2 \newpage\section{Questions (12 points)}
3 \subsection{How and when did Mr. Smith and Mr. Mayer communicate? (2 point)}
4 \begin{center}\begin{tabularx}{\textwidth}{| l | l | l | X | }
5 \hline service & timestamp & (from) to & content\\
6 \hline skype & 27-11-2012 12:20:00 & to:allegro.mayer from:johannes.m.smith & Auth\_Request\\
7 \hline skype & 06-12-2012 13:20:33 & from:allegro.mayer to:johannes.m.smith & Auth\_Granted\\
8 \hline call & 2012-12-06 14:35:38 & Johannes Smith 06603169718 & (0:01:15 sec)\\
9 \hline skype & 06-12-2012 16:33:53 & to:allegro.mayer from:johannes.m.smith & "Hallo"\\
10 \hline sms & 2012-12-06 17:20:46 & to +436603169718 & Ich habe wichtige Informationen über unseren letzten deal für dich. Ruf dich später an, wenn ich ungestört bin.\\
11 \hline sms &2012-12-06 17:30:43 & to +436603169718 & Sicherer kanal wär besser ....\\
12 \hline viber call & 2012-12-06 17:31:57 & Johannes Smith & (71 sec)\\
13 \hline sms & 2012-12-06 17:36:26 & from +436605166042 & Hallo, ich empfehle dir den WhatsApp Messenger für Android, iPhone, Nokia, BlackBerry und Windows Phone auf http://whatsapp.com/dl/\\
14 \hline sms & 2012-12-06 17:42:50 & to +436605166042 & Viel zu unsicher, hab mir vor kurzem einen ganz tollen vortrag darüber angehört...\\
15 \hline sms & 2012-12-06 17:45:19 & to +436605166042 & Ich hab von einem kollegen wichtige informationen. Ruf dich an\\
16 \hline call & 2012-12-06 17:45:36 & Johannes Smith +436605166042 & (0:00:21 sec; diensthandy? DumpBank We Sell Your Shit)\\
18 \end{tabularx}\end{center}
21 \subsection{What information was exchanged between Mr. Smith and Mr. Mayer? (3 points)}
22 dropbox extracted from android. no time now. mutter kollabiert gerade.\\
24 \subsection{Can you find any evidence or hints that support the suspicion of insider trade? (3 points)}
25 No hard evidence was found.\\
26 The fact that both parties looked up stock trading sites could hint at that.\\
27 Also communication between Mayer and Smith does not give a definite proof that they really did anything.
30 \subsection{Was the person that the witness identified really Mr. Mayer? (2 points)}
31 As Mayer was in Paris on Friday, 7th of December 2012, late afternoon it seems unlikely that a witness saw them.\\
32 Unless of course Mayer and Smith met in Paris which could be hinted at by the FILE in the dropbox-directory and the witness too was in Paris at that time.
34 \subsection{Mr. Mayer seems to have more secrets than initially expected. What is his big secret? (2 points)}
35 By using MAYRS EMAIL address, we found out, that he is engaged with NAME.\\
36 Communication suggests that MAYR + Laura were on a romantic trip in Paris.
41 \newpage\section{iPhone}
42 \subsection{Source: iPhone.tar.gz (IPBA)}
43 iPhone backup image from Allegro Mayer's Phone. The extracted files were analysed with iP Backup Analyzer2.
