ã·ããªãª#
åœå±ã®WiFiãããã¯ãŒã¯ã䟵害ããæªæããæ»æè ã®æåšãç¹å®ããããšã«æåããŸããã
æè¿ãOP ERADICATEäœæŠã®äžç°ãšããŠããŽã§ããªã¢ã³ã®éŠéœå ã®ããäœæã§å€æãã®æ¥è¥²ãè¡ããã倧éã®èšŒæ åãæŒåãããŸãããç¹ã«ãææ»å¯Ÿè±¡ã®ãšãŒãžã§ã³ãææã®Androidããã€ã¹ã没åãããæ»æçŸå Žã«ååšããŠãããšèããããŠããŸãã
ãã®ããã€ã¹ã®è§£æãšã以äžã®è©³çŽ°ãªè³ªåãžã®åçã«ãããªãã®å°éç¥èãå¿ èŠãšããŠããŸããæéãéãããŠããããããŽã§ããªã¢ã³COBRäŒè°ãããªãã®æèŠãè°è«ããããã«éå¬ãããŸããâŠ
ãã¡ã€ã«#
opshieldwall2.zip
ãEVIDENCE-CASE-RAVENSKIAN-AGENT-002ããå«ã¿ãAndroidããã€ã¹ã®ãdataãããã³ãstorageããã©ã«ããå«ãŸããŠããŸãã
ãã®æ§æã«ããã/data ãã£ã¬ã¯ããªã«ã¯è±å¯ãªæ å ±ãå«ãŸããŠããã解æã®äœå°ã倧ãããªã£ãŠããŸããäŸãã°:
åæžã#
解æãéå§ããåã«ãAndroidã«é¢ããéèŠãªæ å ±ã以äžã«ç€ºããŸã:
Androidã®ãŠãŒã¶ãŒããŒã¿ã¯å éšããã³å€éšã®äž¡æ¹ã«ä¿åãããããšããããŸããå éšããŒã¿ã¯ãé»æºãåããŠãããŒã¿ãä¿æããäžæ®çºæ§ã¡ã¢ãªã§ããNANDãã©ãã·ã¥ã¡ã¢ãªã«ä¿åãããŸããNANDã«ã¯ããŒãããŒããŒããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããŠãŒã¶ãŒããŒã¿ãæ ŒçŽãããã¢ããªã±ãŒã·ã§ã³ããŒã¿ã¯NANDãã©ãã·ã¥ã¡ã¢ãªãŸãã¯SDã«ãŒãã«ä¿åãããŸãã
Androidã¯ãLinuxã«ãŒãã«ã®Long-Term SupportïŒLTSïŒãã©ã³ãã®æŽŸççã«åºã¥ããŠããŸããAndroid v8ïŒOreoïŒã§ã¯ãGoogleã¯Linuxã«ãŒãã«4.4以äžã®äœ¿çšãæ±ããŸãããäŸãã°ãAndroid v9ïŒPieïŒã¯ããã€ã¹ã«ãã£ãŠ4.4ã4.9ããŸãã¯4.14ã®ããããã®ããŒãžã§ã³äžã§åäœããŸãã詳现ã¯Android OS Wikiã§ã確èªãã ãã: https://source.android.com/docs/core/architecture/kernel/android-common?hl=en.
