Forensic journey: hunting evil within AmCache


When it comes to digital forensics, AmCache plays a vital role in identifying malicious activities in Windows systems. This artifact allows the identification of the execution of both benign and malicious software on a machine.

It is managed by the operating system, and at the time of writing this article, there is no known way to modify or remove AmCache data. Thus, in an incident response scenario, it could be the key to identifying lost artifacts (e.g., ransomware that auto-deletes itself), allowing analysts to search for patterns left by the attacker, such as file names and paths.

Read more…
Source: Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Russia foiled 280,000 DDoS cyberattacks against remote electronic voting system

    March 17, 2024

    Speaking at a news conference in Moscow, Ella Pamfilova, head of Russia’s Central Election Commission, said that the overall turnout in the presidential election as of 3:45 p.m. Moscow time (1245GMT), taking into account remote electronic voting, is 70.81%. Pamfilova also said that about 280,000 DDoS cyberattacks against remote electronic voting had been foiled, including 215,000 ...

  • French state services hit by cyberattacks of ‘unprecedented intensity’

    March 11, 2024

    The latest cyberattack to hit France follows a warning from Attal’s defence adviser just last week that the Olympics games in July and European Parliament elections in June could be “significant targets”. Prime Minister Gabriel Attal’s office said several state bodies were targeted but did not provide details. “Many ministerial services were targeted” from Sunday “using ...

  • Capita shares sink as outsourcing giant swings to £107m loss, takes £25m hit from cyber attack

    March 6, 2024

    Capita has incurred £25.3m in costs tied to a cyber attack last March as the outsourcing giant swung to an annual loss and ramped up its cost-cutting programme. Shares fell 16 per cent on Wednesday morning. The group, which runs key local government, military and NHS services, posted a pretax loss of £106.6m for 2023, compared ...

  • Hacker forum post claims UnitedHealth paid $22 mln ransom in bid to recover data

    March 5, 2024

    A post on a hacker forum popular with cybercriminals has claimed UnitedHealth Group opens new tab paid $22 million in a bid to recover access to data and systems encrypted by the “Blackcat” ransomware gang, according to two researchers. Neither UnitedHealth nor the hackers involved have commented on the alleged ransom payment, but a cryptocurrency tracing ...

  • LockBit cyberattack: Fulton County refuses to pay ransom as deadline passes

    March 1, 2024

    Fulton County leaders say they have not paid any ransom to the criminal group claiming responsibility for the cyberattack that affected several of the county’s agencies. The group LockBit had set a deadline of 8:49 a.m. on Thursday for Fulton County to pay the ransom or risk having stolen data leaked onto the dark web. This ...

  • Golden Corral Corporation Provides Notice of Data Privacy Event

    February 29, 2024

    Golden Corral Corporation is notifying certain individuals of a recent incident that may impact the privacy of past and present employees, dependents, and beneficiary personal information. Golden Corral is unaware of any misuse of the information and is providing notice to potentially affected individuals out of an abundance of caution. On or about August 15, 2023, ...