Did Nobody See?Forensics 未解决
分数:
0
金币:
0
题目作者:
未知
一 血:
viphhs
一血奖励:
0金币
解 决:
1
提 示:
描 述:
We recently obtained a triage image from a Windows laptop belonging to a suspected ransomware operator. The suspect used several anti-forensic techniques and managed to erase any form of web history. We suspect that we may be able to use data from DNS servers as evidence to tie the suspect to the operation. Unfortunately, the suspect was using a VPN. Can you find any DNS servers used during the VPN connection?
The answer will be in the form of byuctf{ip.address}
(there may be multiple answers, any valid IP address for the DNS server will work for the answer).
