Browser History & Download Forensic Analysis Report

Target System Forensics on Mounted Image Drive E:\ (Windows 11)

Analysis Date: 2026-05-31
Host Environment: Mounted Disk (NTFS)
Service State: Active Investigation
Security Standard: NIST Triage SP 800-86
653
History Entries Parsed
74
File Downloads Logged
3
High-Risk Tools Staged
EXECUTIVE FORENSIC ALERT: SYSTEM COMPROMISE CONFIRMED
Our deep analysis of the browser databases revealed that the service account `wacsvc` (Windows Admin Center Service) has been compromised. Interactive web browser downloads and files matching high-risk tools—including the dual-use remote admin utility PsExec (renamed to px.exe), the resource debugger/LSASS-dumper Process Hacker (renamed to ph.exe), and remnants of the browser history-gathering utility NirSoft BrowsingHistoryView (`bhv.cfg`)—were discovered staged under the service account's user directory. Service accounts do not perform interactive web browsing or download tools, which represents an extremely high-severity Indicator of Compromise (IoC).

1. Parsed Browser History Sources

User Profile Browser History Source Database History Entries Downloads
Administrator Microsoft Edge E:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\History 0 0
tdungan Google Chrome E:\Users\tdungan\AppData\Local\Google\Chrome\User Data\Default\History 450 63
tdungan Microsoft Edge E:\Users\tdungan\AppData\Local\Microsoft\Edge\User Data\Default\History 160 8
wacsvc Google Chrome E:\Users\wacsvc\AppData\Local\Google\Chrome\User Data\Default\History 0 2
wacsvc Microsoft Edge E:\Users\wacsvc\AppData\Local\Microsoft\Edge\User Data\Default\History 43 1

2. Chronological Attack Timeline

Extracted chronologically from Edge and Chrome histories and NTFS artifact logs on drive E:\

First Staging: NirSoft BrowsingHistoryView Downloaded

2023-01-17 17:59:00 | User: wacsvc | Browser: Edge

Downloaded bhv.exe (BrowsingHistoryView) via Edge from secure.csharefile.com. This utility extracts browser history across all local profiles.

NirSoft Tool Executed

2023-01-17 18:00:27 | User: wacsvc | Browser: System

bhv.exe executed by the wacsvc service account. This operation created bhv.cfg, capturing browser history logs from 10-01-2023 to 17-01-2023.

Tool Deletion & Evasion

2023-01-17 18:05:00 | User: wacsvc | Browser: System

The attacker deleted bhv.exe to cover their tracks, leaving only bhv.cfg behind in the Downloads directory.

Sysinternals PsExec Staged

2023-01-23 20:54:02 | User: wacsvc | Browser: Chrome

Downloaded px.exe (PsExec) via Chrome from secure.csharefile.com/download/px.exe. This tool is heavily used for remote command execution and lateral movement.

Process Hacker Staged

2023-01-23 20:54:26 | User: wacsvc | Browser: Chrome

Downloaded ph.exe (Process Hacker) via Chrome from secure.csharefile.com/download/ph.exe. Commonly used to terminate security tools or dump credential stores (LSASS).

3. Downloaded High-Risk Executables & Tools

File Name / Path User Owner File Size Status Category PE Compilation Time
ph.exe (Process Hacker)
E:/Users/wacsvc/Downloads/ph.exe
wacsvc 1679.5 KB High Risk HackTool / Suspicious 2016-03-29 01:34:01
px.exe (Sysinternals PsExec)
E:/Users/wacsvc/Downloads/px.exe
wacsvc 1053.4 KB Medium Risk Admin Utility / Dual-Use 2021-05-12 13:11:48
7z2201-x64.exe
E:/Users/tdungan/Downloads/7z2201-x64.exe
tdungan 1538.8 KB Safe Legitimate Software 2022-07-15 16:00:00
q-balls-v3.py.zip
E:/Users/tdungan/Downloads/q-balls-v3.py.zip
tdungan 11.1 KB Safe Legitimate Software N/A
HiPERCalc.exe
E:/Users/tdungan/Downloads/HiPERCalc.exe
tdungan 598.2 KB Safe Legitimate Software 2015-04-18 13:01:48
npp.8.4.7.Installer.x64.exe
E:/Users/tdungan/Downloads/npp.8.4.7.Installer.x64.exe
tdungan 4503.1 KB Safe Legitimate Software 2021-09-25 21:56:47
SlackSetup.exe
E:/Users/tdungan/Downloads/SlackSetup.exe
tdungan 112377.3 KB Safe Legitimate Software 2019-01-15 20:05:12
FoxitPDFReader1201_enu_Setup_Prom.exe
E:/Users/tdungan/Downloads/FoxitPDFReader1201_enu_Setup_Prom.exe
tdungan 164380.6 KB Safe Legitimate Software 2016-04-06 14:39:04
bhv.cfg (BrowsingHistoryView Config)
E:/Users/wacsvc/Downloads/bhv.cfg
wacsvc 1.3 KB Medium Risk Recon Leftover / Config N/A
desktop.ini
E:/Users/wacsvc/Downloads/desktop.ini
wacsvc 0.3 KB Safe Legitimate Software N/A

