100% found this document useful (1 vote)
204 views12 pages

M57.biz Digital Forensic Report

This document is a computer forensic examination report analyzing a case involving the M57.biz company. The report finds that an employee, Jean, was targeted in an email spoofing scheme and tricked into sending a confidential spreadsheet to an outside actor. By analyzing email headers and correspondence, the report establishes a timeline showing how Jean was pressured via emails appearing to come from the company president, but actually from other addresses, to urgently send the file. This led to the information ending up posted publicly. The report concludes Jean was victimized but should have verified the unusual requests via other means. It recommends the company implement tools to prevent spoofing and train employees to spot such schemes, along with data loss protections.

Uploaded by

api-567951159
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
204 views12 pages

M57.biz Digital Forensic Report

This document is a computer forensic examination report analyzing a case involving the M57.biz company. The report finds that an employee, Jean, was targeted in an email spoofing scheme and tricked into sending a confidential spreadsheet to an outside actor. By analyzing email headers and correspondence, the report establishes a timeline showing how Jean was pressured via emails appearing to come from the company president, but actually from other addresses, to urgently send the file. This led to the information ending up posted publicly. The report concludes Jean was victimized but should have verified the unusual requests via other means. It recommends the company implement tools to prevent spoofing and train employees to spot such schemes, along with data loss protections.

Uploaded by

api-567951159
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Background to the Case
  • Introduction
  • Evidence and Tools Used
  • Findings
  • Analysis
  • Conclusion and Recommendations
  • Reference

RUNNING HEADER: CSOL590 FINAL PROJECT ASSIGNMENT

Computer Forensic Examination Report:

[Link] Case

Student: Frank Ahan

Institution: University of San Diego

Instructor: Ron Fulton, M.S.

Class: CSOL-590-004-FA21

Date: 9 December 2021


COMPUTPER FORENSIC EXAMINIATION REPORT 2

Table of Contents

INTRODUCTION .......................................................................................................................................................... 3

BACKGROUND TO THE CASE ................................................................................................................................. 3

EVIDENCE AND TOOLS USED ................................................................................................................................. 3

ANALYSIS .................................................................................................................................................................... 4

FINDINGS ..................................................................................................................................................................... 4

CONCLUSION AND RECOMMENDATIONS ......................................................................................................... 11

REFERENCE ............................................................................................................................................................... 12
COMPUTPER FORENSIC EXAMINIATION REPORT 3

Introduction

The purpose of this report is to explain the processes and tools used to analyze the digital

evidence that was submitted to the digital forensics analyst. Then run through the analysis,

explain the findings, and offer recommendations.

Background to the Case


What prompted this case, and the investigation was that confidential information was

posted on [Link]’s competitors “technical support” forum as an attachment. How did said

attachment end up on that website?

Two witnesses were interviewed Alison, President of [Link] and Jean, CFO of [Link].

The following was gathered from those interviews.

• Alison has and had no knowledge of any requests for Jean to send information found on

the spreadsheet in question. Second, Alison said she never received said spreadsheet from

Jean.

• Jean received an email from Alison requesting for information and the spreadsheet as part

of a new funding round which was to be sent to Alison to her email address.

Email addresses of the witnesses were obtained along with the login credentials. Alison’s

email address is alison@[Link] and Jean’s email address is jean@[Link].

Evidence and Tools Used


A bit-for-bit image of the hard drive of the employee question was provided and used.

• [Link]

jean.E01

• [Link]

jean.E02
COMPUTPER FORENSIC EXAMINIATION REPORT 4

By using the provided image, it provided an exact clone of the original hard drive without

the danger of losing any information or accidentally changing any information from of the original

hard drive which is the digital evidence. By being bit-for-bit, all the data is the same and deleted

information and logs will be kept intact. The hashes are provided in the supplementary analysis

report to prove that everything is a legitimate image of the original files.

A combination of FTK Imager and Autopsy, both digital forensics platforms were used to

process the image file. Before uploading the image files, other sample files were used to test that

the programs were working well and as intended. These programs are fully licensed and used

according to their purposes. All the processes have been documented and are provided within the

supplementary analysis report, in accordance with the reporting aspect of chain of custody for

digital evidence.