45 \textbf{size}: 6775181 byte\\
46 \textbf{''file''-output}: gzip compressed data, last modified: Fri Dec 14 11:42:54 2012, from Unix\\
47 \textbf{sha512}\\\ttfamily{
48 ff746e574a0d668e1d82c3ff72501a75eabe642e1dee7f20d3d74b9fe72054f9\\
49 9b9a91ded1b3f98067a63065423c620c73c42c65e13c3b110424854b3e7f6678}
54 The contacts-db was extracted from \emph{\textbf{IPBA::Home Domain:Library/AddressBook/AddressBook.sqlitedb}}
56 \textbf{size}: 87040 byte\\
57 \textbf{''file''-output}: SQLite 3.x database\\
58 \textbf{sha512}\\\ttfamily{
63 \begin{center}\begin{tabular}{ | l | r | }
64 \hline Name & Phone \\
65 \hline <None> & +436603169718 \\
66 \hline Laura Markovic & 0680 3303660 \\
67 \hline Sabine Oberhuber & +436604413637 \\
68 \hline Johannes Smith & +43 660 5166042 \\
69 \hline Ernst Strasser & 0660 4394199 \\
71 \end{tabular}\end{center}
75 The call-log was extracted from \emph{\textbf{IPBA::Wireless Domain:Library/Callhistory/call\_history.db}}
78 \textbf{''file''-output}: SQLite 3.x database\\
79 \textbf{sha512}\\\ttfamily{
84 \begin{center}\begin{tabular}{ | l | l | l | l | }
85 \hline date & to/from & Phonenumber & duration (sec)\\
86 \hline 2012-12-06 13:35:38 & to & 06603169718 & 75\\
87 \hline 2012-12-06 14:02:20 & to & 06803303660 & 0\\
88 \hline 2012-12-06 14:03:02 & from & +436605969364 & 23\\
89 \hline 2012-12-06 14:08:34 & to & 0660303010 & 0\\
90 \hline 2012-12-06 14:10:02 & to & 0660303030 & 1181\\
91 \hline 2012-12-06 15:17:05 & to & 0660303030 & 1023\\
92 \hline 2012-12-06 15:34:30 & to & 0660303030 & 864\\
93 \hline 2012-12-06 16:00:10 & from & +436605166042 & 17\\
94 \hline 2012-12-06 16:08:02 & to & 06604394199 & 9\\
95 \hline 2012-12-06 16:25:30 & from & +436605166042 & 0\\
96 \hline 2012-12-06 16:26:11 & from & +436605166042 & 0\\
97 \hline 2012-12-06 16:34:39 & to & 06604394199 & 6\\
98 \hline 2012-12-06 16:34:52 & to & 06604394199 & 12\\
99 \hline 2012-12-06 16:35:10 & to & 06604394199 & 23\\
100 \hline 2012-12-06 16:45:36 & to & +436605166042 & 21\\
102 \end{tabular}\end{center}
105 \subsection{SMS/iMessage}
106 The SMS-Database was extracted from \emph{\textbf{IPBA::Home Domain:Library/SMS/sms.db}}
108 \textbf{size}: byte\\
109 \textbf{''file''-output}: SQLite 3.x database\\
110 \textbf{sha512}\\\ttfamily{
116 \begin{center}\begin{tabularx}{\textwidth}{| l | l | l | l | X | }
117 \hline date & from/to & number & service & text\\
118 \hline 2012-12-06 16:17:20 & from & Viber & SMS & Your Viber code is: 9386 Close this message and enter the code into Viber to activate your account.\\
119 \hline 2012-12-06 16:20:46 & to & +436603169718 & SMS & Ich habe wichtige Informationen über unseren letzten deal für dich. Ruf dich später an, wenn ich ungestört bin\\
120 \hline 2012-12-06 16:30:43 & to & +436603169718 & SMS & Sicherer kanal wär besser ....\\
121 \hline 2012-12-06 16:33:58 & to & +436604413637 & iMessage & Hi wie gehts? Treffen wir und mal auf einen drink?\\
122 \hline 2012-12-06 16:36:26 & from & +436605166042 & SMS & Hallo, ich empfehle dir den WhatsApp Messenger für Android, iPhone, Nokia, BlackBerry und Windows Phone auf http://whatsapp.com/dl/\\
123 \hline 2012-12-0616:42:50 & to & +436605166042 & SMS & Viel zu unsicher, hab mir vor kurzem einen ganz tollen vortrag darüber angehört...\\
124 \hline 2012-12-0616:45:19 & to & +436605166042 & SMS & Ich hab von einem kollegen wichtige informationen. Ruf dich an\\
126 \end{tabularx}\end{center}
129 \subsection{Calendar}
130 The Calendar-Database was extracted from \emph{\textbf{IPBA::Home Domain:Library/Calendar/Calendar.sqlitedb}}
132 \textbf{size}: byte\\
133 \textbf{''file''-output}: SQLite 3.x database\\
134 \textbf{sha512}\\\ttfamily{
139 \begin{center}\begin{tabular}{| l | l | l | l | }
140 \hline event & start & end & location\\
141 \hline Paris geschäftsreise & 2012-12-07 14:00:00 & 2012-12-09 19:00:00 & Paris\\
142 \hline Meeting & 2012-12-10 10:00:00 & 2012-12-10 11:00:00 & Zbank\\
143 \hline Nordic walking & 2012-12-11 07:00:00 & 2012-12-11 07:30:00 & \\
144 \hline Statusmeeting & 2012-12-11 08:00:00 & 2012-12-11 12:00:00 & \\
146 \end{tabular}\end{center}
150 The plist \emph{\textbf{IPBA::HomeDomain:Library/Safari/History.plist}} opened with IPBA2 plist-viewer cointains the browser history.
