2 \newpage\section{Questions (12 points)}
3 \subsection{How and when did Mr. Smith and Mr. Mayer communicate? (2 point)}
4 \begin{center}\begin{tabularx}{\textwidth}{| l | l | l | X | }
5 \hline service & timestamp & (from) to & content\\
6 \hline skype & 27-11-2012 12:20:00 & to:allegro.mayer from:johannes.m.smith & Auth\_Request\\
7 \hline skype & 06-12-2012 13:20:33 & from:allegro.mayer to:johannes.m.smith & Auth\_Granted\\
8 \hline call & 2012-12-06 14:35:38 & Johannes Smith 06603169718 & (0:01:15 sec)\\
9 \hline skype & 06-12-2012 16:33:53 & to:allegro.mayer from:johannes.m.smith & "Hallo"\\
10 \hline sms & 2012-12-06 17:20:46 & to +436603169718 & Ich habe wichtige Informationen über unseren letzten deal für dich. Ruf dich später an, wenn ich ungestört bin.\\
11 \hline sms &2012-12-06 17:30:43 & to +436603169718 & Sicherer kanal wär besser ....\\
12 \hline viber call & 2012-12-06 17:31:57 & Johannes Smith & (71 sec)\\
13 \hline sms & 2012-12-06 17:36:26 & from +436605166042 & Hallo, ich empfehle dir den WhatsApp Messenger für Android, iPhone, Nokia, BlackBerry und Windows Phone auf http://whatsapp.com/dl/\\
14 \hline sms & 2012-12-06 17:42:50 & to +436605166042 & Viel zu unsicher, hab mir vor kurzem einen ganz tollen vortrag darüber angehört...\\
15 \hline sms & 2012-12-06 17:45:19 & to +436605166042 & Ich hab von einem kollegen wichtige informationen. Ruf dich an\\
16 \hline call & 2012-12-06 17:45:36 & Johannes Smith +436605166042 & (0:00:21 sec; diensthandy? DumpBank We Sell Your Shit)\\
18 \end{tabularx}\end{center}
21 \subsection{What information was exchanged between Mr. Smith and Mr. Mayer? (3 points)}
22 dropbox extracted from android. no time now. mutter kollabiert gerade.\\
24 \subsection{Can you find any evidence or hints that support the suspicion of insider trade? (3 points)}
25 No hard evidence was found.\\
26 The fact that both parties looked up stock trading sites could hint at that.\\
27 Also communication between Mayer and Smith does not give a definite proof that they really did anything.
30 \subsection{Was the person that the witness identified really Mr. Mayer? (2 points)}
31 As Mayer was in Paris on Friday, 7th of December 2012, late afternoon it seems unlikely that a witness saw them.\\
32 Unless of course Mayer and Smith met in Paris which could be hinted at by the FILE in the dropbox-directory and the witness too was in Paris at that time.
34 \subsection{Mr. Mayer seems to have more secrets than initially expected. What is his big secret? (2 points)}
35 By using MAYRS EMAIL address, we found out, that he is engaged with NAME.\\
36 Communication suggests that MAYR + Laura were on a romantic trip in Paris.
41 \newpage\section{iPhone}
42 \subsection{Source: iPhone.tar.gz (IPBA)}
43 iPhone backup image from Allegro Mayer's Phone. The extracted files were analysed with iP Backup Analyzer2.
