An incident has been created manually to investigate on a USB key infection. A system has been detected having a Raspberry Robin infection. The goal of this case is to find the USB key that was the source of the infection.
Whenever a USB key is plugged in a system, a registry key named USBSTOR is created on the SYSTEM registry hive.
The incident happened on 2022-06-16 05:44:40Z, which means that the USB key has to be plugged before or at the incident time.
Expanding the folder and clicking on the first sub folder, we manage to extract some interesting information regarding the USB key.
Serial # : 37DXYQWK7W33HB5M
First time connected : 2022-06-16 05:44:05Z
Last time connected : 2022-06-16 05:44:05Z
Last time removed : 2022-06-16 05-49-02Z
We see that the D drive letter was associated to the USB key JetFlash Transcend 16GDB&Rev_100. In the value you also find the serial number (37DXYQWK7W33HB5M)