152 \begin{center}\begin{tabularx}{\textwidth}{| l | X | X |}
153 \hline timestamp & title & url \\
154 \hline 2012-12-07 09:03:15 & Flughafen Wien - Abflüge - Offen für neue Horizonte & https://www.google.at/url?sa=t\&source=web\&cd=3\&ved=0CD0QjBAwAg\&url=http\%3A\%2F\%2Fwww.viennaairport.com\%2Fjart\%2Fprj3\%2Fva\%2Fmain.jart\%3Frel\%3Dde\%26content-id\%3D1249344074230\%26reserve-mode\%3Dactive\&ei=jLDBULjlB8bE4gTn-oGABw\&usg=AFQjCNHU5R5b3WsiOhYSIsli3inGLTEFGQ\\
155 \hline 2012-12-07 09:02:03 & flughafen wien - Google-Suche & https://www.google.at/search?q=flughafen+wien\&ie=UTF-8\&oe=UTF-8\&hl=de\&client=safari\\
156 \hline 2012-12-07 09:01:54 & Laura Markovic & https://m.facebook.com/laura.markovic.129?\_\_user=100004760941674\\
157 \hline 2012-12-06 16:14:19 & RNS News - London Stock Exchange & http://m.londonstockexchange.com/exchange/mobile/news/detail.html?announcementId=11421386\\
158 \hline 2012-12-06 16:14:14 & FTSE AIM 100 - London Stock Exchange & http://m.londonstockexchange.com/exchange/mobile/indices/summary.html?index=AIM1\\
159 \hline 2012-12-06 16:14:07 & Homepage - London Stock Exchange & https://www.google.at/url?sa=t\&source=web\&cd=1\&ved=0CEQQFjAA\&url=http\%3A\%2F\%2Fm.londonstockexchange.com\%2Fexchange\%2Fmobile\%2Fhomepage.html\&ei=ScTAUPK8FMfKtAaQq4GYBQ\&usg=AFQjCNE22q6svVgMrwz\_D7x-iD0srW0nTw\\
160 \hline 2012-12-06 16:14:00 & stock exchange london - Google-Suche & https://www.google.at/search?q=stock+exchange+london\&ie=UTF-8\&oe=UTF-8\&hl=de\&client=safari\\
161 \hline 2012-12-06 16:10:22 & Ohne Anstehen: Tickets Eiffelturm \& Rundgang Rive Droite, | Mobil - GetYourGuide.com & http://www.getyourguide.de/paris-l16/ohne-anstehen-tickets-eiffelturm-rundgang-rive-droite-t25185/\#calendar\\
162 \hline 2012-12-06 16:10:03 & Ohne Anstehen: Tickets Eiffelturm \& Rundgang Rive Droite, | Mobil - GetYourGuide.com & http://www.getyourguide.de/paris-l16/ohne-anstehen-tickets-eiffelturm-rundgang-rive-droite-t25185/\\
163 \hline 2012-12-06 16:09:56 & Paris: Touren, Ausflüge \& Aktivitäten | Mobil - GetYourGuide.com & https://www.google.at/aclk?sa=l\&ai=Cw0lOT8PAUNn8BIaX0wXeoYHwD43W1e0EldC\_uXSaooQJCAAQAiD4mYsSKAJQw5HQuPv\_\_\_\_\_AWCpsL6AzAGgAYutzM0DyAEBqQJiko-yhe21PqoEIk\_QmH99e-Hnj0NaSGjzY1ceX0oZt9LcfH\_ckQNETkSVs7yABZfgvAvYBgI\&sig=AOD64\_3cmbdhf4eRcAjv\_a9FMrltcGuHTA\&ved=0CC0Q0Qw\&adurl=http://21.xg4ken.com/media/redir.php\%3Fprof\%3D89\%26camp\%3D65425\%26affcode\%3Dkw720159\%26inhURL\%3D\%26cid\%3D31229666013\%26networkType\%3Dsearch\%26url\%5B\%5D\%3Dhttp\%253A\%252F\%252Fwww.getyourguide.de\%252Fparis\%252Fsightseeing-touren-ltc16-2\%252F\%253Fpartner\_id\%253DCD951\\
164 \hline 2012-12-06 16:09:50 & paris sightseeing - Google-Suche & https://www.google.at/search?q=paris+sightseeing\&ie=UTF-8\&oe=UTF-8\&hl=de\&client=safari\\
165 \hline 2012-12-06 16:08:58 & Laura Markovic & https://m.facebook.com/laura.markovic.129?\_\_user=100004760941674\#!/laura.markovic.129?\_\_user=100004760941674\&soft=jewel\%3D2\\
166 \hline 2012-12-06 16:08:49 & Facebook & https://m.facebook.com/home.php?refid=9\#!/laura.markovic.129?\_\_user=100004760941674\\