android-mainline
ã¯ãAndroidæ©èœã®äž»èŠãªéçºãã©ã³ãã§ããLinus TorvaldsãããŒãžã§ã³ãŸãã¯ãªãªãŒã¹åè£ãçºè¡šãããã³ã«ãã¡ã€ã³ã©ã€ã³ã®Linuxãã©ã³ãã android-mainline
ãšçµ±åãããŸã:
äžè¬çã«èŠããããã¡ã€ã«ã·ã¹ãã ã«ã¯ä»¥äžãå«ãŸããŸã:
- EXT4
- F2FS
- YAFFS2
- exFAT
ã»ãšãã©ã®ã¢ãŒãã£ãã¡ã¯ãã¯SQLiteããŒã¿ããŒã¹ãXMLãã¡ã€ã«ãšããŠä¿åãããŸããAndroidã¯ã«ãŒãã«ã¬ãã«ã§ã¢ããªã±ãŒã·ã§ã³ãéé¢ããåã¢ããªã«åºæã®èå¥åïŒUIDïŒãå²ãåœãŠãŠå®è¡äžã®ã¢ããªã远跡ããŸãã
Android ã¢ãŒããã¯ãã£#
- Linuxã«ãŒãã«ã¯Androidã®åºç€ãæããã¹ã¬ãããäœã¬ãã«ã®ã¡ã¢ãªç®¡çãªã©ãAndroid RuntimeïŒARTïŒã§å©çšãããåºæ¬æ©èœããµããŒãããŸãã
- ããŒããŠã§ã¢æœè±¡åã¬ã€ã€ãŒïŒHALïŒã¯ãããŒããŠã§ã¢æ©èœãäžäœã®Java APIã«å ¬éããæšæºåãããã€ã³ã¿ãŒãã§ãŒã¹ãæäŸããŸããããã¯ãã«ã¡ã©ãBluetoothãªã©åããŒããŠã§ã¢ã³ã³ããŒãã³ãã«åºæã®ã©ã€ãã©ãªã¢ãžã¥ãŒã«ã§æ§æãããAPIãããŒããŠã§ã¢ã«ã¢ã¯ã»ã¹ããéã«å¯Ÿå¿ããã¢ãžã¥ãŒã«ãèªã¿èŸŒã¿ãŸãã
- Android RuntimeïŒARTïŒã¯ãåã¢ããªã±ãŒã·ã§ã³ãç¬èªã®ããã»ã¹ãšã€ã³ã¹ã¿ã³ã¹ã§å®è¡ããäœã¡ã¢ãªããã€ã¹äžã§è€æ°ã®ä»®æ³ãã·ã³ã管çããŸããARTã¯ãAndroidåãã«ç¹å¥ã«èšèšã»æé©åãããDEXãã€ãã³ãŒãã䜿çšããd8ãªã©ã®ã³ã³ãã€ã«ããŒã«ã§Javaã³ãŒããDEXãã€ãã³ãŒãã«å€æããŠå®è¡ããŸãã
- ARTãHALãªã©ãå€ãã®éèŠãªAndroidã·ã¹ãã ã³ã³ããŒãã³ãããµãŒãã¹ã¯ãCãC++ã§èšè¿°ããããã€ãã£ãã©ã€ãã©ãªãå¿ èŠãšãããã€ãã£ãã³ãŒãã§äœæãããŠããŸãã
- Androidã®æ©èœã¯Java APIãéããŠå©çšã§ããéç¥ããªãœãŒã¹ç®¡çãããŒã«ãªãŒãŒã·ã§ã³ãªã©ã®äž»èŠãªã·ã¹ãã ã³ã³ããŒãã³ãããµãŒãã¹ã®åå©çšãä¿é²ãããŸãã
- ã·ã¹ãã ã¢ããªã±ãŒã·ã§ã³ã¯ãAndroidã«æšæºæèŒãããŠããã³ã¢ã®ã¢ããªçŸ€ã§ãã
Android ä»®æ³ãã·ã³#
- ä»®æ³ãã·ã³ïŒVMïŒã¯ãã¢ããªã±ãŒã·ã§ã³ãšåºç€ãšãªãAndroidããã€ã¹ãšã®éã®æœè±¡åã¬ã€ã€ãŒãšããŠæ©èœããŸãã
- åã¢ããªã±ãŒã·ã§ã³ã¯ãVMå ã§ç¬èªã®ã€ã³ã¹ã¿ã³ã¹ãšããŠå®è¡ãããä»ã®ã¢ããªã±ãŒã·ã§ã³ããéé¢ãããŸãã
- Androidã¢ããªã¯Javaã§èšè¿°ãããJavaãã€ãã³ãŒãã«ã³ã³ãã€ã«ãããŸãã
- ãã®ãã€ãã³ãŒãã¯Dalvikãã€ãã³ãŒãïŒ.dexãã¡ã€ã«ïŒãŸãã¯ARTãã€ãã³ãŒãã«å€æãããŸãã
- DalvikãšARTã¯ä»®æ³ãã·ã³å ã§ãã€ãã³ãŒãïŒ.dexïŒãå®è¡ããã¢ããªãåºç€ããŒããŠã§ã¢ã«äŸåããã«åäœã§ããããã«ããŸãã
