some misconceptions and challenges, but also provide some solutions for the initial recovery of video evidence from surveillance systems. Make sure to stay up-to-date with our blog by checking in regularly, as we will be posting a new article every two weeks. You won’t want to miss out on any of the content! Before we look ahead at what’s coming up, let us take a few moments to u...

Dany at Digitella

In this challenge, I utilized Brim and Wireshark to analyze malicious web traffic. In particular, you are analyzing traffic where an exploitation kit infection is present. Question 1:I went into Brim and imported the pcap file. I examined the traffic, and I noticed that a network trojan was detected, right before there is also the exploit kit, which is attached to the IP of 172.16.165.165 ​Question 2:I used the _path=="dhcp" | client_addr 172.16.165.165 filter and found the hostname as shown in ...

Forensafe

Investigating Window F-Secure 17/02/2023 Friday F-Secure Antivirus is a cutting-edge security solution for Windows devices that offers real-time protection against malware, phishing attacks, and other forms of online threats. Equipped with advanced security features, F-Secure Antivirus provides users with a comprehensive and reliable defense mechanism for their devices. Digital Forensics Value of F-Secure F-Secure keeps detailed logs of all actions performed on the device, including file changes...

Investigating Window OpenVPN 17/02/2023 Friday OpenVPN is a virtual private network application, similar to ExpressVPN, ProtonVPN, and NordVPN. A VPN application provides a secure connection for individuals and businesses. OpenVPN solutions primarily target businesses by offering VPN integrated solutions such as OpenVPN Cloud and Self-Hosted Access Server. In addition, OpenVPN Connect client software is available for both individual users and businesses. The software is compatible with several w...

Magnet Forensics

In iOS 11.4.1, Apple introduced the feature of Messages in iCloud. While not default, many users have enabled this option to back up their messages outside of their standard iCloud backup functionality. This could lead to finding retrievable data on different devices, which could be beneficial during your investigations. In this blog, we’ll explore the different ways users’ data syncs across the ecosystem, how it can be retrieved, and how you can use free tools, like the MAGNET Apple Warrant Ret...

Paolo Dal Checco at Studio d’Informatica Forense

Pubblicato il 18 Febbraio 2023 da Paolo Dal CheccoIn ambito di perizia fonica viene sempre più spesso richiesta la verifica di eventuali manipolazioni, plagio o alterazioni su registrazioni audio ambientali o telefoniche, prodotte con registratori analogici o digitali, smartphone, telecamere, disponibili online oppure prodotte in cause civili o penali come prova informatica.La Rete Europea degli Istituti di Scienze Forensi (ENFSI) fondata nel 1995, con lo scopo di migliorare lo scambio reciproco...