Arsenal’s “Anchors in Relative Time” analysis technique was essential to uncovering an unprecedented series of local and remote attacks against Barış Pehlivan’s Odatv computer. The “Anchor Types” shown here are a fundamental part of applying Anchors in Relative Time to modern Microsoft Windows computers and storage devices using Microsoft’s NTFS. Barış Pehlivan’s Odatv computer contained a single hard drive with two storage volumes (referred to here as his “Windows boot volume” and “Auxiliary volume”) and you will see in the following tables that it was important to apply Anchors in Relative Time analysis to both of them.
Event Log Service Start and Stop events (which are normally consistent with Windows starts and stops) between February 9 and 11, 2011 from the System event log on Barış Pehlivan’s Odatv computer. Notice the “RecordNumber” values which increment as expected.
Combinations of $UsnJrnl file system transactions from the Windows boot volume of Barış Pehlivan’s Odatv computer which uniquely and consistently identify Windows starts and stops between February 9 and 11, 2011. Notice the “USN Number” values which increment as expected.
$LogFile file system transactions from the Windows boot volume of Barış Pehlivan’s Odatv computer which uniquely and consistently identify a Windows start and stop on February 11, 2011. Notice the “LSN Number” values which increment as expected and the “Related USN” values.
Combinations of $LogFile file system transactions from the auxiliary volume of Barış Pehlivan’s Odatv computer which uniquely and consistently identify Windows starts and stops between February 9 and 11, 2011. Notice the “LSN Number” values which increment as expected.
A simplified list of Windows starts and stops from combinations of $UsnJrnl file system transactions (see Table 3) on the Windows boot volume of Barış Pehlivan’s Odatv computer.
A simplified list of Windows starts and stops from combinations of $LogFile file system transactions (see Table 5) on the auxiliary volume of Barış Pehlivan’s Odatv computer.
The creation and deletion of the most incriminating documents on the auxiliary volume of Barış Pehlivan’s Odatv computer put into context with Windows starts and stops. Notice the progression of “Anchor #” values and the unusual dates and times associated with some of them.
The creation of Remote Access Trojans (RATs) on the Windows boot volume of Barış Pehlivan’s Odatv computer put into context with Windows starts and stops. Notice the progression of “Anchor #” values and the unusual dates and times associated with some of them.
Components of Ahtapot, the RAT created on the Windows boot volume of Barış Pehlivan’s Odatv computer the evening of February 11, 2011.
A summary of suspicious activity on the Windows boot volume of Barış Pehlivan’s Odatv computer between February 9 and 14, 2011.
A summary of suspicious activity on the auxiliary volume of Barış Pehlivan’s Odatv computer between February 9 and 14, 2011.
A summary of both local and remote RAT attacks against Barış Pehlivan’s Odatv computer from January 2011 onward.
Please note, since the publication of this summary in Digital Forensics Magazine Issue 27, Arsenal has learned more about the local attacks, email attacks, and their RATs. You can see the most up-to-date information about the email attacks and their RATs, as well as the emails themselves, in “The Email Attacks” gallery. We will publish updated information about the local attacks in the future.
Critical documents created and deleted the evening of February 11, 2011, on the auxiliary volume of Barış Pehlivan’s Odatv computer, as seen by Guidance Software’s EnCase, AccessData’s FTK, and X-Ways Software Technology’s X-Ways Forensics. See Table 8 for more information about the creation and deletion of these documents.
Arsenal spreadsheet (Microsoft Excel) containing active MFT output from Joakim Schicht’s Mft2Csv v2.0.0.36.
Bandook and Ahtapot Remote Access Trojans (RATs) created the evenings of February 9 and 11, 2011, on the Windows boot volume of Barış Pehlivan’s Odatv computer, as seen by Guidance Software’s EnCase, AccessData’s FTK, and X-Ways Software Technology’s X-Ways Forensics. See Table 9 for more information about the creation of these RATs.
Arsenal spreadsheet (Microsoft Excel) containing active MFT output from Joakim Schicht’s Mft2Csv v2.0.0.36.
This email purports to include a poster which will make the President of YOK mad. It alleges that the AKP is using YOK (Turkey’s Council of Higher Education) to plot against universities. It also suggests that YOK be abolished and its President Ziya Ozcan brought to trial.
Download native versions of this email (from barisp, barist, info, and sonery mailboxes on Barış Pehlivan’s Odatv computer) with attachment stripped.
View Decoy Image
Attachment Name: yok.rar
Attachment Hash: 9d8805d4c0572d7b2fea913f84074401
Attachment Content: yok.scr
Attachment Content Hash: a686dc1d6a4cc68f111e5a18af4131e9
Remote Access Trojan Identity: Bandook with Decoy
Command & Control: blogg.serveblog.net, twiter.serveblog.net, messenger.serveirc.com
This email purports to include a newsworthy document. The sender says that he follows “your” news regularly and hopes to see what he has provided in future news.
Download native versions of this email (from barisp, barist, info, and sonery mailboxes on Barış Pehlivan’s Odatv computer) with attachment stripped.