- KitKatïŒv4.4ïŒä»¥åã¯Androidã¯Dalvik VMã䜿çšããŠããŸããã
- LollipopïŒv5.0ïŒä»¥éãAndroidã¯Android RuntimeïŒARTïŒã䜿çšããDalvik VMã¯æ®µéçã«å»æ¢ãããŸããã
- DalvikãšARTã¯ã©ã¡ããDEXãã€ãã³ãŒãã䜿çšããŸãããARTã¯æ°ããªæé©åæ©èœãåããŠããŸãã
ãã£ã¬ã¯ããªæ§é #
- /cache: Gmailã®æ·»ä»ãã¡ã€ã«ãããŠã³ããŒããé²èŠ§ããŒã¿ãOTAã¢ããããŒããªã©ãå«ãŸããå¯èœæ§ããããŸãã
- /efs: é害çºçæã«ããã€ã¹ã®åäœã«å¿ èŠãªãã¡ã€ã«ãæ ŒçŽãããŸãã
- /data:
- /data/data: ã¢ããªã±ãŒã·ã§ã³ãã©ã«ãïŒäŸ:
/data/data/com.example.app
ïŒãã¢ããªèšå®ãã¡ã€ã«ãSQLiteããŒã¿ããŒã¹ããã°ããã£ãã·ã¥ãªã©ãå«ãŸããŸãã - /app: AndroidããŒã±ããããã®.apkãã¡ã€ã«ãæ ŒçŽãããŸãã*ãã«ãŠã§ã¢ãååšããå¯èœæ§ããããŸãã
- /backup: éçºè åãããã¯ã¢ããAPIãä¿åãããŸãããŠãŒã¶ãŒããã¯ã¢ããããŒã¿ã¯ããã«ä¿åãããŸããã
- /media: SDã«ãŒãã«çžåœããå éšã¹ãã¬ãŒãžã*ãã«ãŠã§ã¢ãååšããå¯èœæ§ããããŸãã
- /misc: BluetoothãDHCPãVPNãWi-Fiãªã©ã«é¢é£ãããã¡ã€ã«ãæ ŒçŽãããŸãã
- /system:
gesture.key
ãpasswords.key
ããã¡ã€ã«èªèšŒçšã®ãŠãŒã¶ãŒåããã¹ã¯ãŒããä¿åããaccounts.db
ãªã©ãéèŠãªãã¡ã€ã«ãå«ãŸããŸãã - /property: ã¿ã€ã ãŸãŒã³ãèšèªèšå®ãªã©ãã·ã¹ãã ããããã£ãä¿åãããŸãã
- /data/data: ã¢ããªã±ãŒã·ã§ã³ãã©ã«ãïŒäŸ:
- /mnt:
- /asec: æå·åãããŠããªãã¢ããªããŒã¿ãä¿åãããŸãã
- /DCIM: ã¢ã«ãã ã®ãµã ãã€ã«ãä¿åãããŸãã
- /Pictures: ã«ã¡ã©ç»åãä¿åãããŸãã
- /downloads: ããŒã«ã«ã«ããŠã³ããŒãããããã¡ã€ã«ãä¿åãããŸãã
- /secure/asec: æå·åãããã¢ããªããŒã¿ãä¿åãããŸãã
- /system:
- /app: .apkãã¡ã€ã«ãå«ãŸããŸãã*ãã«ãŠã§ã¢ãååšããå¯èœæ§ããããŸãã
- /priv-app: ã·ã¹ãã ã¬ãã«ã®æš©éãæã€.apkãã¡ã€ã«ãå«ãŸããŸãã*ãã«ãŠã§ã¢ãååšããå¯èœæ§ããããŸãã
詳现æ å ±:
- ã¢ããªã®æš©éã«ã€ããŠ: https://developer.android.com/guide/topics/permissions/overview?hl=en, https://blog.mindorks.com/what-are-the-different-protection-levels-in-android-permission/
- Android CLI: https://developer.android.com/tools/adb?hl=en
ã»ããã¢ãã#
ãããã®ãã¡ã€ã«ãšã·ããªãªãèæ ®ããAutopsyããŒã«ã䜿çšããŸããã»ããã¢ããã«ã¯æéããããå¯èœæ§ããããããããããéå§ããŸãã
Autopsyã«äžæ £ããªæ¹ã®ããã«ãç°¡åãªèª¬æã以äžã«ç€ºããŸã:
