Sysinternals cyberdefenders
Category : Digital Forensics FTK Windows Disk
Q1 What was the malicious executable file name that the user downloaded?

Q2 When was the last time the malicious executable file was modified?


Q3 What is the SHA1 hash value of the malware?



Q4 What is the malware's family?

Q5 What is the first mapped domain's Fully Qualified Domain Name (FQDN)?

Q6 The mapped domain is linked to an IP address. What is that IP address?
Q7 What is the name of the executable dropped by the first-stage executable?
Q8 What is the name of the service installed by 2nd stage executable?
Q9 What is the extension of files deleted by the 2nd stage executable?


Last updated