Top Visited Domains

www.google.com 64 visits
www.dropbox.com 42 visits
arxiv.org 41 visits
www.amazon.com 21 visits
phys.org 20 visits
www.semanticscholar.org 18 visits
www.bing.com 16 visits
www.innovationaus.com 13 visits

Recent Search Queries (tdungan)

tdungan chrome 2023-01-24 03:27:46
"carpentry classes"
tdungan chrome 2023-01-23 19:34:24
"water filters for refrigerators"
tdungan chrome 2023-01-19 18:18:17
"qbert arcade game for sale"
tdungan chrome 2023-01-19 18:08:01
"qbert"
tdungan chrome 2023-01-19 18:07:52
"qbert"
tdungan chrome 2023-01-19 18:07:47
"qbert"
tdungan chrome 2023-01-17 23:56:12
"alien transparent png"
tdungan chrome 2023-01-17 23:56:00
"alien transparent png"
tdungan chrome 2023-01-17 23:55:49
"alien"
tdungan chrome 2023-01-17 00:39:57
"has there ever been a space based tourbillon"

4. Deep PE Capability Analysis

Details for ph.exe

MD5: b365af317ae730a67c936f21432b9c71
SHA-256: bd2c2cf0631d881ed382817afcce2b093f4e412ffb170a719e2762f250abfea4
Compilation Time: 2016-03-29T01:34:01+00:00

PE Sections

.text Entropy: 6.43
.rdata Entropy: 5.32
.data Entropy: 2.71
.pdata Entropy: 6.11
.gfids Entropy: 2.19
.rsrc Entropy: 5.75
.reloc Entropy: 5.37

Imports & Capabilities

ntdll.dll
NtCreateTimer, NtAlertThread, NtSetTimer, RtlGetGroupSecurityDescriptor, RtlGetOwnerSecurityDescriptor, RtlGetSaclSecurityDescriptor, RtlLengthSecurityDescriptor, NtCreateSemaphore, NtQueryObject, NtClearEvent, NtCreateKeyedEvent, NtWaitForKeyedEvent (+8 more)
WINSTA.dll
WinStationSendMessageW, WinStationShadow, WinStationGetAllProcesses, WinStationFreeGAPMemory, WinStationRegisterConsoleNotification, WinStationQueryInformationW, WinStationFreeMemory, WinStationEnumerateW, WinStationReset, WinStationDisconnect, WinStationConnectW
COMCTL32.dll
PropertySheetW, InitCommonControlsEx, CreatePropertySheetPageW, ImageList_Remove, ImageList_Destroy, ImageList_Create, ImageList_ReplaceIcon, ImageList_Replace
VERSION.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
UxTheme.dll
IsThemeActive, GetThemeInt, SetWindowTheme, CloseThemeData, DrawThemeBackground, OpenThemeData, IsThemePartDefined, EnableThemeDialogTexture
KERNEL32.dll
GetProcAddress, GetModuleHandleW, CreatePipe, FileTimeToSystemTime, FileTimeToLocalFileTime, CreateProcessW, SetConsoleCtrlHandler, FreeConsole, RaiseException, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId (+8 more)
USER32.dll
SetClipboardData, GetDesktopWindow, CreateDialogIndirectParamW, GetWindowTextW, InternalGetWindowText, EmptyClipboard, CloseClipboard, OpenClipboard, GetActiveWindow, GetFocus, GetWindowLongW, DestroyMenu (+8 more)
GDI32.dll
GetDIBits, SaveDC, TextOutW, GetCharWidthW, Rectangle, SetBkMode, BitBlt, DeleteDC, CreateDIBSection, SetBoundsRect, GetStockObject, Polyline (+8 more)
COMDLG32.dll
GetOpenFileNameW, GetSaveFileNameW, ChooseFontW, ChooseColorW
ADVAPI32.dll
SystemFunction036, SetSecurityInfo, LsaLookupSids, LsaLookupPrivilegeValue, LsaLookupPrivilegeDisplayName, LsaLookupNames2, LsaOpenPolicy, LsaLookupPrivilegeName, EnumServicesStatusExW, QueryServiceConfigW, CreateProcessWithLogonW, LsaOpenAccount (+8 more)
SHELL32.dll
DuplicateIcon, SHGetFileInfoW, ShellExecuteExW, SHGetFolderPathW, SHCreateDirectoryExW, Shell_NotifyIconW, ExtractIconExW
ole32.dll
CoTaskMemFree, CoInitializeEx, CoCreateInstance, CoUninitialize
OLEAUT32.dll
SysFreeString

