DFIRCON Memory Analysis Challenge

DFIRCON APT Malware & Memory Challenge

The memory image contains real APT malware launched against a test system. Your job? Find it.

The object of our challenge is simple: Download the memory image and attempt to answer the 5 questions. To successfully submit for the contest, all answers must be attempted. Each person that correctly answers 3 of the 5 questions will be entered into a drawing to win a FREE Simulcast seat at DFIRCON Monterey this March. The contest ends on January 31st, 2014 and we will announce the winner on February 3rd, 2014. Good luck!

To successfully submit for the contest. All answers must be attempted. Please include your name and email address.

The winner will be able to choose from the below Simulcast courses at DFIRCON:

SEC504: Hacker Techniques, Exploits & Incident Handling
FOR408: Computer Forensic Investigations - Windows In-Depth
FOR508: Advanced Computer Forensic Analysis and Incident Response
FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques

* 1. What is the Process ID of the rogue process on the system?

* 2. Determine the name of the rogue file that is found in the process (PID) that contains the rogue process found in the above question.

* 3. How is the malware achieving persistence on the system?

* 4. What is the filename of the file that is hiding the presence of the malware on the system?

* 5. What is the name of the ISP that hosts the network where the malware is communicating with?

