Forensic Case 1 - Wes Mantooth Case

March 12, 2024 | Author: Anonymous | Category: N/A
Share Embed Donate


Short Description

Download Forensic Case 1 - Wes Mantooth Case...

Description

Forensic Case 1 - Wes Mantooth Case Date of Examination: 4/2/19 Examiners: Rafay Ahmad, Alex Rein, Joonyoung Cha, Tyler Kuhn, Hannah Broadwell Reason For Examination: name was pulled over and arrested for drugs, the team is searching his computer for more information Item: Do we have the computer’s serial number and where it was found? Recommendations: Evaluate all findings in document to further investigation

*I guess this is something related with WES’s serial number info. (AccessData Registry Viewer) Software – Microsoft – Windows NT – CurrentVersion

Table of Contents:

Evidence Image 1 and 2…. Page 3 Explanation

Evidence Image 3 and 4….. Page 3 Explanation

Evidence Images 5-8……….Page 5 Explanation

Image 9-10…………………...Page 6-7

Image 11-20…………………..Page 8-13 Image 20-23…………………..Page 14-17 Explanation

Evidence: Image 1 and 2

Explanation: The screenshots above are evidence of a confession document named My Confession.txt found on the computer’s desktop in a folder labeled “Stuff to Delete”. It is not 100% clear on what the person is confessing to other than that they steal from the rich and poor.

Image 3 and 4

Explanation: Image 3 and 4 are evidence of Photoshopping checks from “Sean”. First file labeled “Seanbefore.jpg” and blank check file named “Seanafter.jpg”. After this initial evidence was found plenty more fraud blank checks were discovered.

Images 5-8

Explanation: The above screenshots show multiple check designs for “Dana”. Does anyone know how to crack this? Image 9

Image 10

Also there were tons of conversation going on * Please check the dates for an order.

Image 11 - 20

Explanation: Images 11-20 show conversations between Wes, Rosco, Skimmerman, and John. The conversation include evidence of the group having “the goods” and talk about having them on ice and moving them. Conversations about getting caught and rigging machines is also part of the evidence above.

Image 20-23

Explanation: Image 20-23 shows how we found the ingredients for crystal meth document that the person in question has in their document folder.

+

Suspicious drug images has been found.

+

Something was encrypted

The photo above represents a Yahoo! Messenger username found on Wes’ account. The username “incisorman420” includes the universal number associated with the drug Marijuana.

View more...

Comments

Copyright ©2017 KUPDF Inc.
SUPPORT KUPDF