Skip to content

Instantly share code, notes, and snippets.

@frenchbox
Last active October 10, 2015 11:08
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 2 You must be signed in to fork a gist
  • Save frenchbox/e18934ce9dd5838c4d48 to your computer and use it in GitHub Desktop.
Save frenchbox/e18934ce9dd5838c4d48 to your computer and use it in GitHub Desktop.
https://gist.github.com/frenchbox/e18934ce9dd5838c4d48
Put you commentaries forth:
CAPSTONE CLOUD
File Encrypting Software
EDS Lite
log.txt
@qjerome
Copy link

qjerome commented Oct 10, 2015

CAPSTONE CLOUD

SGS III:
Conversations
Conv 7: Tells us that the packages are usually sent via FedEx and that Dirty Sanchez is interested in being golden
- DirtySanchez 9/18/2013 9:22:48 PM (UTC) : Got it. Forgot my phone at home today. Is the package and coming via fed ex. ? Should be able to turn it around fast.
- Hank 9/19/2013 12:37:33 AM (UTC) : Yep. Sent today. Overnight. Should be at the drop tomorrow
- DirtySanchez 9/19/2013 12:39:08 AM (UTC) : Awesome. Now just hold tight and keep your mouth shut. We should be golden.

    Conv 9: The intern has started to work for them recently and that Hank is interested in getting money out of this business
        - Carlos Sanchez 9/12/2013 7:41:47 PM (UTC) : Awesome!  Will do. How's the new girlfriend?
        - Hank 9/19/2013 1:54:54 AM (UTC) : Make sure u let me know when it arrives. Then wire me my cut on Friday after the deal
        - Hank 9/19/2013 1:55:03 AM (UTC) : I need the cash!

@msoria
Copy link

msoria commented Oct 10, 2015

image

@msoria
Copy link

msoria commented Oct 10, 2015

image

@msoria
Copy link

msoria commented Oct 10, 2015

image

@msoria
Copy link

msoria commented Oct 10, 2015

sdcard mount: /dev/fuse /storage/sdcard0 fuse rw,nosuid,nodev,noexec,relatime,user_id=1023,group_id=1023,default_permissions,allow_other 0 0

@frenchbox
Copy link
Author

153407 T:[unallocated space]\ Brute-force - Slow, Hardware acceleration possible Encrypted Container (TrueCrypt, etc.) Local Disk Open Password 1970-01-01 00:00 776 KB
375027 T:[unallocated space]\ Brute-force - Slow, Hardware acceleration possible Encrypted Container (TrueCrypt, etc.) Local Disk Open Password 1970-01-01 00:00 1,080 KB
379090 T:[unallocated space]\ Brute-force - Slow, Hardware acceleration possible Encrypted Container (TrueCrypt, etc.) Local Disk Open Password 1970-01-01 00:00 1,212 KB
s3j2mM1KJ1ZmmDqlVX3QR2bM_ZE= U:[root]\data\com.google.android.apps.books\files\accounts\dirtycsez@gmail.com\volumes\KW0YAAAAYAAJ\res2\ Brute-force - Slow, Hardware acceleration possible Encrypted Container (TrueCrypt, etc.) Local Disk Open Password 2013-07-03 02:33 558 KB
20130913_195722.jpg U:[root]\media\DCIM\Camera\ Brute-force - Slow, Hardware acceleration possible Encrypted Container (TrueCrypt, etc.) JPEG image Open Password 2013-09-18 23:24 2,663 KB
qug8jcnn U:[root]\media.rr.fllt\ Brute-force - Slow, Hardware acceleration possible Encrypted Container (TrueCrypt, etc.) Local Disk Open Password 2013-09-18 21:43 2,056 KB
003905 W:[unallocated space]\ Brute-force - Slow, Hardware acceleration possible Encrypted Container (TrueCrypt, etc.) Local Disk Open Password 1970-01-01 00:00 102,400 KB

@msoria
Copy link

msoria commented Oct 10, 2015

com sovworks edslite-1 apk_embedded_1

@msoria
Copy link

msoria commented Oct 10, 2015

com sovworks edslite-1 apk_embedded_2
com sovworks edslite-1 apk_embedded_3
com sovworks edslite-1 apk_embedded_4
com sovworks edslite-1 apk_embedded_5
com sovworks edslite-1 apk_embedded_6
com sovworks edslite-1 apk_embedded_7
com sovworks edslite-1 apk_embedded_8
com sovworks edslite-1 apk_embedded_9
com sovworks edslite-1 apk_embedded_10
com sovworks edslite-1 apk_embedded_11

@msoria
Copy link

msoria commented Oct 10, 2015

EDS continue preferences.xml file:
Seems to be a config file that set a .jpg file as a container:

image

@msoria
Copy link

msoria commented Oct 10, 2015

EDS container list
/* boolean name="wipe_temp_files" value="true"
/* boolean name="container_open_ro_/storage/sdcard0/DCIM/Camera/20130913_195722.jpg" value="false"
/* storage/sdcard0/DCIM/Camera/20130913_195722.jpg
/* boolean name="container_open_ro_/storage/extSdCard/Download/TO DO LIST-2.xls" value="false"

@msoria
Copy link

msoria commented Oct 10, 2015

Question 25:
The calendar of Liz

Time Calendar Entry Event information Del?

1 Start Time:
11-10-13
00:00:00(UTC+0)

End Time:
12-10-13
23:59:59(UTC+0)

Subject: Leave for Aruba

Attendees:

Location:

Details:
United flight 882 from IAD at 9:32am

Category: Work

Reminder:

Priority: Unknown

Status: Unknown

Class: Normal

Repeat Day: None

Repeat Rule: None

Repeat Interval: 0

Repeat Until:

@msoria
Copy link

msoria commented Oct 10, 2015

Question 25:

There is a search on Orbitz app about Detroit and Dulles airoport

    <string>Reagan Airport</string>
    <string>Washington DC</string>
    <string>DC</string>
    <string>US</string>
    <string>Reagan Airport, Washington DC, DC, US</string>
    <false/>
    <integer>34050</integer>
    <string>DCA</string>
    <string>AIRPORT</string>
    <string>America/Detroit</string>
    <real>38.851001739501953</real>
    <real>-77.031997680664062</real>
    <dict>

Fort Lauderdale Hollywood International Airport
Fort Lauderdale
FL
Fort Lauderdale Hollywood International Airport, Fort Lauderdale, FL, US
33351
FLL
AIRPORT
America/Detroit
26.071500778198242
-80.145195007324219
0
2014-02-14T19:38:40.566
2014-02-23T19:38:40.566

@qjerome
Copy link

qjerome commented Oct 10, 2015

IPhone 4s:
Link(s) to Woodland:

@qjerome
Copy link

qjerome commented Oct 10, 2015

SGS III:

  • Sanchez is trying a spyware on his phone killermobilesoftware.com
  • trial account: dirtycsez@gmail.com
  • password: 555555
    • Potential SMS involving Sanchez in a wider drug traffic business:
  • 9/13/2013 2:57:58 AM(UTC+0) Received from: +15718822635 : Hello, This is the Bath Salts Online Head Shop, How may we help...?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment