Professional Documents
Culture Documents
Kericu, Inc.
Lorenze Salas
Kericu, Inc.
In this Final Project, I downloaded the “Lewis-USB.dd” in the CFR225 files on the
Canvas website. After downloading the file, I search .dd on the web browser. DD (.dd) is a disk
image file in a Unix and Linux operating system environment of a hard disk drive. I used
USB.dd” in the downloads folder. After finding the .dd file, it shows FAT16, a file allocation
table that has 2 bytes per cluster with a cluster limit between 4087 and 65526 clusters, file
system in the USB drive. In the root folder, it has 6 deleted files containing 2 documents, 2
excels, and 2 tmp files. TMP is another file extension that creates an invisible file and is often
deleted when the program is closed… created to contain information temporarily while a new
file is being generated” ("TMP file extension," n.d.).The files were modified between 4 th and 8th
To do the hash values, I simply right clicked the 6 deleted files, then exported file hash list, and
name the file “LewisUSB”. It shows a excel spread sheet included the MD5, SHA1, FileNames
Lastly, I opened Autopsy, then created a case, and add “Lewis-usb.dd” as my data source
in the Disk Image or VM File. I configured the first 11 ingest modules, clicked next, and the
they matched the same MD5 hash files that were in the
In the extracted content, on the metadata section, there is 5 source files that was owned by Aiden
Paluchi and Lewis in the Kericu, Inc. organization. In the S column, there is 4 red indicators,
meaning that the hash lookup is bad and unallocated. With the mission statement document, the
Between these two earning spreadsheets, they have the same sales expenses, development
expenses, HR expenses, legal expenses, IT expenses, security expenses, and consulting income.
With the original earnings spreadsheets (on the right), it has the following:
With the editing earnings spreadsheets (on the left), it has the following:
There is a $7 million USD difference between these two spreadsheets. In Lewis’s USB, Aiden
Paluchi tampered to change the documentation destruction expenses, product income, and legal
settlements income to make it more standout. Mr. Paluchi can be charged with an accounting
fraud, which a “company can falsify its financial statements by overstating its revenue, not
References
Fat12, fat16, fat32. File system structure. (n.d.). Find and Restore Lost Files: Undelete deleted
file-system-fat.htm
fraud? Investopedia. https://www.investopedia.com/ask/answers/032715/what-
accounting-fraud.asp
Database. https://fileinfo.com/extension/tmp
Extensions. https://www.whatisfileextension.com/dd/