Details for px.exe

MD5: 18126be163eb7df2194bb902c359ba8e
SHA-256: a9affdcdb398d437e2e1cd9bc1ccf2d101d79fc6d87e95e960e50847a141faa4
Compilation Time: 2021-05-12T13:11:48+00:00

PE Sections

.text Entropy: 6.49
.rdata Entropy: 5.16
.data Entropy: 1.54
.pdata Entropy: 5.84
.rsrc Entropy: 6.42
.reloc Entropy: 4.97

Imports & Capabilities

VERSION.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
NETAPI32.dll
NetServerEnum, NetApiBufferFree
WS2_32.dll
gethostbyname, WSAStartup, gethostname, inet_ntoa
MPR.dll
WNetAddConnection2W, WNetCancelConnection2W
KERNEL32.dll
CreateEventW, GetEnvironmentVariableW, GetFullPathNameW, SetFileAttributesW, GetFileAttributesW, CopyFileW, WaitNamedPipeW, SetConsoleCtrlHandler, SetConsoleTitleW, ReadConsoleW, TransactNamedPipe, SetProcessAffinityMask (+8 more)
USER32.dll
GetDlgItem, EndDialog, SetWindowTextW, SendMessageW, SetCursor, GetSysColorBrush, LoadStringW, InflateRect, LoadCursorW, DialogBoxIndirectParamW
GDI32.dll
StartPage, EndDoc, StartDocW, SetMapMode, GetDeviceCaps, EndPage
COMDLG32.dll
PrintDlgW
ADVAPI32.dll
SetEntriesInAclW, CreateProcessAsUserW, OpenThreadToken, ImpersonateNamedPipeClient, CryptHashData, CryptCreateHash, CryptDecrypt, CryptEncrypt, CryptImportKey, CryptExportKey, CryptDestroyKey, CryptDeriveKey (+8 more)

Details for 7z2201-x64.exe

MD5: a6a0f7c173094f8dafef996157751ecf
SHA-256: b055fee85472921575071464a97a79540e489c1c3a14b9bdfbdbab60e17f36e4
Compilation Time: 2022-07-15T16:00:00+00:00

PE Sections

.text Entropy: 6.59
.rdata Entropy: 4.70
.data Entropy: 0.02
.rsrc Entropy: 4.37

Imports & Capabilities

ole32.dll
CoCreateInstance, CoInitialize
USER32.dll
PeekMessageW, ExitWindowsEx, GetDlgItemTextW, SetWindowTextW, ShowWindow, MessageBoxW, CreateDialogParamW, LoadIconW, SendMessageW, GetMessageW, EnableWindow, GetDlgItem (+5 more)
ADVAPI32.dll
RegSetValueExW, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegCreateKeyExW
SHELL32.dll
SHGetFolderPathW, SHBrowseForFolderW, SHGetPathFromIDListW
MSVCRT.dll
_exit, _XcptFilter, _acmdln, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp (+7 more)
KERNEL32.dll
ReadFile, CloseHandle, CreateFileW, FormatMessageW, WriteFile, DeleteFileW, CreateDirectoryW, GetSystemDirectoryW, LoadLibraryW, GetModuleFileNameW, GetFileAttributesW, SetFilePointer (+8 more)

Details for HiPERCalc.exe

MD5: c3f97d0b4be6651cf8d7f4fadc0e1cb0
SHA-256: 1a2d8bcad164cebc8d73ab8ea4b94e10a19db4d498ce192b95aa900e8ffc7f8d
Compilation Time: 2015-04-18T13:01:48+00:00

PE Sections

.text Entropy: 6.06
.data Entropy: 0.35
.rdata Entropy: 5.00
.bss Entropy: 0.00
.idata Entropy: 4.62
.rsrc Entropy: 4.09

Imports & Capabilities

ADVAPI32.DLL
RegCloseKey, RegEnumKeyExA, RegOpenKeyExA, RegQueryValueExA
KERNEL32.dll
CloseHandle, CreateMutexA, CreateProcessA, ExitProcess, FindResourceExA, FormatMessageA, GetCommandLineA, GetCurrentDirectoryA, GetCurrentProcess, GetEnvironmentVariableA, GetExitCodeProcess, GetLastError (+8 more)
msvcrt.dll
__getmainargs, __p__environ, __p__fmode, __set_app_type, _cexit, _chdir, _close, _findclose, _findfirst, _findnext, _iob, _itoa (+8 more)
SHELL32.DLL
ShellExecuteA
USER32.dll
CreateWindowExA, DispatchMessageA, EnumWindows, FindWindowExA, GetMessageA, GetSystemMetrics, GetWindowLongA, GetWindowRect, GetWindowTextA, GetWindowThreadProcessId, KillTimer, LoadImageA (+8 more)

