Target System Forensics on Mounted Image Drive E:\ (Windows 11)
| User Profile | Browser | History Source Database | History Entries | Downloads |
|---|---|---|---|---|
| Administrator | Microsoft Edge | E:\Users\Administrator\AppData\Local\Microsoft\Edge\User Data\Default\History |
0 | 0 |
| tdungan | Google Chrome | E:\Users\tdungan\AppData\Local\Google\Chrome\User Data\Default\History |
450 | 63 |
| tdungan | Microsoft Edge | E:\Users\tdungan\AppData\Local\Microsoft\Edge\User Data\Default\History |
160 | 8 |
| wacsvc | Google Chrome | E:\Users\wacsvc\AppData\Local\Google\Chrome\User Data\Default\History |
0 | 2 |
| wacsvc | Microsoft Edge | E:\Users\wacsvc\AppData\Local\Microsoft\Edge\User Data\Default\History |
43 | 1 |
Extracted chronologically from Edge and Chrome histories and NTFS artifact logs on drive E:\
2023-01-17 17:59:00 | User: wacsvc | Browser: Edge
Downloaded bhv.exe (BrowsingHistoryView) via Edge from secure.csharefile.com. This utility extracts browser history across all local profiles.
2023-01-17 18:00:27 | User: wacsvc | Browser: System
bhv.exe executed by the wacsvc service account. This operation created bhv.cfg, capturing browser history logs from 10-01-2023 to 17-01-2023.
2023-01-17 18:05:00 | User: wacsvc | Browser: System
The attacker deleted bhv.exe to cover their tracks, leaving only bhv.cfg behind in the Downloads directory.
2023-01-23 20:54:02 | User: wacsvc | Browser: Chrome
Downloaded px.exe (PsExec) via Chrome from secure.csharefile.com/download/px.exe. This tool is heavily used for remote command execution and lateral movement.
2023-01-23 20:54:26 | User: wacsvc | Browser: Chrome
Downloaded ph.exe (Process Hacker) via Chrome from secure.csharefile.com/download/ph.exe. Commonly used to terminate security tools or dump credential stores (LSASS).
| File Name / Path | User Owner | File Size | Status | Category | PE Compilation Time |
|---|---|---|---|---|---|
|
ph.exe (Process Hacker)
E:/Users/wacsvc/Downloads/ph.exe
|
wacsvc | 1679.5 KB | High Risk | HackTool / Suspicious | 2016-03-29 01:34:01 |
|
px.exe (Sysinternals PsExec)
E:/Users/wacsvc/Downloads/px.exe
|
wacsvc | 1053.4 KB | Medium Risk | Admin Utility / Dual-Use | 2021-05-12 13:11:48 |
|
7z2201-x64.exe
E:/Users/tdungan/Downloads/7z2201-x64.exe
|
tdungan | 1538.8 KB | Safe | Legitimate Software | 2022-07-15 16:00:00 |
|
q-balls-v3.py.zip
E:/Users/tdungan/Downloads/q-balls-v3.py.zip
|
tdungan | 11.1 KB | Safe | Legitimate Software | N/A |
|
HiPERCalc.exe
E:/Users/tdungan/Downloads/HiPERCalc.exe
|
tdungan | 598.2 KB | Safe | Legitimate Software | 2015-04-18 13:01:48 |
|
npp.8.4.7.Installer.x64.exe
E:/Users/tdungan/Downloads/npp.8.4.7.Installer.x64.exe
|
tdungan | 4503.1 KB | Safe | Legitimate Software | 2021-09-25 21:56:47 |
|
SlackSetup.exe
E:/Users/tdungan/Downloads/SlackSetup.exe
|
tdungan | 112377.3 KB | Safe | Legitimate Software | 2019-01-15 20:05:12 |
|
FoxitPDFReader1201_enu_Setup_Prom.exe
E:/Users/tdungan/Downloads/FoxitPDFReader1201_enu_Setup_Prom.exe
|
tdungan | 164380.6 KB | Safe | Legitimate Software | 2016-04-06 14:39:04 |
|
bhv.cfg (BrowsingHistoryView Config)
E:/Users/wacsvc/Downloads/bhv.cfg
|
wacsvc | 1.3 KB | Medium Risk | Recon Leftover / Config | N/A |
|
desktop.ini
E:/Users/wacsvc/Downloads/desktop.ini
|
wacsvc | 0.3 KB | Safe | Legitimate Software | N/A |
b365af317ae730a67c936f21432b9c71
18126be163eb7df2194bb902c359ba8e
a6a0f7c173094f8dafef996157751ecf
c3f97d0b4be6651cf8d7f4fadc0e1cb0
feaa91429fb314271bb2cd3db61bcb8a
d2906ad650f517d5a5e9645fc1c0a27d
421366c71d2ce55f4c80af11de2b359d
px.exe) strongly suggests the host was prepared for lateral movement across the internal subnet.wacsvc service account across the entire Active Directory domain/workgroup immediately.ph.exe) is commonly used to dump the LSASS process memory. Verify whether any LSASS dump files (e.g. lsass.dmp) exist on the C:\ or E:\ drives.E:\Windows\Prefetch) to obtain the exact execution timestamps, run counts, and loaded files for bhv.exe, px.exe, and ph.exe.