Dearest Digital Forensic peeps….
I've got a gigatribe job at the moment, while I'm happy with all the chat history and shared folder stuff…
There is a folder called Ressources in side of \users\username\appdata\local\shalsoft\gigatribe\123456\ressources….
This folder contains some imaging that I'm interested in all image file names with the format
stil_12344567890_1234567_12.png
or anim_….gif for animated gifs
Anyone any idea what thease images are used for (slightly larger than your average avatar /display type image too….)
Thanks in advance
neontube
Hi,
I think the Ressorces folder is where thumbnails of images shown during the chat is stored.
I have not finished testing this yet, but if you look to page 53, nr 7 in the pdf in the link below, you might get a bit wiser.
I´ll try to get back to you when I finish my testing!
TomE
If you LE, Eric Zimmerman has some pretty good tools for decoding all the Gigatribe stuff, he's usually around on this forum.
Btw,
the number in your filepath seems to be the GigaTribe ID of the user in question. If you use IEF on the .dat files, you will see that every chatlog .dat file has the same number and then an underscore, and then another number. So every chatlog .dat file is the chat between two users, identified by their Gigatribe ID. When you "decode" the .dat files(I used IEF), the nickname will also appear.
The same nickname appears also under the folder "GigaTribe Downloads" - /Users/[username]/Documents/GigaTribe Downloads/[nickname]
TomE
If you LE, Eric Zimmerman has some pretty good tools for decoding all the Gigatribe stuff, he's usually around on this forum.
Thanks!!
did you get this resolved? if not, lemme know!
while other tools do a decent job parsing things, my tools fully decode all available info and do some unique things as well, especially with the ressources file. full manuals are included as well which explains everything.
The ressources folder does in fact contain thumbnails that are transferred during chats in Giga. My chat parser will show the messages and transferred files inline, so it makes it very easy to see who sent what and what was said about the images.
lemme know!