MAC timestamps in A...
 
Notifications
Clear all

MAC timestamps in Android 4.4.2

5 Posts
4 Users
0 Reactions
929 Views
(@anirudhrata)
Active Member
Joined: 10 years ago
Posts: 17
Topic starter  

Hi all, the phone I am currently examining is a HTC Desire 816 running Android 4.4.2. The items in question are the call recordings done on the phone. There is a suspicion that the recorded files were planted.

I have done logical extraction and file system extraction in Cellebrite UFED Touch ultimate. There are a few recorded files in /shared location of that app. But UFED shows only one timestamp ( modified date) for those files. And for some files the timestamp is missing entirely. Is there any other way I could get created date or any other timestamp from the logical or FS dump? Thanks.


   
Quote
(@trewmte)
Noble Member
Joined: 19 years ago
Posts: 1877
 

Have a look and see if Riff Box can help

http//www.riffbox.org/?s=HTC+Desire+816


   
ReplyQuote
(@anirudhrata)
Active Member
Joined: 10 years ago
Posts: 17
Topic starter  

Right now I cannot get a Riff Box to try that out. Only UFED and Oxygen are available, but anyway thanks for the help.


   
ReplyQuote
nightworker
(@nightworker)
Estimable Member
Joined: 16 years ago
Posts: 134
 

go to ufed analyser and search that timestamp in binary mode after that look other bytes manually


   
ReplyQuote
OxygenForensics
(@oxygenforensics)
Estimable Member
Joined: 14 years ago
Posts: 143
 

Hi all, the phone I am currently examining is a HTC Desire 816 running Android 4.4.2. The items in question are the call recordings done on the phone. There is a suspicion that the recorded files were planted.

I have done logical extraction and file system extraction in Cellebrite UFED Touch ultimate. There are a few recorded files in /shared location of that app. But UFED shows only one timestamp ( modified date) for those files. And for some files the timestamp is missing entirely. Is there any other way I could get created date or any other timestamp from the logical or FS dump? Thanks.

In Oxygen have you tried physical dump or Android backup extraction method? What app are you trying to analyze?


   
ReplyQuote
Share: