GSM Mobile Device Evidence File – Device Seizure
The data contained in the image was acquired using Paraben’s Device Seizure version 2.1 build 3079.29886. While forensic mobile device acquisition tools continue to improve, the forensic workstation must be configured allowing successful playback of audio and video files as well as displaying foreign languages.
Scenario
The mobile device (manufacture/model depicted in image filename) image and acquisition type (i.e., logical, physical) contains data present on the internal memory of the mobile device and/or the Subscriber Identity Module (SIM). The logical internal memory acquisition contains two audio files (one .wav and one .mp3) and two video files (i.e., .3gp) present in the mobile device’s internal memory. Your task is to load the mobile device acquisition image with Device Seizure, locate the personalized audio and video files, export them and successfully open the files via the forensic workstation. The second task is to properly display French and Chinese text messages and phonebook entries found in both the device’s internal memory and the SIM internal memory. The final task is to load the physical acquisition and locate the long note (3000 characters) located in PM Memory.
Answer
The mobile device logical internal memory image (i.e., nokia_6101_logical) contains two audio files of type .mp3 and .wav and two .3gp video files. Additionally, phonebook and text message entries residing on the mobile device internal memory and Subscriber Identity Module (SIM) are illustrated below.
Phonebook entries in French and Chinese.
Text messages in French and Chinese.
Creating this test image
The test image was created first by populating data onto the internal memory of a mobile device and associated media (i.e., subscriber identity module [SIM]) and acquiring the data with Paraben’s Device Seizure version 2.1.
The test images provide mobile forensics specialists using Paraben’s Device Seizure the ability to determine if the forensic application and workstation are setup to display foreign character sets and to ensure that the forensic workstation is properly configured to support .3gp files and audio files.