TryHackMe: Intro to ISAC
This is a write up for the Investigation Scenarios task of the Intro to ISAC room on TryHackMe. Some tasks have been omitted as they do not require an answer.
What is the name of the file from Scenario 1?
Answer: 29D6161522C7F7F21B35401907C702BDDB05ED47.bin
What is the size of the file from Scenario 1 in bytes?
Answer: 96,535
What is the size on disk of the file from Scenario 1 in bytes?
Answer: 98,304
What is the MD5 hash of the file from Scenario 1?
Open WinMD5 and select the Scenario 1 file.
Answer: 8baa9b809b591a11af423824f4d9726a
What is the name of the file from Scenario 2?
Answer: cryptowall.bin
What is the size of the file from Scenario 2 in bytes?
Answer: 246,272
What is the size on disk of the file from Scenario 2 in bytes?
Answer: 249,856
What is the MD5 hash of the file from Scenario 2?
Open WinMD5 and select the Scenario 2 file.
Answer: 47363b94cee907e2b8926c1be61150c7
Recap
In this task we learnt how to:
- Find file information in Windows
- Use WinMD5 to generate hash values
- Use IOCe to create IOCs
- Use AlienVault to search for and identify existing threats