Autopsyã¯ãªãŒãã³ãœãŒã¹ã®ããžã¿ã«èª¿æ»ããŒã«ã§ããSleuth Kitããã®ä»ã®ãã©ã¬ã³ãžãã¯ããŒã«ã®ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ãŒã¹ãšããŠæ©èœããããŒããã©ã€ããã¹ããŒããã©ã³ã®è§£æã«äžè¬çã«äœ¿çšãããŸããäž»ãªæ©èœãšããŠãåé€ãã¡ã€ã«ã®åŸ©å ãã¡ã¿ããŒã¿è§£æãããŒã¯ãŒãæ€çŽ¢ãã¿ã€ã ã©ã€ã³ã®å¯èŠåããã¡ã€ã«ã·ã¹ãã 解æãªã©ããããŸãã
䜿çšããã«ã¯ããã±ãŒã¹ããäœæããå¿ èŠããããŸã:
ããã§ã¯ããã£ã¹ã¯ã€ã¡ãŒãžããVMãããŒã«ã«ãã£ã¹ã¯ã§ã¯ãªãããLogical FilesããéžæããŸã:
Autopsyããã³ãã®ã¢ãžã¥ãŒã«ãã€ã³ãžã§ã¹ãããã»ã¹ãå®äºããã®ãåŸ ã¡ãŸããããã«ã¯æéããããå ŽåããããŸãã
æºåå®äºã§ãã調æ»ãéå§ããŸããã:
質å#
質å 1#
ãšãŒãžã§ã³ããåçš®ã¢ããªã±ãŒã·ã§ã³ïŒãµãŒãã¹ã§äœ¿çšããŠããã¡ãŒã«ã¢ãã¬ã¹ã¯äœã§ããïŒ
ããã«çãããããAutopsyãALEAPPïŒAndroid Logs Events And Protobuf ParserïŒçµç±ã§å®è¡ããã¬ããŒãã䜿çšããŸãã
ïŒALEAPPã¯ããã©ã¬ã³ãžãã¯è§£æã®ããã«æ¢ç¥ã®Androidã¢ãŒãã£ãã¡ã¯ãããã¹ãŠè§£æããããšãç®çãšãããªãŒãã³ãœãŒã¹ãããžã§ã¯ãã§ããïŒ
è¿ éãã€å®¹æã«èŠã€ããããã«ã以äžãæ€çŽ¢ããŸã:
/data/data/com.android.vending/databases/library.db
ïŒã¢ããªããŠã³ããŒãã«äœ¿çšãããGoogleã¢ã«ãŠã³ãã確èªããããïŒ
/data/data/com.android.providers.contacts/databases/contacts2.db
ïŒé£çµ¡å åæã«äœ¿çšãããGoogleã¢ã«ãŠã³ãã確èªããããïŒ
ããã«ïŒãã®ãã£ã¬ã³ãžã«ã¯è©²åœããŸããïŒ:
/data/com.android.vending/shared_prefs/lastaccount.xml
ïŒAndroid 9以éã§Google PlayStoreã§æåŸã«äœ¿çšãããã¢ã«ãŠã³ãïŒ/data/com.google.android.gms/shared_prefs/BackupAccount.xml
ïŒããã¯ã¢ããã¢ã«ãŠã³ãã®ã¡ãŒã«ã¢ãã¬ã¹ïŒ/data/com.android.email/databases/EmailProvider.db
ïŒã¡ãŒã«ã¢ã«ãŠã³ãããµãŒãããŒãã£ã¢ããªã®ããŒã¿ãåã³ã¡ãŒã«éç¥ã«é¢é£ããã¡ãã»ãŒãžïŒ
æçµçã«ãHTMLã¬ããŒããçæãããŸã:
ã¡ãŒã«ã¢ãã¬ã¹ã¯æ§ã
ãªå Žæã§ç¢ºèªã§ããŸãã
äŸãã°ããChromeãã¢ããªã®ãAutofillãïŒä¿åãããæ
å ±ã§ãã©ãŒã ãèªåå
¥åããæ©èœïŒã«ãŠ:
ãŸããChromeã®ãLogin Dataãã§ã:
ããã«ããInstalled Apps (Library)ãã»ã¯ã·ã§ã³ã«ã¯ãã¢ããªããŠã³ããŒãã«äœ¿çšãããGoogleã¢ã«ãŠã³ãã®ã¡ãŒã«ã¢ãã¬ã¹ãèšèŒãããŠããŸã:
åç:
olegpachinksy@gmail.com
質å 2#
