Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Site Notices
Posted: 5/16/2017 5:51:48 PM EDT
I grabbed a pair of flash drives from the local Microcenter today. I went to use one and found a weird .LNK file on it. I say 'weird' because the name is in Chinese pictograph form. 

What's even weirder... while one of these drives was for my Mom, the other was purchased to be a Kali live boot stick. I wanted that so I could safely look into an SD card that was suspiciously placed outside the office building over the weekend. Talk about good timing!

Lets see... step one, make an image of the flash drive.
No, no...
Step One - get Kali installed on an old laptop we can't use (Vista license, non-upgraded)
Step Two - capture image of SD card AND both flash drives. 

I was thinking of paging B3cauzy to this thread, but then I decided it would be better more fun / intresting to see what I could come up with on my own. OK, with 'a little' help from Google and the Kali docs. 
Link Posted: 5/16/2017 5:54:29 PM EDT
[#1]
Most likely explanation is manual testing done at random on the product before it leaves the factory, but the tester screwed up on deleting one of the test files.
Link Posted: 5/16/2017 6:13:13 PM EDT
[#2]
The ChiComs aren't smooth operators.
Link Posted: 5/16/2017 6:15:44 PM EDT
[#3]
If you are concerned, set up a vm, and do a full format (not quick format).
Link Posted: 5/16/2017 7:09:07 PM EDT
[#4]
I'm not as much concerned as I am curious.

I expect 99.87% odds of neither drive being malicious. It is, however, a perfect learning opportunity. 
Link Posted: 5/17/2017 5:13:14 AM EDT
[#5]
lnk file is just a shortcut.  If you want, post the image file up on google drive and link it here, I'll take a look at it.
Link Posted: 5/17/2017 10:21:53 AM EDT
[#6]
The question is, a shortcut to where / what?

I fear this is an unintentional Found Safe post. Honest, I'll try to not let this drag on too long. (have to look into SQL running low on memory since the last MS patch run first)
Link Posted: 5/17/2017 10:25:17 AM EDT
[#7]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
The question is, a shortcut to where / what?

I fear this is an unintentional Found Safe post. Honest, I'll try to not let this drag on too long. (have to look into SQL running low on memory since the last MS patch run first)
View Quote
give me an image and I'll tell you...
Link Posted: 5/22/2017 11:28:20 AM EDT
[#8]
so whats the result of the random SD card you found? 
Link Posted: 5/22/2017 11:01:23 PM EDT
[#9]
According to RecoverJPEG and Foremost (in Kali), the SD card has 0 files on it. The flash drive is equally bereft of hidden / deleted garbage.

Kind of anticlimactic, imho. I was rather hoping this would not run the predictable Arf Safe Thread route, but alas....
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top