312-49 · Question #350
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?
The correct answer is D. Nothing in particular as these can be operational files. While the t0rn rootkit is known to drop files with similar-sounding names, finding files named 'Zer0.tar.gz' and 'copy.tar.gz' alone is not conclusive evidence of compromise. These could legitimately be backup archives or operational files created by an administrator. Forensic co
Question
If you see the files Zer0.tar.gz and copy.tar.gz on a Linux system while doing an investigation, what can you conclude?
Options
- AThe system has been compromised using a t0rnrootkit
- BThe system administrator has created an incremental backup
- CThe system files have been copied by a remote attacker
- DNothing in particular as these can be operational files
How the community answered
(25 responses)- A4% (1)
- B8% (2)
- D88% (22)
Explanation
While the t0rn rootkit is known to drop files with similar-sounding names, finding files named 'Zer0.tar.gz' and 'copy.tar.gz' alone is not conclusive evidence of compromise. These could legitimately be backup archives or operational files created by an administrator. Forensic conclusions must be based on corroborating evidence (file hashes, unexpected processes, modified system binaries, etc.), not filenames alone. Jumping to the conclusion that the system has a rootkit (A) or was attacked (C) based solely on file names would be an investigative error.
Topics
Community Discussion
No community discussion yet for this question.