Showing posts with label Foreniscs. Show all posts
Showing posts with label Foreniscs. Show all posts

7/24/2026

Case 04 Time Zone

 

DIGITAL FORENSICS PENETRATION TEST REPORT

Target Investigation: Time Zone Alignment & Prefetch Analysis

Customer / Target Unit:

NewmindSet Co., Ltd. (新心資安科技)

Report Date:

May 23, 2026

Acquisition Period:

July 18, 2026 (09:00 - 18:00)

Reporting Period:

July 25, 2026 – August 1, 2026 (09:00 - 18:00)

 

1. Executive Summary

This penetration and digital forensics investigation target—code-named "Time Zone"—represents the digital forensics findings conducted on an internal office workstation at NewmindSet Co., Ltd. The investigation was initiated following research into Dark Web forensics using Tor Onion Browser (based on CHFI methodologies), which highlights that if a suspect has uninstalled Tor, forensic investigators must analyze Windows Prefetch files to reconstruct execution history.

During the analysis of Prefetch files on the author's primary workstation, the Prefetch parser indicated that Adobe PDF Reader (ACROBAT.EXE) had been executed at 03:00 AM on two consecutive days. Given that standard office hours strictly run from 09:00 AM to 10:00 PM (with workstations powered off overnight), this initial finding suggested anomalous off-hours activity.

Persevering through deep-dive investigative verification revealed that forensic utilities default to Coordinated Universal Time (UTC+00:00), whereas local office operations run on Taipei Time (UTC+08:00 / GMT+8). Adjusting the timestamp by +8 hours shifted the reported 03:00 AM execution time to 11:00 AM during normal working hours. Multi-tool cross-validation fully verified system integrity and eliminated suspected unauthorized access.

2. Purpose and Scope

The primary objective of this digital forensics assessment is to demonstrate NewmindSet Co., Ltd.'s digital forensics capabilities through a standardized and thorough reporting structure. This report serves as a benchmark for prospective clients to evaluate forensics standards and align their technical requirements when commissioning external forensic investigations.

Forensic Insights & Structured Analysis Framework

·         Note Title: Cross-Validation of Forensic Artifacts via Adobe PDF Reader Execution Timestamps at 03:00 AM.

·         Knowledge Context: Although Windows 11 removed the native Timeline feature, specialized digital forensic utilities can reconstruct complete application execution history. Practicing forensics on a personal workstation provides a clear baseline due to highly deterministic user schedules.

·         Core Principles: Forensic utilities standardize all artifact timestamps to UTC+00:00 (Coordinated Universal Time) to ensure consistent global evidence interpretation and chain of custody communication.

·         Associative Reasoning: Had the anomalous 03:00 AM PDF access record not appeared, the timezone settings of the forensic parser might have gone unverified. Multi-tool cross-referencing provided conclusive proof of normal usage.

·         Applied Takeaways: Beyond Adobe PDF Reader, forensic artifact timestamps across various applications must strictly account for UTC offsets during client-side evidence preservation and incident response engagements.

·         Actionable Directives: When leveraging AI models to parse timestamped log files, AI prompts must explicitly enforce timezone conversion to GMT+08:00 (Taipei Time) prior to reporting findings.

Forensic Toolkit Specification
Tool Deployment & Setup Directory:
• Tools repository: https://ericzimmerman.github.io/
• Installation directory: D:\ or C:\
• PECmd.exe (Prefetch Explorer Command Line): High-performance Windows Prefetch (.pf) parser developed by Eric Zimmerman.
• LECmd.exe (Lnk Explorer Command Line): Windows Shortcut (.lnk) binary file parser developed by Eric Zimmerman.
• Event Viewer: Native Windows OS Event Log audit interface.

 

3. Forensic Methodologies and Workflow

The forensic acquisition and analysis strictly adhered to international digital evidence handling standards, primarily ISO/IEC 27037 (Guidelines for identification, collection, acquisition, and preservation of digital evidence).

ISO/IEC 27037 Operational Stages

·         Identification: Pinpointing physical and virtual media containing potential evidentiary data.

·         Collection: Properly isolating, documenting, and securing physical hardware or logical drives.

·         Acquisition: Creating bit-stream forensic images without altering raw source data.

·         Preservation: Maintaining strict chain-of-custody and verifying evidence integrity via cryptographic hash values (MD5 / SHA-256).

Scope of Inspection & Timeline

·         Prefetch Artifact Analysis: Parsing C:\Windows\Prefetch\ACROBAT.EXE-4E1700B6.pf to evaluate program execution history and timestamp records.

·         Shortcut Analysis (.lnk): Examining recent file shortcuts to establish file access chronology.

·         Windows Security Event Logs: Auditing logon events, account privilege usage, and system security logs.

·         Integrity Verification: Computing and recording MD5 hashes for all acquired artifact files.

