Honeynet Project
Scan of the Month 24
2002

OFFICAL RESULTS PAGES

Question/Answer 5, Continued

Question:

What processes did you (the investigator) use to successfully examine the entire contents of each file?

Answer:
Scheduled visits.exe - misrepresented and password protected/Restored

Original file extension "zip" was replaced by "exe" for both the Long File Name and DOS legal name (8+3).
-Examined starting cluster for signature and found "PK", which is the signature for a zip file. Location  = Cluster 73, Sector, Offsets 0 and 1
-In the root directory, "exe" was replaced with "zip" for both the Long File Name and DOS legal name (8+3)

File size was changed from "2420" bytes to "1000" bytes.
-Identified total number of required clusters for this file to be 5. Multiplied 5 * 512 to come up with the file size of 2560
-Changed file size "1000" to "2560" in the root directory


Zipped Excel spreadsheet was password protected.

-Opened zipped password protected file by entering the password "goodtimes" found earlier in the slack space of cover page.jpg