45 \textbf{size}: 6775181 byte\\
46 \textbf{''file''-output}: gzip compressed data, last modified: Fri Dec 14 11:42:54 2012, from Unix\\
47 \textbf{sha512}\\\ttfamily{
48 ff746e574a0d668e1d82c3ff72501a75eabe642e1dee7f20d3d74b9fe72054f9\\
49 9b9a91ded1b3f98067a63065423c620c73c42c65e13c3b110424854b3e7f6678}
54 The contacts-db was extracted from \emph{\textbf{IPBA::Home Domain:Library/AddressBook/AddressBook.sqlitedb}}
56 \textbf{size}: 87040 byte\\
57 \textbf{''file''-output}: SQLite 3.x database\\
58 \textbf{sha512}\\\ttfamily{
59 450e49183cc8781577f0c57a91a8a40f604ac2d3621037467f80745850b5613b\\
60 8c0492724930e90552c671a5f81e20b7f88e5cfd175fe6718eab350b2f3dbc90}
64 \begin{center}\begin{tabular}{ | l | r | }
65 \hline Name & Phone \\
66 \hline <None> & +436603169718 \\
67 \hline Laura Markovic & 0680 3303660 \\
68 \hline Sabine Oberhuber & +436604413637 \\
69 \hline Johannes Smith & +43 660 5166042 \\
70 \hline Ernst Strasser & 0660 4394199 \\
72 \end{tabular}\end{center}
76 The call-log was extracted from \emph{\textbf{IPBA::Wireless Domain:Library/Callhistory/call\_history.db}}
78 \textbf{size}: 12288 byte\\
79 \textbf{''file''-output}: SQLite 3.x database\\
80 \textbf{sha512}\\\ttfamily{
81 4cf477e649e9fc868183667489222e3e48cba5e2925423bc8dcdb51783c9b9b6\\
82 47fc184518b06e8a2b44f7c1e0fc746058eaf0b23a462870b380ea6f7354b6e1}
86 \begin{center}\begin{tabular}{ | l | l | l | l | }
87 \hline date & to/from & Phonenumber & duration (sec)\\
88 \hline 2012-12-06 13:35:38 & to & 06603169718 & 75\\
89 \hline 2012-12-06 14:02:20 & to & 06803303660 & 0\\
90 \hline 2012-12-06 14:03:02 & from & +436605969364 & 23\\
91 \hline 2012-12-06 14:08:34 & to & 0660303010 & 0\\
92 \hline 2012-12-06 14:10:02 & to & 0660303030 & 1181\\
93 \hline 2012-12-06 15:17:05 & to & 0660303030 & 1023\\
94 \hline 2012-12-06 15:34:30 & to & 0660303030 & 864\\
95 \hline 2012-12-06 16:00:10 & from & +436605166042 & 17\\
96 \hline 2012-12-06 16:08:02 & to & 06604394199 & 9\\
97 \hline 2012-12-06 16:25:30 & from & +436605166042 & 0\\
98 \hline 2012-12-06 16:26:11 & from & +436605166042 & 0\\
99 \hline 2012-12-06 16:34:39 & to & 06604394199 & 6\\
100 \hline 2012-12-06 16:34:52 & to & 06604394199 & 12\\
101 \hline 2012-12-06 16:35:10 & to & 06604394199 & 23\\
102 \hline 2012-12-06 16:45:36 & to & +436605166042 & 21\\
104 \end{tabular}\end{center}
107 \subsection{SMS/iMessage}
108 The SMS-Database was extracted from \emph{\textbf{IPBA::Home Domain:Library/SMS/sms.db}}
110 \textbf{size}: 41984 byte\\
111 \textbf{''file''-output}: SQLite 3.x database\\
112 \textbf{sha512}\\\ttfamily{
113 6fa73f676ca04eed70f10b8286c884ebcc5c01073bbdd8128ba26f676c7a6212\\
114 793f944999a9331fb990ef8e5dd5420b9d758b8456cb7b6f9f577bb8098cfafa}
119 \begin{center}\begin{tabularx}{\textwidth}{| l | l | l | l | X | }
120 \hline date & from/to & number & service & text\\
121 \hline 2012-12-06 16:17:20 & from & Viber & SMS & Your Viber code is: 9386 Close this message and enter the code into Viber to activate your account.\\
122 \hline 2012-12-06 16:20:46 & to & +436603169718 & SMS & Ich habe wichtige Informationen über unseren letzten deal für dich. Ruf dich später an, wenn ich ungestört bin\\
123 \hline 2012-12-06 16:30:43 & to & +436603169718 & SMS & Sicherer kanal wär besser ....\\
