Blue Team Labs Online - Thumbs Up

A new superweapon concept art plans were leaked from a hungarian research center.
Digital Forensics
Tags: Thumbcache Viewer PowerShell Google Image Search
Scenario A new superweapon concept art plans were leaked from a hungarian research center. Before our Operative Threat Hunter Team found the presumed guilty, he deleted all of the pictures/documents from his laptop.
All of the DFIR team members are working hard to get back the data, now you got a piece of the evidences to work on. Find related evidences and prove the original concept art plans was on this computer.
Environment Awareness
Evidence & Tool Discovery

We have a single folder on the desktop that we can use to solve this investigation and inside this folder, there are 3 more subfolders inside of it which contains thumbcache files, original concept art and thumbcache viewer that will be used to open thumbcache files.
Investigation
Q1) How many entries are there in the iconcache_16.db?

After open iconcache_16.db in thumbcache viewer, we can see that there are total of 370 entries that recognized by thumbcache viewer
Answer
370
Q2) How many .db files are empty?

We can take a look at .db files inside Evidence folder which we can see that there are 3 db files with 1KB file size indicates that its not store any data but database structure.
Answer
3
Q3) Which vpn client was used to connect other computers securely?

After searching for a while then we will come across this icon at entry 119 and if you searched for this icon on Google then you will see that this is an icon of openvpn
Answer
openvpn
Q4) What is the name of the PDF reader they used?

Scroll down to entry 123 then we will see this icon

Which is an icon of Javelin PDF Readers
Answer
Javelin
Q5) There are maps saved to plan the stealing operation. What is the name of the city where the research lab is (inside a hill)?

After browsing thumbcache_1280.db, we can see a map that was opened by user and this map leads to Zirc
Answer
Zirc
Q6) What was the operation name?

We can also see the name of the operation from thumbcache_1280.db as well which we can see that the silhouette really resembled concept art we have.
Answer
STEALTHTAURUS
Q7) What is the first recognizable, 256px wide concept art picture's Cache Entry Hash?

We can see all 3 of concept art within these thumbcache but the first recongizable one is this image that resembled taurus03.jpg file and we can copy value inside Cache Entry Hash field to answer this question
Answer
8c6951f58d98fde9
Q8) What is the md5 sum of the previously mentioned file?

We can right click and "Save Selected..." to save this cache image file to our desired location

Then we can use available tool such as certutil or Get-FileHash cmdlet to calculate MD5 hash of this file like this
Answer
c8f2dc1db01247a38af6ba74edfd3a2c
https://blueteamlabs.online/achievement/share/52929/159