Details for npp.8.4.7.Installer.x64.exe

MD5: feaa91429fb314271bb2cd3db61bcb8a
SHA-256: 515d2c71ece7c4c7432794b9e1bb6fcf60fdaa2e499744c09af113c65d6dbb68
Compilation Time: 2021-09-25T21:56:47+00:00

PE Sections

.text Entropy: 6.42
.rdata Entropy: 5.14
.data Entropy: 4.11
.ndata Entropy: 0.00
.rsrc Entropy: 5.73

Imports & Capabilities

ADVAPI32.dll
RegCreateKeyExW, RegEnumKeyW, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetFileSecurityW, RegOpenKeyExW (+1 more)
SHELL32.dll
SHGetSpecialFolderLocation, SHFileOperationW, SHBrowseForFolderW, SHGetPathFromIDListW, ShellExecuteExW, SHGetFileInfoW
ole32.dll
OleInitialize, OleUninitialize, CoCreateInstance, IIDFromString, CoTaskMemFree
COMCTL32.dll
ordinal_17, ImageList_Create, ImageList_Destroy, ImageList_AddMasked
USER32.dll
GetClientRect, EndPaint, DrawTextW, IsWindowEnabled, DispatchMessageW, wsprintfA, CharNextA, CharPrevW, MessageBoxIndirectW, GetDlgItemTextW, SetDlgItemTextW, GetSystemMetrics (+8 more)
GDI32.dll
SetBkMode, SetBkColor, GetDeviceCaps, CreateFontIndirectW, CreateBrushIndirect, DeleteObject, SetTextColor, SelectObject
KERNEL32.dll
GetExitCodeProcess, WaitForSingleObject, GetModuleHandleA, GetProcAddress, GetSystemDirectoryW, lstrcatW, Sleep, lstrcpyA, WriteFile, GetTempFileNameW, lstrcmpiA, RemoveDirectoryW (+8 more)

Details for SlackSetup.exe

MD5: d2906ad650f517d5a5e9645fc1c0a27d
SHA-256: 7135eafdbea45df8f14e51cc5680cb8931d8a4925c28c98e825e3bfdf0e010a8
Compilation Time: 2019-01-15T20:05:12+00:00

PE Sections

.text Entropy: 6.66
.rdata Entropy: 4.94
.data Entropy: 3.28
.rsrc Entropy: 8.00
.reloc Entropy: 6.53

Imports & Capabilities

KERNEL32.dll
LoadResource, FindResourceW, lstrlenW, GetProcAddress, GetModuleHandleW, DeleteCriticalSection, GetTempPathW, GetLastError, GetTempFileNameW, MoveFileW, WaitForSingleObject, GetExitCodeProcess (+8 more)
SHLWAPI.dll
PathIsUNCW
COMCTL32.dll
InitCommonControlsEx

Details for FoxitPDFReader1201_enu_Setup_Prom.exe

MD5: 421366c71d2ce55f4c80af11de2b359d
SHA-256: 6998b33a7f9fa9f0a666035b8d4988f22aefde2934871ce4dc431c9937dbd9e8
Compilation Time: 2016-04-06T14:39:04+00:00

PE Sections

.text Entropy: 6.38
.itext Entropy: 5.73
.data Entropy: 2.30
.bss Entropy: 0.00
.idata Entropy: 4.60
.tls Entropy: 0.00
.rdata Entropy: 0.20
.rsrc Entropy: 4.05

Imports & Capabilities

oleaut32.dll
SysFreeString, SysReAllocStringLen, SysAllocStringLen
advapi32.dll
AdjustTokenPrivileges
user32.dll
CreateWindowExW, TranslateMessage, SetWindowLongW, PeekMessageW, MsgWaitForMultipleObjects, MessageBoxW, LoadStringW, GetSystemMetrics, ExitWindowsEx, DispatchMessageW, DestroyWindow, CharUpperBuffW (+1 more)
kernel32.dll
Sleep
comctl32.dll
InitCommonControls
SUGGESTED FORENSIC INCIDENT RESPONSE PLAYBOOK
  • Immediate Machine Isolation: Disconnect this host from the enterprise network. The staging of PsExec (px.exe) strongly suggests the host was prepared for lateral movement across the internal subnet.
  • Service Account Credential Rotation: Reset and rotate credentials for the wacsvc service account across the entire Active Directory domain/workgroup immediately.
  • LSASS Access Audit: Process Hacker (ph.exe) is commonly used to dump the LSASS process memory. Verify whether any LSASS dump files (e.g. lsass.dmp) exist on the C:\ or E:\ drives.
  • Prefetch Forensic Walk: Review the Windows Prefetch directory on E:\ (E:\Windows\Prefetch) to obtain the exact execution timestamps, run counts, and loaded files for bhv.exe, px.exe, and ph.exe.