Jan. 23, 2022, 6:46 p.m. | /u/NazgulNr5

Computer Forensics www.reddit.com

Hi there,

I'm analysing a memory dump from an infected system that is running a cryptominer and connecting to the mining server through a Tor router.

I know the processes of the miner and the tor router it installed on the system. Is there a way to show the miner handing over the IP of the actual mininf server to the Tor router?

The firewall of course just sees the connection to the next Tor router.

submitted by /u/NazgulNr5
[link] …

computerforensics host router tor tracing

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Information Security Manager & ISSO

@ Federal Reserve System | Minneapolis, MN

Forensic Lead

@ Arete | Hyderabad

Lead Security Risk Analyst (GRC)

@ Justworks, Inc. | New York City

Consultant Senior en Gestion de Crise Cyber et Continuité d’Activité H/F

@ Hifield | Sèvres, France