Honeynet Project
Scan of the Month 24
2002

OFFICAL RESULTS PAGES

Questions/Answer 4

Question:
For each file, what processes were taken by the suspect to mask them from others?

Answer:
simmy jungle.doc  - deleted

The "J" in Jimmy jungle.doc was replaced with hexadecimal value 5h "
s".

In regards to the Long File Name, the File ID "LFN" was replaced with "Del LFN".

In Regards to the DOS legal name (8+3), the File ID "File" was replaced with "Erased".

The pointers in FAT for each cluster starting at cluster 2 up to and including cluster 41 were zeroed (0) out.