Android10 ImageCreation
Android10 ImageCreation
Android 10 Image
DESCRIPTION
An image of Android 10 was created using a stock Android image from Google. Several popular
applications (apps) were populated with user data utilizing the capabilities of each individual app. The
stock Android apps were also populated with user data.
All times listed in this document are 24-hr, Eastern Standard Time (UTC -0500).
Some of the data available in the apps were sync’d with data that had been previously populated.
Information about the previously populated data can be found in the documentation of the respective
images, which can be found at https://thebinaryhick.blog.
PHONE INFORMATION
Make: Google Pixel 3
Model: G013A
Storage: 64 GB
RAM: 4GB
Carrier: Google Fi
Phone Number: 919-579-4674
Serial: 8CEX1N716
Wi-Fi MAC: 7c:d9:5c:ac:a2:cf
BT MAC: 7c:d9:5c:ac:a2:ce
Android 10 Image Image Created by: Joshua Hickman
PROCEDURE
1. The phone was reset to factory defaults, including a wipe of the device. Android was then
installed.
2. A Google Fi account was added in order to apply cellular service to the device.
3. The bootloader was unlocked.
4. Magisk, a rooting application, was added to the device in order to gain root level access to the
operating system.
5. Thirty-one (31) non-stock apps were installed from the Google Play store and populated with user
data based on each app’s respective capabilities.
6. Stock Android apps were populated with user data based on each app’s respective capabilities.
7. A second user profile was added to the device. User activity data was generated.
Note:
Name: Discord
Version Number: 10.2.8
Install Date: 01/29/2020
Install Time: 12:02
Name: Dust
Version Number: 6.1.3.2887
Install Date: 01/29/2020
Install Time: 12:04
Username: 919-579-4674
Password: fallout-lamp-lymphoma
Note:
Name: GalleryVault
Version Number: 3.14.82
Install Date: 01/29/2020
Install Time: 12:06
Note: This is not a stock app. Some episodes were played through Android Auto; see
entries for that app for playback dates/times.
Name: Imgur
Version Number: 4.5.9.12223
Install Date: 01/29/2020
Install Time: 12:12
Username: thisisdfir@gmail.com
Password: lack-triumph-porous9
Note:
Name: Instagram
Version Number: 126.0.0.25.121
Install Date: 01/29/2020
Install Time: 13:08
Username: thisisdfir
Email: thisisdfir@gmail.com
Password: moleskin-tepee-ageless
Note: Five following, one follower. Previous data resides in this app due to account
sync’ing. Only the data that was populated during the creation of this image is
described below. For information about the previous data, see the documentation
for the Android 7.x, Android 8.x, and Android 9.x images. Chats that appear in
the app Threads also appear here.
Name: kik
Version Number: 15.19.0.22104
Install Date: 01/29/2020
Install Time: 12:08
Username: ThisIsDFIR
Email: thisisdfir@gmail.com
Password: tide-asylum-defense
Note:
Name: Line
Version Number: 10.0.2
Install Date: 01/29/2020
Install Time: 12:05
Note:
Note: This app is installed in order to root the test phone. No data was generated. App
was downloaded via Chrome and installed.
Name: MeWe
Version Number: 6.0.9.4
Install Date: 01/29/2020
Install Time: 12:02
Note: Audio and video calls required subscriptions and were not purchased.
Name: Signal
Version Number: 4.53.7
Install Date: 01/29/2020
Install Time: 12:06
Note:
Username: ThisIsDFIR
Password: jurist-turtle-percept
Phone Number: 919-636-5829
Note:
Name: Skout
Version Number: 6.17.0
Install Date: 01/29/2020
Install Time: 12:07
Username: thisisdfir@gmail.com
Password: *3qpAs82ZgT9UBFZ}TZCqmg4%Av6R&nc
Note:
Name: Skype
Version Number: 8.37.0.98
Install Date: 01/29/2020
Install Time: 12:07
Username: +1 919-579-4674
Screen Name: This Is DFIR
Skype Name: live:756b2840ef68b86b
Password: seed-varlet-leftover
Note:
Name: Snapchat
Version Number: 10.74.6.0
Install Date: 01/29/2020
Install Time: 12:09
Username: thisisdfir
Name: This Is DFIR
Email Address: thisisdfir@gmail.com
Password: antelope-waxwing-tidbit
Note: Chat settings were changed from the default (delete after viewing) to delete
after 24 hours. Some account data was sync’d from Snapchat servers due to
previous population.