167 \hline 2012-12-06 13:56:39 & Facebook & http://m.facebook.com/?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&\_rdr\#!/home.php?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&soft=side-area\&\_\_user=100004760941674\\
168 \hline 2012-12-06 13:55:36 & Facebook & http://facebook.com/\\
169 \hline 2012-12-06 13:51:26 & Facebook & https://m.facebook.com/home.php?refid=9\#!/home.php?soft=side-area\&\_\_user=100004760941674\\
170 \hline 2012-12-06 13:50:58 & Facebook & https://m.facebook.com/home.php?refid=9\#!/home.php?soft=jewel\%3D0\&\_\_user=100004760941674\\
171 \hline 2012-12-06 13:46:54 & Facebook & https://m.facebook.com/login.php?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&landing\_serial=2\&refid=9\\
172 \hline 2012-12-06 13:46:08 & Willkommen bei Facebook & https://m.facebook.com/login.php?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&landing\_serial=1\&refid=8\\
174 \end{tabularx}\end{center}
178 The plist \emph{\textbf{IPBA::SystemPreferencesDomain:SystemConfiguration/com.apple.wifi.plist}} opened with IPBA2 plist-viewer cointains a list of Wireless Networks the phone has joined.\\
180 \begin{center}\begin{tabular}{| l | l | l |}
181 \hline ssid & last join & last autojoin \\
182 \hline tunet & 2012-12-06 90:41:55 & \\
183 \hline VirtualRouter & 2012-12-06 09:38:00 & 2012-12-06 09:45:45 \\
184 \hline pornhub & 2012-12-06 11:51:01 & 2012-12-06 16:05:07 \\
186 \end{tabular}\end{center}
190 Images were extracted from \emph{\textbf{IPBA::CameraRollDomain:Media/DCIM/100APPLE}}\\
192 Screenshot of Facebook-App showING a photograph of a woman. Laura Markovic (\url{https://www.facebook.com/laura.markovic.129}) seems to be tagged in that photograph.
194 \textbf{size}: byte\\
195 \textbf{''file''-output}: SQLite 3.x database\\
196 \textbf{sha512}\\\ttfamily{
200 Screenshot from Maps-App showing directions within Paris.
202 \textbf{size}: byte\\
203 \textbf{''file''-output}: SQLite 3.x database\\
204 \textbf{sha512}\\\ttfamily{
208 Showing some statistics about company shares.
210 \textbf{size}: byte\\
211 \textbf{''file''-output}: SQLite 3.x database\\
212 \textbf{sha512}\\\ttfamily{
217 \subsection{Viber-App}
218 The Viber-Database was extracted from \emph{\textbf{IPBA::AppDomain:com.viber/Documents/Contacts.data}}
220 \textbf{size}: byte\\
221 \textbf{''file''-output}: SQLite 3.x database\\
222 \textbf{sha512}\\\ttfamily{
227 \begin{center}\begin{tabular}{| l | l | l | l | l |}
228 \hline timestamp & to/from & number & name & duration (sec)\\
229 \hline 2012-12-06 16:27:32 & to & 436803303660 & Laura Markovic & 0\\
230 \hline 2012-12-06 16:31:57 & to & 436605166042 & Johannes Smith & 72\\
232 \end{tabular}\end{center}
235 \subsection{Skype-App}
236 The Skype-Database was extracted from \emph{\textbf{IPBA::AppDomain:com.viber/Documents/Contacts.data}}
238 \textbf{size}: byte\\
239 \textbf{''file''-output}: SQLite 3.x database\\
240 \textbf{sha512}\\\ttfamily{
245 \begin{center}\begin{tabularx}{\textwidth}{| l | l | l | l | X |}
246 \hline timestamp & to/from & Skype id & name & content\\
247 \hline 2012-11-27 12:20:00 & from & johannes.m.smith & Johannes Smith & Hallo! Ich wüurde Sie gerne in meine Skype-Kontaktliste aufnehmen. Johannes Smith\\
248 \hline 2012-12-06 13:20:33 & to & johannes.m.smith & Johannes Smith & \\