é®æããããšãŒãžã§ã³ãã«å²ãåœãŠããããã³ãã©ãŒã®é£çµ¡å çªå·ã¯äœã§ããïŒ
ãContactsãã»ã¯ã·ã§ã³ã«ãŠ:
åç:
+323145232315
質å 3#
RavenskiãšãŒãžã§ã³ãçšã®èªèšŒæ
å ±ãšå
¬åŒããŒã¿ã«ãžã®ãªã³ã¯ãååŸããŠãã ããã
ããã«ãããRavenskiæ¿åºãèšç»ããä»åŸã®äœæŠã«é¢ããå®è¡å¯èœãªæ
å ±ãåéããããã®ã€ã³ããªãžã§ã³ã¹äžã®åªäœæ§ãåŸãããå¯èœæ§ããããŸãã
ãã®è³ªåã®åçã¯ããã§ã«è³ªå1ã§Chromeã®ãLogin Dataãã«ãã確èªãããŠããŸã:
åç:
agent.ravensk.idu.com:olegpachinksy007:HBLKNKD0MADsdfsa2334(*&DSMDB
質å 4#
å®å šãªãã£ãããã£ãã«ã䜿çšããéããšãŒãžã§ã³ããšãã³ãã©ãŒã®èº«å 確èªã«äœ¿çšãããé£çµ¡ã³ãŒãã¯äœã§ããïŒ
ãŸãã以äžã§SMSã¡ãã»ãŒãžã®å¯èœæ§ã確èªããŸã:/data/data/com.android.providers.telephony/databases/mmssms.db
äœãèŠã€ãããŸããã§ããã
ãŸãã以äžã確èªå¯èœã§ããããã®ãã£ã¬ã³ãžã«ã¯è©²åœããŸãã:
/data/com.google.android.gms/databases/icing_mmssms.db
(SMS/MMS)/data/com.google.android.gms/databases/ipa_mmssms.db
(SMS/MMS)
䜿çšãããŠããã¡ãã»ãŒãžã³ã°ã¢ããªãç¹å®ãããããAutopsyã®ãInstalled Programsãã»ã¯ã·ã§ã³ã§å šãŠã®ã€ã³ã¹ããŒã«æžã¿ã¢ããªã確èªããŸã:
ç°ãªãã«ããŽãªã衚瀺ãããŸã:
- Installed Apps (GMS)
- Installed Apps (Library)
- Installed Apps (Vending)
Installed Apps - GMS:
ãã®ã«ããŽãªã¯ãã€ã³ã¹ããŒã«æ¹æ³ã«é¢ä¿ãªãããã€ã¹ã«ã€ã³ã¹ããŒã«ãããã¢ããªãæããããŒã¿ã¯ /data/com.google.android.gms/databases/
ã«ä¿åãããŠããŸãã
Installed Apps - Library:
ãã®ã«ããŽãªã¯ãããã€ã¹äžã®GoogleãŠãŒã¶ãŒçšã®ã¢ããªã©ã€ãã©ãªãæããåäžGoogleã¢ã«ãŠã³ãã§å¥ã®ããã€ã¹ã以åã®ã€ã³ã¹ããŒã«ã§å
¥æãããã¢ããªãå«ãŸããå ŽåããããããŒã¿ã¯ /data/com.android.vending/databases/
ã«ä¿åãããŠããŸãã
Installed Apps - Vending:
ãã®ã«ããŽãªã¯ãGoogle Play Storeçµç±ã§ã€ã³ã¹ããŒã«ãããã¢ããªãæããã¢ããªãã¢ã³ã€ã³ã¹ããŒã«ãããŠãããŒã¿ã¯ä¿æããã/data/com.android.vending/databases/
ã«ä¿åãããŠããŸãã
æ確ã«ãããããALEAPPã«æ»ãããVendingãã¿ã€ãã®ã¢ããªã«çŠç¹ãåœãŠãŸã:
ç®ç«ã€ã¢ããªã¯ mega.privacy.android.app
ã§ããå®éãããã¯ã¡ãã»ãŒãžã³ã°ã¢ããªã±ãŒã·ã§ã³ã§ã:
ALEAPPã¯ãMEGAãä»ããŠäº€æãããã¡ãã»ãŒãžã解æããŠããŸã:
ãã®æ
