Intro to digital forensics, rapid traige examination and analysis

During our examination of the USN Journal within Timeline Explorer, we observed “uninstall.exe”. The attacker subsequently renamed this file. Use Zone.Identifier information to determine its new name and enter it as your answer. any hints on this one

did you solve it bro? i am struck too

parse the MFT open it in time line viewer and look for the zoneID for uninstall.exe, then there is a file name column that will show the original file name.

thanks, i have done that already, i am at last module in soc analyst, appreciate your response

To determine the new name of the “uninstall.exe” file, check the Zone. Identifier information linked to it in Timeline Explorer. Look for any renaming events associated with the file.
You need to define a new file name “uninstall.exe” using the information from Zone.Identifier. It is important to extract this information and continue the analysis without discussing the methods for obtaining it.

saw those clues in the timeline explorer but still can’t find the new name in mft explorer

Well, I got stuck there for a while. Let me help you to get out there:

:information_source: Make sure to parse to csv the $MFT File, don’t spend a lot of time analyzing $J (USN).

Using the Time Explorer, instead of filter by the Entry ID, do it by the file name (uninstall.exe). You will notice a couple of downloads of the file with ZoneIdentifier 3.

From there, just analyze the File Name column, good luck! :slight_smile:

i saw several. like discord.exe, and other but all are wrong. any hint.

solution, i quite simple, read the instruction careful, use the PS script, search with the Timeline Explorer for the uninstall.exe and then have a look to the “FileName” Column