Quantcast
Channel: Forensic Focus Forums - Recent Topics
Viewing all articles
Browse latest Browse all 20102

Mobile Phone Forensics: iphone analysis, spyware, etc.

$
0
0
@Adam10541 - Oh boy, I'm afraid I am a can of worms on this one. This is going to be quite a read. 2 years ago I discovered my husband was having an affair with a coworker (for 6 months). First, he denied it, then only admitted to what was undeniable. I can forgive, but not blindly. I have to know what I'm forgiving - all of the good, the bad and the ugly - before I can grant it. So I spent months foraging through a single backup I had off the phone he carried during the affair (he conveniently upgraded his phone about a week after the affair was discovered then the old phone mysteriously disappeared). I got into the "affair phone" files with an iphone backup extractor. I sifted through pages of gibberish and recovered bits and pieces of deleted texts. It was helpful, but I know my lack of know-how left rocks un-turned. I utilized google maps to examine places he'd been that were out of the ordinary, I learned about places they had been/things they discussed using his search entries on safari, and using the auto-dictionary his phone kept of phrases, etc, that he was texting during that time. I cross-referenced thousands of texts/calls with her and the times they happened to the texts/calls he placed to me with the google map info, etc., to drum up as complete a picture as I could. You get the idea. I may not be tech-savvy, but I'm persistent and willing to learn. =) After confronting him with the timeline I had managed through my little forensics party, he did reveal more details about the affair (like admitting it lasted 6 months instead of the 2 he originally claimed), but again, he shared very little beyond what I already knew. The kicker for me with the entire thing is that he admits there was physical contact, "I love you's" exchanged, etc etc (thousands upon thousands of texts, calls, skypes, meetings, lunches, coffees, even after-hours drinks, etc), but they never actually...well...trying to keep this G-rated here so I'll let you fill in that blank. Hard to believe, right? So...fast-forward to this past June when I realized HE had put SPYWARE on MY PHONE. (Ummmm....areyoukiddingme? LOL) I didn't say anything to him at first - I just launched another investigation so that I could be prepared for whatever explanation he had for it. When I finally confronted him that's when I got the whole "Yes, I did it but I never actually spied on you" story. Sounds sort of familiar, doesn't it? It walks like a duck and quacks like a duck but it isn't a duck, honey, I promise. This is why it matters a great deal to me to be able to prove otherwise. I've already had to live with one far-fetched account of deal-breaker behavior due to my limited abilities to prove otherwise (I'd love to be able to manage better forensics on the affair phone files!!), so this second hard-to-believe-story is beyond insulting. On the other hand, suspicion alone does not warrant divorce. My vows and my children mean he gets the benefit of the doubt when doubt exists. The truth makes the difference between one horrible mistake that's behind us or realizing I'm married to a self-centered liar who isn't going to change. See - a can of worms. Aren't you glad you asked? =) @trewmte & Adam10541 - My phone began the odd behavior thing - dropped all contacts, I woke up to it in a perpetual reboot stage one morning (lost contacts again), running hot, draining battery, lighting up for no reason at odd times and very sluggish texts. I thought I just had a janky old iphone that had seen better days. I was trying to troubleshoot some of those issues and under Settings->About->Diagnostics & Usage, I found a long list of dated entries (crash, lockdownd, low battery, low memory, etc). Under a random "Low Memory" report, lo and behold, it listed the largest process at the time to be "MSpy". Nothing more obvious than that! I have to laugh at their claim to be "undetectable". Really? It took me less than 5 minutes and I don't know a thing about what I'm doing! I called MSpy and even though they state they do not condone spyware being used without the knowledge of the phone owner, they didn't give a flip that it had happened to me. All they would tell me is that a) you pay online, b) you receive an email with the software download as well as log-in information for your account, c) a phone must be jailbroken to upload the spyware, d) you monitor activity by logging into your account online. I still wasn't 100% that "MSpy" in the logs meant it was on my phone, bc obviously there weren't any other signs of it. So I brushed up on jailbreaking and figured out how to reverse the code that hides the Cydia app from view. I was floored when it actually worked and I realized my phone really HAD been tampered with. I started using other tools (Lookout, Oxygen Forensics, etc) to try and figure out what he'd been up to on my phone and for how long. I was able to figure out the code name for MSpy in the files (iphoneInternalService) and I think I am pretty solid on when he did it, but that's as far as I got. When I confronted him, he said he used a prepaid Visa to buy the software (which already makes no sense bc he has a separate account from our joint account and I can't get into that, so why not use it?). He said when he went to submit payment, it would not process his card because it needed the name/address info attached to the card, and a prepaid card doesn't have that info. He called customer service. The rep took his payment over the phone, and verbally gave him link info by which to access the software (MSpy says the card would have processed just fine, and they they do not take payments by phone. Even if they had taken payment over the phone, he would have sent the software and log in instructions to whatever email address he provided...not verbally). He says he then jailbroke my phone and tried to upload the software, but it went into an endless "loading" stage and never gave him any confirmation that the transaction was successful. He cleared it out, tried again, same thing. He panicked, thinking it was taking too long, so he ended the process. He says he never went back to try again, so he never tried to access any spy-data, thinking there wouldn't be any if the upload was incomplete. He says he doesn't remember giving an email address, and does not remember getting an email from them. He checked two email accounts in front of me - his work and personal. He let me do searches. Nothing found. MSpy tried to find his account using those two email addresses and found nothing either. Yet he says he did make a purchase and I know it's on my phone. I think he has an alternate email address but it's yet another thing I can't prove. Finally, I asked him where he expected to view the data coming off of my phone if he didn't have any login info that he knew of. I mean, he was going to put it on my phone and then what? Receive it telepathically? He just says "I don't know". So this is where I sit - so many files, so much info - I know between my phone, his and our desktop there has to be a way to find what I'm looking for, but I've tried everything I know to try. I'm certain there are hidden files I haven't seen, or effective ways to read files that I don't know about. (For example, none of the MSpy files are anything I can read - and many file sizes indicate there is material to be viewed, but I open them and nothing is there. I can't figure out why that happens.) Well, this only took all morning. I'm sorry to be so long-winded - it's a very long story. I hope I have not freaked everyone completely out now. =)

Viewing all articles
Browse latest Browse all 20102

Trending Articles