Name: Spotify
Version Number: 8.5.42.812
Install Date: 01/29/2020
Install Time: 12:06
Username: thisisdfir
Name: Thisisdfir
Email Address: thisisdfir@gmail.com
Password: socket-ominous-tactics
Note:
Name: Telegram
Version Number: 5.14.0
Install Date: 01/29/2020
Install Time: 12:06
Note:
Name: TextNow
Version Number: 20.1.1.0
Install Date: 01/29/2020
Install Time: 12:08
Username: thisisdfir@gmail.com
TextNow Number: 984-235-2054
Password: flirt-dewberry-wardrobe
Note:
Username: thisisdfir
Email: thisisdfir@gmail.com
Password: moleskin-tepee-ageless
Name: TikTok
Version Number: 14.7.5
Install Date: 01/29/2020
Install Time: 12:07
Username: 9195744674
Password: relation-meal-tenpin
Note:
Note:
Name: Twitter
Version Number: 8.29.0-release.00
Install Date: 01/29/2020
Install Time: 12:09
Username: @TDfir
Password: ides-cudgel-husking
Note: Previous data resides in this app due to account sync’ing. Only the data that was
populated during the creation of this image is described below. For information
about the previous data, see the documentation for the Android 7.x, Android 8.x,
and Android 9.x images.
Name: Venmo
Version Number: 7.45.0
Install Date: 01/29/2020
Install Time: 12:02
Username: @ThisIs-DFIR
Password: perfuse-show-rubric-the
Note:
Name: Viber
Version Number: 12.2.2.1
Install Date: 01/29/2020
Install Time: 12:05
Phone: 919-579-4674
Note:
Name: WhatsApp
Version Number: 2.20.11
Install Date: 01/29/2020
Install Time: 12:09
Phone: 919-574-4674
Note:
Name: WeChat
Version Number: 7.0.10
Install Date: 01/29/2020
Install Time: 12:04
Note:
Name: Wickr Me
Version Number: 5.45.4
Install Date: 01/29/2020
Install Time: 12:04
Username: ThisIsDFIR
Password: offing-ammo-railbird
Phone: +1 919-579-4674
Note:
Name: Wire
Version Number: 3.44.877
Install Date: 01/29/2020
Install Time: 12:04
Note:
Each time the device was connected to the vehicle also indicates a power event
(on charge). Power event stops when device is disconnected. Messages that are
read/dictated will appear in the Message section of the document. Each
connection event also indicates a Bluetooth connection.
Name: Camera
Version Number: 7.2.018.281779528
Note: For information about the disposition of the picture listed below, see the entry for
the Photos app.
Name: Chrome
Version Number: 79.0.3945.136
Note:
Name: Docs
Version Number: 1.20.022.05.40
Note: An action to move the document was taken within Drive. See that app’s entries
for details.
Name: Drive
Version Number: 2.20.035.04.40
Note:
Name: Duo
Version Number: 71.0.290855224.DR71_RC06
Note:
Name: Gmail
Version Number: 2019.12.30.289507923.release
Note:
Name: Google
Version Number: 10.93.13.21.arm64
Note: Some Google activity (Assistant) was conducted via Android Auto. See the
entries for that app for details on that activity. This section will also include
activity conducted in the Google Search Bar (GSB) from the home screen.
Messages that were sent using Google Assistant will also be seen in the
Messages app below.
Note: No action was taken with the app. However, a Google Home Speaker (“Office
Speaker”) and Google Home Hub (“Office Display”) was seen in the app (those
devices were setup by a different device).
Name: Maps
Version Number: 10.33.1
Note: Some Maps activity was conducted via Android Auto. See the entries for that
app for details on that activity. Map usage via Android Auto should appear in the
Maps area of the image.
Name: Messages
Version Number: 5.2.062 (Pegasus_RC17_xxhdpi.arm64-v8a.phone)
Note: For a listing of messages, please see the Excel spreadsheets in the folder
“Messages.”
02/09/2020 13:41 Message sent I am on my way to the coffee shop. Do you want
anything?
13:43 Message received No, thank you.
Name: Phone
Version Number: 43.0.290782351
Note:
Name: Photos
Version Number: 4.36.0.290828616
Note: Camera and other apps placed pictures in Photos. No actions were taken within
the app. If a picture was saved via another app, the entry is documented in that
app.
POWER EVENTS
Below are the power events that occurred on the device.
SSID Password
CcookiesDcastleR5 No password is stored for this BSSID
Android 10 Image Image Created by: Joshua Hickman
Name: Nissan
MAC: b4:ec:02:73:ff:93
Android 10 Image Image Created by: Joshua Hickman
OTHER EVENTS
Below are other various events that occurred on the device.
Android 10 Image Image Created by: Joshua Hickman
Figure 1 – Home Screen 1.
Android 10 Image Image Created by: Joshua Hickman
Figure 2 – Home Screen 2.
Android 10 Image Image Created by: Joshua Hickman
Figure 3 – Home Screen 2 with exposed folder.