Analysis
Once the image file was uploaded and analyzed, the email files were found, and a discovery

process was started. The email with the attachment in question was found and any relevant

conversation or thread emails were also analyzed. The text and the headers were looked at to help

with the analysis of the events and how things happened. By using the emails, a timeline was able

to be put together to get a clearer picture of the succession of events and eventually explain how

the information was exfiltrated from the company and ultimately end up on the competitor’s

website.

Findings
This first email seems to be the start of the events.
COMPUTPER FORENSIC EXAMINIATION REPORT 5

Figure 1: First email

In the text it shows the request for the background check with a timestamp of 2008-07-19

116:39:57

Figure 2: Text of the initial Email

When looking at the header files it reveals that the return path of this email is different than

who is meant to be the receiver which is the email account alison@[Link] and rather going to

simsong@[Link].
COMPUTPER FORENSIC EXAMINIATION REPORT 6

Figure 3: Header information showing different email address

Second email received by Jean, who assumed it was Alison comes two hours later putting

pressure on Jean to send over the file urgently.

Figure 4: Second email, urgency requested


COMPUTPER FORENSIC EXAMINIATION REPORT 7

Figure 5: Second email text

Looking at the header of the email again shows that it is not from alison@[Link] but from

simsong@[Link] but also another email address of tuckgorge@[Link] is found.

Figure 6: Header information


COMPUTPER FORENSIC EXAMINIATION REPORT 8

Then a third email thanking Jean for the file and asking her not to let anyone know that

such a file was sent, was received.

Figure 7: Third Email

From looking at the text, seems as though the imposter got sloppy and showed the

tuckgorge@[Link] in the message itself.

Figure 8: Text of third email in question

Again, the header shows that it is coming from and going to the

simsong@[Link] email address.


COMPUTPER FORENSIC EXAMINIATION REPORT 9

Figure 9: Header Information

What is interesting though, it seems as though some of the email correspondence was still

going back and forth from Jean to Alison legitimately. But because of this outside thread was

unknown to Alison she sent back a confused message.

Figure 10: Confused Message


COMPUTPER FORENSIC EXAMINIATION REPORT 10

Figure 11: Text

Figure 12: From legitimate address


COMPUTPER FORENSIC EXAMINIATION REPORT 11

Conclusion and Recommendations


After reviewing the evidence in particular the emails correspondence back and forth from

Jean and Alison. It looks like Jean jean@[Link] was the victim of email spoofing thinking it was

the President of the company Alison alison@[Link] asking for sensitive information on a

spreadsheet. Common tactics used by malicious actors were found, such as putting urgency

pressure on the victim to send information as soon as possible, and also asking the victim to not

let anyone know as it is a confidential matter. These should have been flags for the victim and

should have reached out to Alison directly by other means of communication, perhaps with a SMS

message or a phone call. There were correspondences going between Jean and the Spoofer and

other messages between Jean and Alison, where Alison is confused of the messages. Finally, as

the different engineers are hearing that their information has been posted somewhere reach out to

Jean to figure out what is going on. This tipped off Jean that something was amiss and reported it

to the proper authorities.

As a recommendation for the organization going forward to avoid the reoccurrence of such

events, we recommend that [Link] use tools that are available to avoid email spoofing and filter

them out, so they do not reach the users inboxes. Provide training going forward to users to spot

and detect spoofing, but also to reach out by other means if a message or a request seems off.

Lastly, use tools to be able to allow for Data Loss Protection, and block the sending of personal

identifiable information through unsecure means and through attachments.


COMPUTPER FORENSIC EXAMINIATION REPORT 12

Reference
AY, O. (2020, May 29). Digital Forensics Investigation Jurisprudence: Issues of Admissibility of

Digital Evidence. [Link]. Retrieved December 6, 2021, from

[Link]

jurisprudence-issues-of-admissibility-of-digital-evidence

GeeksforGeeks. (2020, June 2). Chain of Custody - Digital Forensics. Retrieved December 6,

2021, from [Link]

Murphy, M. (2015, February 25). Digital Forensic Evidence. YouTube. Retrieved December 6,

2021, from [Link]

Common questions

Powered by AI

The evidence of email spoofing in the M57.biz case was deduced from the analysis of email headers and the email content. The headers showed that while emails appeared to be sent from Alison's email address, they were actually from different accounts such as simsong@xy.dreamhostps.com. Additionally, the urgency and secretive nature of the emails and the request to not inform anyone else were red flags consistent with spoofing tactics .