124 \hline 2012-12-06 16:33:58 & to & +436604413637 & iMessage & Hi wie gehts? Treffen wir und mal auf einen drink?\\
125 \hline 2012-12-06 16:36:26 & from & +436605166042 & SMS & Hallo, ich empfehle dir den WhatsApp Messenger für Android, iPhone, Nokia, BlackBerry und Windows Phone auf http://whatsapp.com/dl/\\
126 \hline 2012-12-0616:42:50 & to & +436605166042 & SMS & Viel zu unsicher, hab mir vor kurzem einen ganz tollen vortrag darüber angehört...\\
127 \hline 2012-12-0616:45:19 & to & +436605166042 & SMS & Ich hab von einem kollegen wichtige informationen. Ruf dich an\\
129 \end{tabularx}\end{center}
132 \subsection{Calendar}
133 The Calendar-Database was extracted from \emph{\textbf{IPBA::Home Domain:Library/Calendar/Calendar.sqlitedb}}
135 \textbf{size}: 126976 byte\\
136 \textbf{''file''-output}: SQLite 3.x database\\
137 \textbf{sha512}\\\ttfamily{
138 bcb14cbb2df068bf6905f3383c0bade056a0f1188aa9606dbe639e4d11f32a5d\\
139 79dee3f3fdf4ac6eb7581c6a4c6c46f0620cf6e49f46567a40870e13926cc3af}
143 \begin{center}\begin{tabular}{| l | l | l | l | }
144 \hline event & start & end & location\\
145 \hline Paris geschäftsreise & 2012-12-07 14:00:00 & 2012-12-09 19:00:00 & Paris\\
146 \hline Meeting & 2012-12-10 10:00:00 & 2012-12-10 11:00:00 & Zbank\\
147 \hline Nordic walking & 2012-12-11 07:00:00 & 2012-12-11 07:30:00 & \\
148 \hline Statusmeeting & 2012-12-11 08:00:00 & 2012-12-11 12:00:00 & \\
150 \end{tabular}\end{center}
154 The plist \emph{\textbf{IPBA::HomeDomain:Library/Safari/History.plist}} opened with IPBA2 plist-viewer cointains the browser history.
156 \begin{center}\begin{tabularx}{\textwidth}{| l | X | X |}
157 \hline timestamp & title & url \\
158 \hline 2012-12-07 09:03:15 & Flughafen Wien - Abflüge - Offen für neue Horizonte & https://www.google.at/url?sa=t\&source=web\&cd=3\&ved=0CD0QjBAwAg\&url=http\%3A\%2F\%2Fwww.viennaairport.com\%2Fjart\%2Fprj3\%2Fva\%2Fmain.jart\%3Frel\%3Dde\%26content-id\%3D1249344074230\%26reserve-mode\%3Dactive\&ei=jLDBULjlB8bE4gTn-oGABw\&usg=AFQjCNHU5R5b3WsiOhYSIsli3inGLTEFGQ\\
159 \hline 2012-12-07 09:02:03 & flughafen wien - Google-Suche & https://www.google.at/search?q=flughafen+wien\&ie=UTF-8\&oe=UTF-8\&hl=de\&client=safari\\
160 \hline 2012-12-07 09:01:54 & Laura Markovic & https://m.facebook.com/laura.markovic.129?\_\_user=100004760941674\\
161 \hline 2012-12-06 16:14:19 & RNS News - London Stock Exchange & http://m.londonstockexchange.com/exchange/mobile/news/detail.html?announcementId=11421386\\
162 \hline 2012-12-06 16:14:14 & FTSE AIM 100 - London Stock Exchange & http://m.londonstockexchange.com/exchange/mobile/indices/summary.html?index=AIM1\\
163 \hline 2012-12-06 16:14:07 & Homepage - London Stock Exchange & https://www.google.at/url?sa=t\&source=web\&cd=1\&ved=0CEQQFjAA\&url=http\%3A\%2F\%2Fm.londonstockexchange.com\%2Fexchange\%2Fmobile\%2Fhomepage.html\&ei=ScTAUPK8FMfKtAaQq4GYBQ\&usg=AFQjCNE22q6svVgMrwz\_D7x-iD0srW0nTw\\
164 \hline 2012-12-06 16:14:00 & stock exchange london - Google-Suche & https://www.google.at/search?q=stock+exchange+london\&ie=UTF-8\&oe=UTF-8\&hl=de\&client=safari\\
