Challenge #7 – SysInternals Case

The user downloaded what they thought was the SysInternals tool suite, double-clicked it, but the tools did not open and were not accessible. Since that time, the user has noticed that the system has “slowed down” and become less and less responsive.

– Goal is to determine what happened, and when.
– Files could be found here: Mega or Archive
– Special Thanks to Harlan Carvey for helping form this case. Please check his amazing work here.

Solutions to this case and others can be found at Cyber 5W under the Case Studies section which can be found here.

End of Case.

About [email protected]

[Between Teams of Red and Blue, I'm with the Purple Team]
This entry was posted in Challenges, DFIR, Forensics, Investigations, Malware and tagged , , , , , , . Bookmark the permalink.