Information System
Lab 2: Online-Based Forensics
You recently began a new position as a member of a large manufacturing firm’s computer incident response team (CIRT). Your role is to investigate threats that are identified by the forensic investigators in their forensic analysis of compromised devices.
Two suspicious files have been identified:
· Filename: trfg.exe, MD5: 322fcf1b134fef1bae52fbd80a373ede
· Filename: furjhf83.jar, MD5: 856de08a947a40e00ea7ed66b8e02c53
Based on the tools I discussed in the lecture please address the following questions. Note: You are NOT allowed to collaborate on this lab.
1. When were these files first identified in the wild?
2. Have these files been used recently?
3. Based on the time period that they were discovered now and from the data you have found online, can we say anything about the threat actors that we may be dealing with?
4. Are these two files related to each other?
5. Are these files possibly part of a larger campaign?
a. If yes, which ones?
6. Are there other files (hashes or filenames) that are related to these two files?
7. Can we link any email addresses to the provided files or other files that you have determined to be related to these files?
8. Given what you have uncovered, what do you think your next steps should be?