å ±ã¯ã次ã®å Žæã§ç¢ºèªã§ããŸã:/data/data/mega.privacy.android.app/karere-TU1IaTh4TUJpdTQKAfO_2P0qU8NMP7zDRlgv.db
åç:
REDAPPLEONACAR
質å 5#
ãã³ãã©ãŒã¯ã¯ã©ãŠãã¹ãã¬ãŒãžãµãŒãã¹ã䜿çšããŠãšãŒãžã§ã³ããšããã¥ã¡ã³ããå
±æããŸããã
ãã®ãã¡ã€ã«ã¯ãã€ãšãŒãžã§ã³ããšå
±æãããã®ã§ããããïŒ
ã¡ãã»ãŒãžå
ã«ã¯äœãèŠã€ãããŸããã§ãããããã¥ã¡ã³ãã¯å¥ã®æ¹æ³ã§éä¿¡ãããã«éããããŸããã
ä»ã®ã¡ãã»ãŒãžã³ã°ã¢ããªããªããSMS/MMSã§éä¿¡ãããå¯èœæ§ããããŸããã
ã€ã³ã¹ããŒã«æžã¿ã¢ããªã®äžã« com.google.android.apps.docs
ãèŠãããããã以äžã確èªããŸã:\data\data\com.google.android.apps.docs
ãã®æ
å ±ãå«ãããŒã¿ããŒã¹/data/data/com.google.android.apps.docs/app_cello/olegpachinksy@gmail.com/cello.db
ãèŠã€ãããŸã:
ãŸãããã¡ã€ã«ã¯æ¬¡ã®å Žæã«ãååšããŸã:EVIDENCE-CASE-RAVENSKIAN-AGENT-002/storage/emulated/0/Download/Debrief-Velorian OP Expansion East.pdf
泚æ: Autopsyã¯ããã©ã«ãã§ã³ã³ãã¥ãŒã¿ã®ã¿ã€ã ãŸãŒã³ã䜿çšããŠã¿ã€ã ã¹ã¿ã³ãã解éããŸããAutopsyã®èšå®ïŒTools > Options > View > Time ZoneïŒã§ãã®èšå®ã調æŽããããšãå¿ããªãã§ãã ããã
åç:
2024-04-01 09:36:41
質å 6#
å ã«ç¹å®ãããå ±æãã¡ã€ã«ã®ããŠã³ããŒãURIã¯äœã§ããïŒ
ãã¡ã€ã«ã¯ /storage/emulated/0/Download/
ã«ååšããŠãããããããŠã³ããŒããããããšãåãããŸãã
ãããã£ãŠã/data/data/com.android.providers.downloads/databases/downloads.db
ãæ€çŽ¢ããŸã:
åç:
https://www.googleapis.com/drive/v2internal/files/1iQKKlBU2vuJD1Xet6IYPt7IODVtDHxv1?alt=media&source=downloadUrl&auditContext=fileAction&reason=909&syncType=1&featureLabel=android-sync-classic&openDrive=false&errorRecovery=false&originatorApp=102
質å 7#
ãŽã§ããªã¢ã®å¯Ÿã¹ãã€æŽ»åã«åããè¿œå æ å ±åéã®ãããRavenskiæ¿åºäž»å°ã®ãã®ãµã€ããŒäœæŠã®äž»èŠãªç®çã¯äœã§ãããïŒ
ããã¥ã¡ã³ãã«æ»ããš:
åç:
ãŽã§ããªã¢ã®ã»ãã¥ã¢ãããã¯ãŒã¯ã«äŸµå
¥ããä»åŸã®ãµã€ããŒæ»æããã®ææ³ãåã³æšçåœã«é¢ããæ
å ±ãåéããã
質å 8#
ãã®äœæŠã®ç¯å²ãææ¡ããããããã³ãã©ãŒã®ç¹å®ã¯ãŽã§ããªã¢ã®æ³å·è¡æ©é¢ã«ãšã£ãŠã極ããŠéèŠã§ãã
ãã³ãã©ãŒã®ã¡ãŒã«ã¢ãã¬ã¹ã¯äœã§ããïŒ
ããã¯ãã§ã«MEGAã¢ããªã®ã¡ãã»ãŒãžã§ç¢ºèªãããŠããŸã:
åç:
ivoryalex783@gmail.com