Android 10 Image Image Created by: Joshua Hickman
USER 2 ACTIVITY
Name: Camera
Version Number: 7.2.018.281779528
Note: For information about the disposition of the picture listed below, see the entry for
the Photos app.
Name: Chrome
Version Number: 79.0.3945.136
Note:
Name: Google
Version Number: 10.93.13.21.arm64
Note:
Note:
Name: Gmail
Version Number: 2019.12.30.289507923.release
Note:
Name: Messages
Version Number: 5.2.062 (Pegasus_RC17_xxhdpi.arm64-v8a.phone)
Note: For a full listing of messages, please see the Excel spreadsheets in the folder
“Messages.”
Name: Phone
Version Number: 43.0.290782351
Note:
Name: Snapchat
Version Number: 10.75.5.0
Install Date: 02/14/2020
Install Time: 08:45
Username: tdfirtwo
Name: This Is DFIR Two
Email Address: thisisdfirtw0@gmail.com
Password: crease-acts-cra
Note: Chat settings were changed from the default (delete after viewing) to delete
after 24 hours.
Name: Wickr Me
Version Number: 5.46.1
Install Date: 02/14/2020
Install Time: 09:27
Username: thisisdfirtwo
Password: warren-foreleg-ambient
Phone: none
Note:
Android 10 Image Image Created by: Joshua Hickman
IMAGE CREATION
Application: Cellebrite UFED 4PC
Version: 7.28.2.8
Date: 02/14/2020
Time: 18:43
Note: All files are included in the zip file Android 10 Image with Documentation.zip.
Once extracted, multiple files are present. The document
Android10-ImageCreation.pdf along with the file folder FileSystem ADB 02.
The extraction is segmented across several files; a .ufd file is included.
Hash Values:
MD5: c6f52d360b8024ba218050d50fd3fc4e
SHA-1: 7b742df7cdc9527d1a87516308f350935554f589
SHA-256: cbcc2624170347515cd1d0daac2c0d5d49fb2ee8bec08ff57e1b4f13d0c1a641
MD5: e9e3be16594e65a90fc712795d72de42
SHA-1: bb91c934c3fe5977428e2ec8b3d11b9aa5fb4542
SHA-256: d1b6a233d67ba1022feab914796ee0864f14868e4b1adfffeab31bb04e887f1e
MD5: d3430253650c4686b32855b3ed1e96e3
SHA-1: c11f9e0e6d2e572fa02957a2c5511d7b28eaeb32
SHA-256: 82e59a968ef3cc51e61e0ebaf3cbbce11827b12a92b8abf30a68d5b591e02a0d
MD5: b68dfd27113c9498b616a57d302ec939
SHA-1: a8518c3f550266485b372076b59242ddecaab389
SHA-256: 5dc14cbd8d7745361816404680b8a3f9ce9d934318ea092712308f2f6936cf06
Android 10 Image Image Created by: Joshua Hickman
MD5: e8935c29acdf3152f2e7fa8b49f4717f
SHA-1: 020c6368faf717f83cb9ffecb74d6c36e11f9c67
SHA-256: a0d51333f3f2775647b08fa9e08551d7daa27d223a53dcf95f6a789646f1586b
MD5: 9686ec3068351a6f30e8369a437c9600
SHA-1: ee573b2a28da8966e7d3e484d73a53af9681a87e
SHA-256: 395db9eac18d868482e98b7d0e313f726ce0f6c16bf71b341df70b50a1671563
MD5: 82212a983140cf27f644ac083b2c2bad
SHA-1: 0adad282ffd85e62ad47f7b0bb476ae5bfe900ec
SHA-256: 5d1c3bf9c95923cc2f4ea98921f720f32510aae1753a132ee4867426f8e49730
MD5: 37a9419354d8e71aedad051bd3283de8
SHA-1: d2b00c95f9bc31ce250d061492aa2ca69a163813
SHA-256: 3dba6d8083d5d7f56044a60bcfcb820b7edf4027a7b0acfbd4e29ea3cb18b78a
MD5: 214ed9c81144dd4a9ca55c5fc11d945c
SHA-1: 63fa898492aa6f6453686ff3ba7ca948ea5a3fc7
SHA-256: 721c65557617004a9846817432ee210eade34659e5c617869b59b3fc08619675
MD5: 286da85cf63eb5027a77b03792bd216b
SHA-1: 6732d2e9607409510afac080717b7cdd7eaa17ef
SHA-256: ba74bdb0074348ab9d9305319bd0140c468bfe3c077a44911c31c8555a0b83be
SMS-Messages.xlsx
MD5: e0d08e10d6084077293220a03289008e
SHA-1: 9817705daa3ae687ec824738d90e60c67a75c5c2
SHA-256: e5f158d6560b5458039728424e4390a8182a578e919617442d326c5591861310