165 \hline 2012-12-06 16:10:22 & Ohne Anstehen: Tickets Eiffelturm \& Rundgang Rive Droite, | Mobil - GetYourGuide.com & http://www.getyourguide.de/paris-l16/ohne-anstehen-tickets-eiffelturm-rundgang-rive-droite-t25185/\#calendar\\
166 \hline 2012-12-06 16:10:03 & Ohne Anstehen: Tickets Eiffelturm \& Rundgang Rive Droite, | Mobil - GetYourGuide.com & http://www.getyourguide.de/paris-l16/ohne-anstehen-tickets-eiffelturm-rundgang-rive-droite-t25185/\\
167 \hline 2012-12-06 16:09:56 & Paris: Touren, Ausflüge \& Aktivitäten | Mobil - GetYourGuide.com & https://www.google.at/aclk?sa=l\&ai=Cw0lOT8PAUNn8BIaX0wXeoYHwD43W1e0EldC\_uXSaooQJCAAQAiD4mYsSKAJQw5HQuPv\_\_\_\_\_AWCpsL6AzAGgAYutzM0DyAEBqQJiko-yhe21PqoEIk\_QmH99e-Hnj0NaSGjzY1ceX0oZt9LcfH\_ckQNETkSVs7yABZfgvAvYBgI\&sig=AOD64\_3cmbdhf4eRcAjv\_a9FMrltcGuHTA\&ved=0CC0Q0Qw\&adurl=http://21.xg4ken.com/media/redir.php\%3Fprof\%3D89\%26camp\%3D65425\%26affcode\%3Dkw720159\%26inhURL\%3D\%26cid\%3D31229666013\%26networkType\%3Dsearch\%26url\%5B\%5D\%3Dhttp\%253A\%252F\%252Fwww.getyourguide.de\%252Fparis\%252Fsightseeing-touren-ltc16-2\%252F\%253Fpartner\_id\%253DCD951\\
168 \hline 2012-12-06 16:09:50 & paris sightseeing - Google-Suche & https://www.google.at/search?q=paris+sightseeing\&ie=UTF-8\&oe=UTF-8\&hl=de\&client=safari\\
169 \hline 2012-12-06 16:08:58 & Laura Markovic & https://m.facebook.com/laura.markovic.129?\_\_user=100004760941674\#!/laura.markovic.129?\_\_user=100004760941674\&soft=jewel\%3D2\\
170 \hline 2012-12-06 16:08:49 & Facebook & https://m.facebook.com/home.php?refid=9\#!/laura.markovic.129?\_\_user=100004760941674\\
171 \hline 2012-12-06 13:56:39 & Facebook & http://m.facebook.com/?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&\_rdr\#!/home.php?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&soft=side-area\&\_\_user=100004760941674\\
172 \hline 2012-12-06 13:55:36 & Facebook & http://facebook.com/\\
173 \hline 2012-12-06 13:51:26 & Facebook & https://m.facebook.com/home.php?refid=9\#!/home.php?soft=side-area\&\_\_user=100004760941674\\
174 \hline 2012-12-06 13:50:58 & Facebook & https://m.facebook.com/home.php?refid=9\#!/home.php?soft=jewel\%3D0\&\_\_user=100004760941674\\
175 \hline 2012-12-06 13:46:54 & Facebook & https://m.facebook.com/login.php?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&landing\_serial=2\&refid=9\\
176 \hline 2012-12-06 13:46:08 & Willkommen bei Facebook & https://m.facebook.com/login.php?refsrc=http\%3A\%2F\%2Fwww.facebook.com\%2F\&landing\_serial=1\&refid=8\\
178 \end{tabularx}\end{center}
182 The plist \emph{\textbf{IPBA::SystemPreferencesDomain:SystemConfiguration/com.apple.wifi.plist}} opened with IPBA2 plist-viewer cointains a list of Wireless Networks the phone has joined.\\
184 \begin{center}\begin{tabular}{| l | l | l |}
185 \hline ssid & last join & last autojoin \\
186 \hline tunet & 2012-12-06 90:41:55 & \\
187 \hline VirtualRouter & 2012-12-06 09:38:00 & 2012-12-06 09:45:45 \\
188 \hline pornhub & 2012-12-06 11:51:01 & 2012-12-06 16:05:07 \\
190 \end{tabular}\end{center}
194 Images were extracted from \emph{\textbf{IPBA::CameraRollDomain:Media/DCIM/100APPLE}}\\
196 IMG\_0002.PNG: Screenshot of Facebook-App showING a photograph of a woman. Laura Markovic (\url{https://www.facebook.com/laura.markovic.129}) seems to be tagged in that photograph.