4. Forensic Findings and Risk Assessment

Anomalous Timestamp ResolutionFindings Summary:

Following UTC timezone conversion (+08:00), the initial 03:00 AM execution timestamp was recalibrated to 11:00 AM across two consecutive days. This perfectly aligns with normal office business hours.

Investigation Deep-Dive

·         Artifact Category: Application Execution (Prefetch / .lnk)

·         Impacted OS Framework: Cross-platform operating systems (Linux, Windows)

·         Root Cause Analysis: Forensic tools interact with low-level Windows kernel artifacts natively recorded in UTC (GMT+00:00). Initial AI model queries incorrectly assumed input timestamps were in local GMT+08:00 (Taipei Time), misflagging 11:00 AM activity as 03:00 AM off-hours activity.

Potential Operational Risks & Impact Assessment

Because office workstations are completely powered down and disconnected overnight (making Wake-on-LAN impossible), a genuine 03:00 AM access event would indicate physical intrusion or compromise. Initial investigation eliminated physical access (post-examination fatigue) and isolated the anomaly to automated timestamp parsing errors.

5. Forensic Recommendations and Strategy

·         AI Model Peer Review & Verification: Initial Google Gemini model evaluations indicated forensic tools parsed local timezone settings (GMT+08:00). Secondary validation with OpenAI ChatGPT confirmed that raw forensic tools parse artifacts in UTC (GMT+00:00). Multi-LLM verification is recommended for automated log analysis.

·         Multi-Source Artifact Cross-Validation: Forensic conclusions on Windows systems must never rely on a single artifact. Corroboration across Event Viewer, File System metadata (MFT), and Prefetch/LNK artifacts is mandatory before issuing final findings.

6. Conclusion

This digital forensic evaluation concludes with two pivotal takeaways:

·         LLM & Tooling Boundaries: Artificial Intelligence and automated forensic scripts have operational boundaries and can hallucinate or misinterpret raw timeframes. Human oversight and timezone awareness are essential.

·         Forensic Rigor: Forensic investigators must exercise continuous skepticism and rigorous cross-verification prior to finalizing intrusion conclusions.

7. Appendices and Reference Artifacts

Step 1: PECmd Prefetch Parsing Raw Output

Command Executed: pecmd -f C:\Windows\Prefetch\ACROBAT.EXE-4E1700B6.pf

PECmd version 2026.5.0

Author: Eric Zimmerman (saericzimmerman@gmail.com)

https://github.com/EricZimmerman/PECmd

Command line: -f C:\Windows\Prefetch\ACROBAT.EXE-4E1700B6.pf

Keywords: temp, tmp

Processing C:\Windows\Prefetch\ACROBAT.EXE-4E1700B6.pf

Created on: 2024-08-12 13:31:43

Modified on: 2026-07-09 09:35:57

Last accessed on: 2026-07-10 09:56:41

Executable name: ACROBAT.EXE

Hash: 4E1700B6

File size (bytes): 184,868

Version: Windows 10 or Windows 11

Run count: 1,501

Last run: 2026-07-09 09:35:46

Other run times: 2026-07-09 09:32:09, 2026-07-09 09:19:49, 2026-07-09 08:52:28, 2026-07-08 09:48:07, 2026-07-08 07:51:50, 2026-07-08 03:03:32, 2026-07-07 03:41:53

Volume information:

#0: Name: \VOLUME{01d6278415e81c2f-b6163964} Serial: B6163964 Created: 2020-05-11 11:05:31

Directories referenced: 19 | Files referenced: 124

 

Step 2: LECmd LNK Shortcut Parsing Raw Output

Analysis of Recent Document Shortcuts (.lnk):

Source file: C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\HuaNan_D&O_Liability_Insurance_v3.lnk

  Source created:  2023-01-16 11:25:32

  Source modified: 2023-01-16 11:26:22

  Source accessed: 2026-07-10 10:59:55

--- Header ---

  Target created:  2022-12-21 12:19:56

  Target modified: 2023-01-16 11:26:21

  Target accessed: 2023-01-16 11:26:22

  File size (bytes): 4,096

  Flags: HasTargetIdList, HasLinkInfo, IsUnicode, DisableKnownFolderTracking

--- Extra blocks information ---

>> Tracker database block

   Machine ID:  desktop-pj689uv

   MAC Address: 30:9c:23:87:6c:f4 (MICRO-STAR INTL)

   Creation:    2022-12-21 10:06:16

>> Link Information:

   Drive type: Removable storage media (USB)

   Volume Label: NeoTech | Serial: 0C83CE92

 


Case 04 Time Zone

  DIGITAL FORENSICS PENETRATION TEST REPORT Target Investigation: Time Zone Alignment & Prefetch Analysis Customer / Targe...