Forensics

What is the Operating System of this Dump file? (OS name)

vol3 -f victim.raw windows.info

What is the PID of SearchIndexer?

What is the last directory accessed by the user?

Cara de shinji cansado

There are many suspicious open ports; which one is it? (ANSWER format: protocol:port)

Vads tag and execute protection are strong indicators of malicious processes; can you find which they are? (ANSWER format: Pid1;Pid2;Pid3)

'www.go****.ru' (write full url without any quotation marks)

'www.i****.com' (write full url without any quotation marks)

'www.ic******.com'

202.***.233.*** (Write full IP)

***.200.**.164 (Write full IP)

209.190.***.***

What is the unique environmental variable of PID 2464?

Last updated