Honeynet Forensics Challenge - Banking Troubles
Submitted by famousjs on Sun, 03/28/2010 - 11:49
The new forensics challenge has been posted to the Honeynet Web Site.
http://honeynet.org/challenges/2010_3_banking_troubles
"Company X has contacted you to perform forensics work on a recent incident that occurred. One of their employees had received an email from a fellow co-worker that pointed to a PDF file. Upon opening, the employee did not seem to notice anything, however recently they have had unusual activity in their bank account. Company X was able to obtain a memory image of the employee’s virtual machine upon suspected infection. Company X wishes you to analyze the virtual memory and report on any suspected activities found. Questions can be found below to help in the formal report for the investigation."
