iPhone_Forensics

Overview

This project involved using the Autopsy tool (https://www.autopsy.com/) to perform forensics on an image captured from an Apple iPhone. The actual case report is provided as a Word file in the GitHub repo as Case Report National Gallery DC. The significant details are included here in this README file. We performed the role of investigator as ‘Digitech, Inc’. The case involved a conspiracy to steal valuable collectable stamps from the National Gallery in Washington, DC. We were given a forensic image of an iPhone device, and gathered evidence to support the criminal investigation.

Executive Summary

On January 21, 2016, Digitech Inc. was called in to assist the National Gallery, Washington D.C. (NGDC) case involving the conspiracy associated with the theft of valuable stamps and defacing of museums are at the NGDC.

As described fully in the report, Digitech, Inc. made the following findings.

Based on the evidence shown below, it appears that Tracy and her brother Pat conspired with an unknown 3rd party with email address “King kthings throne1966@hotmail.com” to steal stamps from the National Gallery.

Equipment and Tools

Digitech used the Autopsy open-source forensics tool on a Kali Linux host to analyze an image of Tracy’s iphone. Other websites and tools were also used (e.g. maps.google.com, etc.).

iphone_details.png

Evidence to Establish Personas

This section establishes aliases, phone numbers, emails addresses associated with each person, and relationships between each individual.

Person Description Data
Tracy    
  Phone Number (703) 340-9961
  Personal Email tracysumtwelve@gmail.com
  Work Email tracy.sumtwelve@nationalgallerydc.org
  Relationship Accused
Pat    
  Phone Number (571) 308-3236
  Email perrypatsum@yahoo.com
    patsumtwelve@gmail.com
  Relationship Tracy’s brother
Terry    
  Phone Number (703) 829-6071
  Email unknown
  Relationship Tracy & Joe’s daughter
Joe    
  Phone Number unknown
  Email unknown
  Relationship Tracy’s ex-husband
Carry    
  Phone Number (202) 725-2124
  Email unknown
  Relationship Tracy’s accomplice and friend

Evidence relating to theft of valuable stamps

This sub-section provides details regarding the evidence found as it relates to the theft of valuable stamps.

Emails and SMS messages were exchanged between Tracy, Pat, Carry, and an unnamed co-conspirator with email address “King kthings throne1966@hotmail.com” (referenced in Appendix A).

One email from “King kthings” contained an attachment with a list of items needed for the theft.

Figure 1. Email attachment ‘needs.jpg’ from “King kthings”

needs.png

There was also an MP3 audio file attachment (Crazydave1.mp3) with covert instructions on how to install a VirtualBox VM on a host computer, which was to be used for this crime.

There was an SMS message notifying Tracy that she had received a $1000 Target Giftcard, with instructions to visit a misleadingly named website (www.target.com.trdt.biz) with instructions to entre a numeric code followed by “where to ship it”. The website ‘trdt.biz’ domain is no longer registered by anyone, and it uses ‘www.target.com’ as a subdomain to hide the fact that it’s really a part of ‘trdt.biz’, and is not affiliated with the Target corporation.

There were 3 .pdf email attachments which were Memoranda of Insurance for various valuable stamps and photos of those stamps in the camera storage location (shown below).

In addition, there were photo images of each of the stamps listed in the insurance documents on the phone.

Figure 2 - Stamp_insurance1.pdf email attachment

stamp_insurance1.png

Figure 3 - The three stamps mentioned in Figure 2 above

stamps2.png

Figure 4 - Stamp_insurance2.pdf email attachment

stamp_insurance1.png

Figure 5 - The three stamps mentioned in Figure 4 above

stamps2.png

Figure 6 - Stamp_insurance3.pdf email attachment

stamp_insurance1.png

Figure 7 - The three stamps mentioned in Figure 6 above

stamps2.png

Evidence relating to the defacement of museum art

This sub-section provides details regarding the evidence found as it relates to the defacement of museum art.

There was no evidence related to defacement of museum art in the iphone image. Only evidence related to the theft of stamps.

Plot Timeline

For details please refer to Appendix A below and the section labelled ‘Evidence relating to theft of valuable stamps” above.

Figure 8 - Persons under investigation

perps.png

Conclusion

Evidence found on Tracy’s iPhone indicated the following:

Appendix A Correspondence Evidence

This subsection will provide an amalgamation of the email and SMS corresponce evidence which was obtained from the forensic image file of the iPhone.

correspondence1.png

correspondence2.png

correspondence3.png

correspondence4.png

correspondence5.png

correspondence6.png

Appendix B WiFi and GPS Location information

WiFi locations gathered from /vol5/root/Library/Caches/locationd/consolidated.db and plotted using maps.google.com

Figure B1 - National Gallery with green marker vs. iPhone GPS Lat / Lon tracking coordinates data

natl_gallery.png