198 \textbf{size}: 844814 byte\\
199 \textbf{''file''-output}: PNG image data640 960 8-bit/color RGB, non-interlaced\\
200 \textbf{sha512}\\\ttfamily{
201 986ae5d4272e003d2b8de8a9851d02721c908a43b3eb824331447c309ac92bc3\\
202 426d99ec2a749462372778feacaedcbd23823cc34dd53d07ab5e7524e4276a0f}
205 IMG\_0003.PNG: Screenshot from Maps-App showing directions within Paris.
207 \textbf{size}: 939169 byte\\
208 \textbf{''file''-output}: PNG image data640 960 8-bit/color RGB, non-interlaced\\
209 \textbf{sha512}\\\ttfamily{
210 4238d1a52b41c7f0991dcce42ca347863244af381f34ff59efa33ab9cc85b241\\
211 849d7087cf42ce426936fc83b3a72ae991a3fc220d4716d874590222237edacf}
214 IMG\_0005.JPG: Showing some statistics about company shares.
216 \textbf{size}: 62763 byte\\
217 \textbf{''file''-output}: JPEG image data, EXIF standard\\
218 \textbf{sha512}\\\ttfamily{
219 6201ddb71d24c5b662284ef091f758db5d4144643909eb29dc2522a91fc75bf0\\
220 e54995f6115f66c96cbd51ec7c052294e8a587eedc156aaa085214fee0619293}
224 \subsection{Viber-App}
225 The Viber-Database was extracted from \emph{\textbf{IPBA::AppDomain:com.viber/Documents/Contacts.data}}
227 \textbf{size}: 41984 byte\\
228 \textbf{''file''-output}: SQLite 3.x database\\
229 \textbf{sha512}\\\ttfamily{
230 89eae3d5fa62a3ea1b499a539f71ee8fc7c8adb147c12d5bb90868384b93206c\\
231 21f2ce84f493d6c6601851844d14cf4dbdd1523ebe98bdc9deb5db380533df77}
235 \begin{center}\begin{tabular}{| l | l | l | l | l |}
236 \hline timestamp & to/from & number & name & duration (sec)\\
237 \hline 2012-12-06 16:27:32 & to & 436803303660 & Laura Markovic & 0\\
238 \hline 2012-12-06 16:31:57 & to & 436605166042 & Johannes Smith & 72\\
240 \end{tabular}\end{center}
243 \subsection{Skype-App}
244 The Skype-Database was extracted from \emph{\textbf{IPBA::AppDomain:com.skype.skype/Library/Application Support/Skype/allegro.mayer/main.db}}
246 \textbf{size}: 128000 byte\\
247 \textbf{''file''-output}: SQLite 3.x database\\
248 \textbf{sha512}\\\ttfamily{
249 29da4b939b6f3f2def0296ca2087355e57321ecb0a5d0e10264c16c69359a748\\
250 593fd29b8eef03407be07d386e6a980f2b6d25d29a5d3740bd566531a03c79a1}
254 \begin{center}\begin{tabularx}{\textwidth}{| l | l | l | l | X |}
255 \hline timestamp & to/from & Skype id & name & content\\
256 \hline 2012-11-27 12:20:00 & from & johannes.m.smith & Johannes Smith & Hallo! Ich wüurde Sie gerne in meine Skype-Kontaktliste aufnehmen. Johannes Smith\\
257 \hline 2012-12-06 13:20:33 & to & johannes.m.smith & Johannes Smith & \\
258 \hline 2012-12-06 13:20:57 & to & christoffel.johannes.smith & Chris Smith & Fügen Sie mich als Kontakt hinzu, damit wir anrufen und chatten können\\
259 \hline 2012-12-06 13:21:33 & to & addy-juli & Julia & Fügen Sie mich als Kontakthinzu, damit wir anrufen und chatten können.\\
260 \hline 2012-12-06 16:33:51 & from & johannes.m.smith & Johannes Smith & Hallo\\
