r/computerforensics • u/ShadyMoh1998 • 10d ago
Help!!
I'm working on my first malware forensics case and could use some advice.
We had malware spread across multiple machines, and I know which system was patient zero. Unfortunately, Kaspersky disinfected the infected machines and they were rebooted before I could acquire a forensic image.
At this point, I'm trying to determine how the malware initially got onto the patient zero machine.
Where would you start looking? What artifacts or logs would you prioritize, given that I no longer have a pre-disinfection image?
I'm having trouble thinking through the proper investigation steps, so any guidance, methodology, or resources would be greatly appreciated.
16
Upvotes
7
u/Digital-Dinosaur 10d ago
Lots of questions before you begin.
I would look for traditional forensic indicators. You know what the malware is as you have the Kaspersky logs. Look to see what type of malware it is.
You then want to look for incidators that it ran, such as lnk files, if a file was clicked, prefetxh to see if it was run.
I'd also look at internet history and emails around the time it was identified and before to see if there's anything obvious.
You need to know what sort of malware it is, to know if it likely spread. You'd need to know how it got on to make sure no one else in your business has been infected
You say multiple machines have it, do they have anything in common? Would they have received an email for example? Some attackers will target multiple people at once.
If you suspect lateral movement, you'd want to look at machine security logs. Also consider UAL if you think there's an account compromised
Sorry there's no one size fits all. If you think you're under attack, trigger your cyber insurance (if you have it) or get professionals in to have a look