The differentiation was made by closely examining the email headers and content. Legitimate communications had consistent return paths and metadata aligning with trusted information, whereas emails from the malicious actor showed inconsistencies, like mismatched sender names and different originating email addresses .

Maintaining a 'chain of custody' in digital forensics ensures that all evidence is reliably documented and preserved, which is crucial for its admissibility in legal proceedings. In this case, detailed processes were followed to demonstrate that the digital evidence analyzed was untampered and authentic, supporting the investigation's integrity and findings .

The timeline was constructed by analyzing the timestamps and headers of the relevant emails to establish a sequence of events. By organizing these times and examining the content of the emails, investigators were able to reconstruct how the malicious actor leveraged email spoofing to extract sensitive information from Jean .

Challenges include verifying the authenticity of emails, distinguishing spoofed emails from legitimate ones, and tracing the origin of spoofed emails which often utilize fake or masked addresses. Ensuring a secure and documented chain of custody for digital evidence further complicates the investigation .

Indicators of phishing in the emails included the use of urgency to compel the recipient (Jean) to quickly comply with requests, the presence of a fake 'from' address masking the true sender, and requests to keep confidentiality which are common phishing tactics .

The recommendations for M57.biz included implementing email spoofing detection tools, training employees to recognize phishing attempts, advising verification of suspicious requests via alternative communication methods, and adopting Data Loss Protection tools to prevent unauthorized data transfer .

The key methods used for analyzing the digital evidence included creating a bit-for-bit image of the hard drive, ensuring all data and logs were intact. The analysis was conducted using digital forensics platforms such as FTK Imager and Autopsy, which allowed for a detailed examination of emails and documentation of the entire process for maintaining the chain of custody .

Email header analysis was crucial in uncovering the deceit, as it revealed discrepancies between the apparent sender of the emails (Alison) and the actual sender, which were fraudulent email addresses. This analysis exposed that the communications were part of an elaborate ruse to solicit confidential information under false pretenses .

The initial suspicion arose when confidential information belonging to M57.biz was found posted on a competitor’s technical support forum. This unauthorized disclosure prompted an investigation to determine how the data was leaked .

RUNNING HEADER: CSOL590 FINAL PROJECT ASSIGNMENT 
 
 
 
 
 
 
 
 
Computer Forensic Examination Report: 
M57.biz Case
COMPUTPER FORENSIC EXAMINIATION REPORT 
2 
 
Table of Contents 
INTRODUCTION ................................................
COMPUTPER FORENSIC EXAMINIATION REPORT 
3 
Introduction 
 
The purpose of this report is to explain the processes and tools u
COMPUTPER FORENSIC EXAMINIATION REPORT 
4 
By using the provided image, it provided an exact clone of the original hard drive
COMPUTPER FORENSIC EXAMINIATION REPORT 
5 
 
Figure 1: First email 
In the text it shows the request for the background check
COMPUTPER FORENSIC EXAMINIATION REPORT 
6 
 
Figure 3: Header information showing different email address 
 
Second email rec
COMPUTPER FORENSIC EXAMINIATION REPORT 
7 
 
Figure 5: Second email text 
 
Looking at the header of the email again shows th
COMPUTPER FORENSIC EXAMINIATION REPORT 
8 
 
 
Then a third email thanking Jean for the file and asking her not to let anyone
COMPUTPER FORENSIC EXAMINIATION REPORT 
9 
 
Figure 9: Header Information 
 
What is interesting though, it seems as though s
COMPUTPER FORENSIC EXAMINIATION REPORT 
10 
 
Figure 11: Text 
 
Figure 12: From legitimate address

You might also like