Honeynet Project
Scan of the Month 24
2002

OFFICAL RESULTS PAGES

Questions/Answer 4, Continued


Question:
For each file, what processes were taken by the suspect to mask them from others?

Answer:
Scheduled visits.exe -misrepresented and password protected


Original file extension "zip" was replaced by "exe" for both the Long File Name and DOS legal name (8+3)

File size was changed from "2420" bytes to "1000" bytes

Zipped Microsoft Excel spreadsheet was password protected