249 \hline 2012-12-06 13:20:57 & to & christoffel.johannes.smith & Chris Smith & Fügen Sie mich als Kontakt hinzu, damit wir anrufen und chatten können\\
250 \hline 2012-12-06 13:21:33 & to & addy-juli & Julia & Fügen Sie mich als Kontakthinzu, damit wir anrufen und chatten können.\\
251 \hline 2012-12-06 16:33:51 & from & johannes.m.smith & Johannes Smith & Hallo\\
253 \end{tabularx}\end{center}
256 \subsection{Dropbox-App}
257 The plist \emph{\textbf{IPBA::AppDomain:com.getdropbox.Dropbox/Library/Preferences/com.getdropbox.Dropbox.plist}} opened with IPBA2 plist-viewer cointains a field \emph{\textbf{Dropbox Username}} and the email-address \emph{\textbf{allegro.mayer\@gmail.com}}\\
259 Also the field \emph{\textbf{Dropbox Camera Upload Has Ever Uploaded}} is \emph{\textbf{true}}\\
262 \subsection{Facebook-App}
263 The plist \emph{\textbf{IPBA::AppDomain:com.facebook.Facebook/com.facebook.Facebook.plist}} opened with IPBA2 plist-viewer cointains a field \emph{\textbf{FBLastLoginEmail}} and the email-address \emph{\textbf{allegro.mayer\@gmail.com}}\\
265 Searching of FB reveales the link to the profile: \url{https://www.facebook.com/allegro.mayer}.\\
266 That About-Page states his relationship status is married to Mrs. Ilse Mayer-Brandl (profile: \url{https://www.facebook.com/ilse.mayerbrandl}).\\
268 Relevant FB-postings by Allegro Mayer:\\
269 On December 7. 2012 11:54 at Flughafen Wien, Vienna Airport, Austria.
270 \begin{quote}On my way to Paris\end{quote}
272 On December 7. 2012 14:17 at Paris, with Laura Markovic (\url{https://www.facebook.com/laura.markovic.129}).
273 \begin{quote}enjoying a romantic weekend with my dearest love in Paris!\end{quote}
280 \newpage\section{Android}
281 \subsection{Source: Android.tar.gz (ANDROID)}
282 Android image from Johannes Maskus Smith's phone.
284 \textbf{size}: 270397822 byte\\
285 \textbf{''file''-output}: gzip compressed data, last modified: Fri Dec 14 12:06:37 2012, from Unix\\
286 \textbf{sha512}\\\ttfamily{
287 9614e30affc09d1cbfad5a96e43b2e40dae3c5c123db22dcbd53e980d14418d9\\
288 ab18c6a2b5b9f8a0e1539474612a4a7ceae627255a2169565f0dddf3409ef67d}
291 \subsection{Contacts}
292 \subsection{Call-Log}
295 \subsection{eMail-App}
296 \subsection{Viber-App}
297 \subsection{Skype-App}
298 \subsection{Whatsapp-App}
299 \subsection{Dropbox-App}
300 \subsection{Facebook-App}
303 \newpage\section{Details}
304 \subsection{Used tools on GuestVM}
305 Tools that were used for analysis (-{}-version):
307 \item IP Backup Aanalyzer 2.0 build 20130319 (mar 2013)
310 \subsection{Used tools on Host}
311 Tools that were used for analysis (-{}-version):
313 \item sqlite3 3.8.5 2014-06-04 14:06:34 b1ed4f2a34ba66c29b130f8d13e9092758019212
314 \item sha512sum (GNU coreutils) 8.22
315 \item ls (GNU coreutils) 8.22
317 \item tar tar (GNU tar) 1.27.1
320 \subsection{Machines}
322 \item \textbf{Virtual machine}\\
323 Windows XP Version5.1 (Build2600.xpsp\_sp3\_qfe.130704-0421 : Service Pack3)
324 \item \textbf{Oracle VirtualBox} 4.3.10
325 \item \textbf{Host machine}\\
326 Linux rebx 3.14.0-gentoo-somenet.org \#1 SMP Sun Apr 6 01:00:17 CEST 2014 x86\_64 Intel(R) Core(TM)2 Duo CPU T9300 \@ 2.50GHz GenuineIntel GNU/Linux