262 \end{tabularx}\end{center}
265 \subsection{Dropbox-App}
266 The plist \emph{\textbf{IPBA::AppDomain:com.getdropbox.Dropbox/Library/Preferences/com.getdropbox.Dropbox.plist}} opened with IPBA2 plist-viewer cointains a field \emph{\textbf{Dropbox Username}} and the email-address \emph{\textbf{allegro.mayer\@gmail.com}}\\
268 Also the field \emph{\textbf{Dropbox Camera Upload Has Ever Uploaded}} is \emph{\textbf{true}}\\
271 \subsection{Facebook-App}
272 The plist \emph{\textbf{IPBA::AppDomain:com.facebook.Facebook/com.facebook.Facebook.plist}} opened with IPBA2 plist-viewer cointains a field \emph{\textbf{FBLastLoginEmail}} and the email-address \emph{\textbf{allegro.mayer\@gmail.com}}\\
274 Searching of FB reveales the link to the profile: \url{https://www.facebook.com/allegro.mayer}.\\
275 That About-Page states his relationship status is married to Mrs. Ilse Mayer-Brandl (profile: \url{https://www.facebook.com/ilse.mayerbrandl}).\\
277 Relevant FB-postings by Allegro Mayer:\\
278 On December 7. 2012 11:54 at Flughafen Wien, Vienna Airport, Austria.
279 \begin{quote}On my way to Paris\end{quote}
281 On December 7. 2012 14:17 at Paris, with Laura Markovic (\url{https://www.facebook.com/laura.markovic.129}).
282 \begin{quote}enjoying a romantic weekend with my dearest love in Paris!\end{quote}
289 \newpage\section{Android}
290 \subsection{Source: Android.tar.gz (ANDROID)}
291 Android image from Johannes Maskus Smith's phone.
293 \textbf{size}: 270397822 byte\\
294 \textbf{''file''-output}: gzip compressed data, last modified: Fri Dec 14 12:06:37 2012, from Unix\\
295 \textbf{sha512}\\\ttfamily{
296 9614e30affc09d1cbfad5a96e43b2e40dae3c5c123db22dcbd53e980d14418d9\\
297 ab18c6a2b5b9f8a0e1539474612a4a7ceae627255a2169565f0dddf3409ef67d}
300 \subsection{Contacts}
301 \subsection{Call-Log}
304 \subsection{eMail-App}
305 \subsection{Viber-App}
306 \subsection{Skype-App}
307 \subsection{Whatsapp-App}
308 \subsection{Dropbox-App}
309 \subsection{Facebook-App}
312 \newpage\section{Details}
313 \subsection{Used tools on GuestVM}
314 Tools that were used for analysis (-{}-version):
316 \item IP Backup Aanalyzer 2.0 build 20130319 (mar 2013)
319 \subsection{Used tools on Host}
320 Tools that were used for analysis (-{}-version):
322 \item sqlite3 3.8.5 2014-06-04 14:06:34 b1ed4f2a34ba66c29b130f8d13e9092758019212
323 \item sha512sum (GNU coreutils) 8.22
324 \item ls (GNU coreutils) 8.22
326 \item tar tar (GNU tar) 1.27.1
329 \subsection{Machines}
331 \item \textbf{Virtual machine}\\
332 Windows XP Version5.1 (Build2600.xpsp\_sp3\_qfe.130704-0421 : Service Pack3)
333 \item \textbf{Oracle VirtualBox} 4.3.10
334 \item \textbf{Host machine}\\
335 Linux rebx 3.14.0-gentoo-somenet.org \#1 SMP Sun Apr 6 01:00:17 CEST 2014 x86\_64 Intel(R) Core(TM)2 Duo CPU T9300 \@ 2.50GHz GenuineIntel GNU/Linux