I'm currently working on a case where a computer has been identified on a corporate network as downloading a vast amount of data over a thirty-day period (approx 170GB). The uploading amounts to around 8GB. All of this data is coming from/going to one particular address. A quick bit of Googling has identified the computer is likely to have picked up a browser hijack which is diverting the traffic to this location in order to provide the user with 'relevant' advertising.
Using RegRipper and log2timeline I've identified that the user has downloaded and installed some software for a legit purpose, and is likely to have installed a toolbar as part of it. The toolbar has attached itself to an installation of Firefox. A look through the files that have been installed confirmed they are connected to this website, and that the user's browsing is being diverted in that direction.
I'm waiting on the Internet logs to be sent to me from IT - until then, has anybody got any suggestions regarding what could be generating this amount of traffic, or where I can LOOK to see what might be doing it?
A check of the local Internet history files doesn't indicate use of streaming sites like YouTube or any other movie sites. There isn't any P2P stuff installed either. I'm sure the logs will come back with some more info, but if they don't, I'm stumped on where else to look.
Thanks in advance,
HDRNR
Wireshark.
If that doesn't help, get sys internals as well and use procexplorer and procmon.
Thanks Xennith.
It's a little late in the day now, but I was contemplating virtualising the image (the machine cannot go back on the network) and running Wireshark to see what happens.
I will give the sysinternals tools a run in the morning and post my findings (if any).
Thanks again.
Sounds like some Browser Helper Object (BHO). HolaSearch is one of many such bits of software that hijack searches and can generate a lot of traffic. Have you looked into those?
If you can run the machine (real machine or virtualized one) run HiJackthis, it usually gets quickly any Registry key/file associated with BHO's
http//
jaclaz
A quick bit of Googling has identified the computer is likely to have picked up a browser hijack which is diverting the traffic to this location in order to provide the user with 'relevant' advertising.
Okay, if I understand this correctly, you Googled the issue rather than actually analyzing the system?
A quick bit of Googling has identified the computer is likely to have picked up a browser hijack which is diverting the traffic to this location in order to provide the user with 'relevant' advertising.
Okay, if I understand this correctly, you Googled the issue rather than actually analyzing the system?
No, you don't understand correctly; perhaps I phrased it poorly. For the record (and so people don't read your comment and think I'm just another two-bit point-and-click examiner), I thoroughly analysed this computer to the best of my abilities using the tools I have, and have identified the entry point for this software, the changes this software has made on the computer, and the behaviour of this software. All this I detailed in my original post.
I came here to ask other examiners if they have had any experience of such software, or if they could provide advice on any other local locations I can check with regards to the excessive bandwidth usage, so that I may also better my knowledge.
If you can provide me with any help with this, or believe there is something I have not done or missed, I will gladly take your advice onboard, and use it to further my investigation. As you can see from the posts above yours and below mine, others are already providing such help.
Thanks to Xennith, BitHead and jaclaz. I will try your suggestions out tomorrow. BitHead this the SmartBar toolbar, which I guess is the same animal as HolaSearch. Thanks again for your help.
Harlan, I apologise if I've come across as rude. It's been a long day. I have the utmost respect for you, however I would appreciate it if you could make your posts a little less sharp and little more helpful. The purpose of this forum is for people to learn and to share. Right now, I'm looking to learn.
Thanks. Andrew.
For the record, there is a Smartbar (linked to snap.do) and a Linkury Smartbar, this latter seemingly much more "naughty" and "persistent".
http//
http//
http//
Also, judging form the Registry keys listed here
http//
http//
it really seems something "insecure".
jaclaz