Cryptocurrency has been (ab)used to purchase illicit goods and services such as drugs, weapons and child pornography (also referred to as child sexual abuse materials), and thus mobile devices (where cryptocurrency wallet applications are installed) are a potential source of evidence in a criminal investigation. Not surprisingly, there has been increased focus on the security of cryptocurrency wallets, although forensic extraction and attribution of forensic artefacts from such wallets is understudied. In this paper, we examine Bitcoin and Dogecoin. The latter is increasingly popular partly due to endorsements from celebrities and being positioned as an introductory path to cryptocurrency for newcomers. Specifically, we demonstrate how one can acquire forensic artefacts from Android Bitcoin and Dogecoin cryptocurrency wallets, such as wallet IDs, transaction IDs, timestamp information, email addresses, cookies, and OAuth tokens.
翻译:加密货币被用于购买非法物品和服务,如毒品、武器和儿童色情(也称为儿童性虐待材料),因此移动装置(安装加密货币钱包应用程序的地方)是刑事调查中可能的证据来源,毫不奇怪,对加密货币钱包的安全给予了更多的重视,尽管对从这类钱包中提取的法医手工艺品的法证提取和归属研究不足。在本文件中,我们检查了Bitcoin和Dogecoin,后者越来越受欢迎,部分原因是名人认可,并被定位为新来者加密货币的介绍性途径。具体地说,我们展示了人们如何从Android Bitcoin和Dogecoin加密货币钱包获得法医手工艺品,例如钱包身份、交易身份、时间戳信息、电子邮件地址、饼干和OAuth标志。