Examining an Android Virtual Disk Image
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
Already have an account? Sign In »
hi and welcome to everyday digital forensics. I'm your hostess and he said, And in today's mantra of mobile forensics, I'm gonna examine in Android virtual disk image.
So in today's videos, we have to android images dot gov and dot VD h. Cain
that we're gonna go ahead and compare the differences in the data that's displayed an autopsy and anti K for both of the images.
So here we have autopsy opens up on and both images are available. We have our dot VD i and R 0.0.0 v a.
Take a look at the hex values over dot beady eye.
You can see that this is an article V M virtual box this image
and just kind of slide through the kind of showing the different data information. So first would be the identifier of what the devices Maybe some boot loaders, depending on the image,
and then use girl down to data here. We see that way, see no data whatsoever.
Moving over to the dot gov a. We have our files and a fire, which with the name and then some values most likely time stamps
Breakdown of the device details such a networking and some of the configurations and settings that are in Ebel's
this size CPU
description. Some of the element values that you confined once you're loaded that are better defaulted to this image.
We can also see the name of the file or device itself. So this is a virtual box machine with version 1.6 Lennox and drinks for
and you're always type of Lennox to six underscore 60 Forces is a 64 bit medics
We get Last State changed is the last time that the state in itself changed. So we created an image at that point, and that was the point of accusation.
Some more interesting information that you can find is the Mac address. So the Mac address is pounds in your 0.0 v. Eight.
You also have not network details,
any network information. So this is networks that it connected Teoh or was connected to, at the time
particular time, Sam specially of guests.
If they were able to read and what kind of flags were set on them
now moving over to F. T. K,
it's gonna see what values that this gives us.
So we're gonna open up our data sources.
And first start with the dot V I
So just in itself the dot b I gave so much more information here than it did in autopsy. A first class.
You have your
offset zero, which identifies what it is.
And you can just kind of tell the difference here. Talks about the oracle
we're in after Kate. You're actually given information
on the device itself, but on the left, you can actually go through the fall system.
You go to the first partition or the UN partition space, which is this empty slack space
here. We have no way to trans verse, no way to actually look for any files. They're gonna exit out of autopsy
and see what details abdicate gives us.
Now we've broken down to root and unallocated space route will be your main user.
So moving into the no name we see are different blocks very similar in the NT. If Esther you had her on meth T your bit map
and those different values bad blocks, you can see some similarities in your NDFs and your injury.
In just this one section based on the additional houses of objects that has
you ever allocated space that kind of break sound into random
directories of numbers. Not gonna go into that detail.
You have your master boot record, which is a storage of your files
and links. As you can see, this is the same information that you saw at first glance when use when we selected the thought VD I
You can see partition. One starts at physical sector zero where
the master boot record and the original starts at Sector Jerrelle.
So this is sector Zero,
your original images at sector zero. That's why you may see similarities
and what's being displayed.
So I hope you enjoyed today's video and where we quickly examined to Android fouled images one of dot gov a another dot VD I in both autopsy and abdicate. We also compare the differences in the data that's displayed an autopsy, an uptick A
has seen an F decay, an autopsy for your dot beady eye. Your autopsy just kind of gave you
a small view of your not beady eye folder.
But when you went into F ck, you had the option of trans Mersing through the different sections. Your ableto first see your master boot record. See where the physical location, physical sector location that you're viewing. See your root folder go through your root folder directories as well. See the UN partition space
We don't go into too much details over the files or the information in there. This is just more of a view or feel for how the foul system looks. And there was a section there were. It was it showed bad sectors.
It showed back clusters and similar information that could be seen in an empty FS fall system. Such a Jew pot, Klosters, some of your attributes
and so on.
I hope you enjoyed today's video and future lectures. I look forward to examining some of the images that were acquired during the organization face. We're gonna perform some of the centre graphic techniques.
We're also gonna see how to properly check and execute a malicious file and explore some of the professional tools at both a beginner and advanced level.
I hope you enjoyed today's video, and I'll control next one