質å 9#
ãšãŒãžã§ã³ããšãã³ãã©ãŒãåºäŒã£ãå Žæã®å称ã¯äœã§ããïŒ
ã¡ãã»ãŒãžã«æ»ããš:
ãã®è³ªåã¯æãæéãããããçŽ1æéãè²»ãããŸããã
æåã¯ã以äžã®éåžžã®å Žæãæ€çŽ¢ããŸãã:
/data/com.google.android.apps.maps/databases/gmm_storage.db
/data/com.google.android.apps.maps/databases/search_history.db
/data/com.google.android.apps.maps/databases/da_destination_history
/data/com.sec.android.daemonapp/db/weatherClock
/data/com.google.android.apps.maps/app_tts-cache/
/data/com.google.android.apps.maps/cache/image_manager_disk_cache/
äœãèŠã€ãããªãã£ããããåçã¯é»è©±å ã®ç»åã¡ã¿ããŒã¿ã«ãããããããªããšèããŸãããå®éã48æã®ç»åãããããã®ãã¡æ°æã«ã¯ããŒãåã£ãŠããŸãã:
ãããã決å®çãªãã®ã¯èŠã€ãããŸããã§ããã
次ã«ä»¥äžã®ç¹ãæ€èšããŸãã:
- é»è©±å ã«ä»ã®ããã²ãŒã·ã§ã³ïŒäœçœ®æ å ±ã¢ããªã¯ãããïŒ
- 確å®ã«Google Mapsã¢ããªãèŠãã¹ããïŒ
- ããããGoogle Mapsã®ã¿ã§ãã
- ããããæ€çŽ¢ã¯ãã©ãŠã¶ã§è¡ãããå¯èœæ§ããããŸãã
äžè¬çãªGoogle Mapsã®ã¢ãŒãã£ãã¡ã¯ãã確èªåŸããã©ãŠã¶ã§æ€çŽ¢ããŸãããäœãèŠã€ãããŸããã§ããã
ãã®ãããå床Google Mapsã®ã¢ãŒãã£ãã¡ã¯ãã®è§£æã«æ»ããŸãã:
- app: é¢é£ãããã®ã¯ãããŸããã§ãã
- app_offline_downloads: é¢é£ãããã®ã¯ãããŸããã§ãã
- app_offline_hashes: é¢é£ãããã®ã¯ãããŸããã§ãã
- app_textures: é¢é£ãããã®ã¯ãããŸããã§ãã
- app_webview: é¢é£ãããã®ã¯ãããŸããã§ãã
- cache: é¢é£ãããã®ã¯ãããŸããã§ãã
- databases: ãã¡ã€ã«ãå€ããããããåŸã§åæ€èšããŸã
- files: ãnew_recent_history_cache_search.csã
çµå±ããPubããšããããŒã¯ãŒãã§åçŽã«æ€çŽ¢ããã°ããã£ãããšãå€æããŸãã ð€¡
åç:
Levstik Pub
質å 10#
ãšãŒãžã§ã³ããšãã³ãã©ãŒéã®ãã£ããã«ãããšããã³ãã©ãŒã¯Ravenskiæ¿åºããã®ãµã€ããŒè«å ±äœæŠã§äœ¿çšããŠããã€ã³ãã©ã«é¢é£ããç»åããšãŒãžã§ã³ãã«éä¿¡ããããã§ãã
Ravenskiæ¿åºã䜿çšããŠããC2ãã¬ãŒã ã¯ãŒã¯ã¯äœã§ããïŒ
質å9ã®ããã«å šãŠã®ç»åã確èªæžã¿ã§ãããããåçã¯æããã§ã:
åç:
Empire
質å 11#
IPã¢ãã¬ã¹ããã¹ãåãªã©ãã€ã³ãã©ã«é¢ããæ
å ±ã®åéã¯ããŽã§ããªã¢åœå±ãåæãæºåããäžã§æ¥µããŠéèŠã§ãã
ãã³ãã©ãŒããšãŒãžã§ã³ãã«éä¿¡ããç»åã«åºã¥ããŠãRavenskiã®è
åšã¢ã¯ã¿ãŒãéå¶ããC2ãµãŒããŒã®1ã€ã®IPã¢ãã¬ã¹ã¯äœã§ããïŒ
åç:
98.24.12.45