View Decoy Image
Attachment Name: belge.zip
Attachment Hash: 61890ec3617cfdeaf736bf389fa0fe8e
Attachment Content: belge.scr
Attachment Content Hash: bf24a6e6ff11192391abe532452a5ba9
Remote Access Trojan Identity: Turkojan with Decoy
Command & Control: tigereyes2.servepics.com
This email purports to include an analysis of before and after the AKP which will remind one of “certain things.” The sender urges that this information be distributed.
Download native version of this email (from barisp mailbox on Barış Pehlivan’s Odatv computer) with attachment stripped.
View Decoy Image
Attachment Name: AKP_oncesi-sonrasi.pdf
Attachment Hash: 686079b97d40e96a5ceadb1638666aef
Remote Access Trojan Identity: Bandook with Exploit and Decoy
Command & Control: driver.myftp.org
This email purports to include a screen saver with pictures of Ataturk, built by one of “our members” and “worth trying.”
Download native versions of "Atatürk…" email (from barist and info mailboxes on Barış Pehlivan’s Odatv computer and sent to Müyesser Yıldız’s personal Yahoo! account muyesseryildiz@yahoo.com) with attachment stripped.
This email purports to include a “most suitable” application for receiving RSS news faster and more efficiently.
Download native versions of this email (from barisp and barist mailboxes on Barış Pehlivan’s Odatv computer and sent to Müyesser Yıldız’s personal Yahoo! account muyesseryildiz@yahoo.com) with attachment stripped.
Attachment Name: RssReader2.1.zip
Attachment Hash: fe0cfc6ce9ab4d3728661f2d1091abef
Attachment Content: RssReader2.1.exe
Attachment Content Hash: 8e5bccfa5beba02720544bb96f7b0375
Remote Access Trojan Identity: Turkojan
Command & Control: antivirus.myftp.org
This email purports to include a schedule of events the Turkish President will be attending the following week. It is directed to "members of the press."
Download native versions of "Basın Duyurusu" email (barisp and barist mailboxes on Barış Pehlivan’s Odatv computer and sent to Müyesser Yıldız’s personal Yahoo! account muyesseryildiz@yahoo.com) with attachment stripped.
This email purports to include AKP cartoons that "you can’t find anywhere else."
Download the native version of this email (from barist mailbox on Barış Pehlivan’s Odatv computer and sent to Müyesser Yıldız’s personal Yahoo! account muyesseryildiz@yahoo.com) with attachment stripped.
Attachment Name: AKPkarikaturleri.zip
Attachment Hash: e64ae254070700e523cf053dca745fa9
Attachment Content: 0tayyip2it2.scr, 1tayyip.scr, 27cilali.gif, gun19907.jpg, kapak116sm0.jpg, tayyip2it2.jpg, y6rr3.jpg
0tayyip2it2.scr and 1tayyip.scr Hash: f58dfcf5b186f4521e451452bc7609b2
Remote Access Trojan Identity: Bandook
Command & Control: adobupdate.serveftp.com, adobupdate.servehttp.com
These eleven documents were crucial to the indictments of the Odatv defendants.
Bilinçlendirme.doc purportedly contains strategies of the Ergenekon organization and instructs Sledgehammer and Ergenekon defendants (and their attorneys) to create difficulties for the courts. We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on July 26, 2010.
Sample Microsoft Word Metadata
Author: USER
Last Saved By: soner
Create Time (UTC): 03/03/10 05:56 PM
Last Saved Time (UTC): 03/24/10 11:15 PM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Bilinçlendirme.doc found on Barış Pehlivan’s Odatv computer.
Hanefi.doc purportedly contains Ergenekon-related directives from Soner Yalçın (Odatv co-founder), Hanefi Avcı (a former police chief) and Nedim Şener (a prominent investigative journalist). We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on July 26, 2010. This document was also found on Müyesser Yıldız’s personal computer, created on February 14, 2011 - the same day Odatv was being raided by the Turkish National Police - but its timestamps were tampered with to make it appear as if it was created on August 17, 2010.
Sample Microsoft Word Metadata
Author: soner
Last Saved By: soner
Company: Conqueror
Embedded Create Time (UTC): 07/12/10 07:06 AM
Embedded Last Saved Time (UTC): 07/12/10 07:17 AM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Hanefi.doc found on both Barış Pehlivan’s Odatv computer and Müyesser Yıldız’s personal computer.
Koz.doc purportedly contains directives from Soner Yalçın (Odatv co-founder) regarding how information obtained from Kaşif Kozinoğlu (another Odatv defendant who was a senior intelligence officer at Turkey’s MİT and is now deceased) should be used by Odatv. We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on August 16, 2010.
Sample Microsoft Word Metadata
Author: soner
Last Saved By: soner
Company: Conqueror
Embedded Create Time (UTC): 08/04/10 09:48 AM
Embedded Last Saved Time (UTC): 08/04/10 09:49 AM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Koz.doc found on Barış Pehlivan’s Odatv computer.
Nedim.doc purportedly contains directives from Soner Yalçın (Odatv co-founder) regarding avoiding conflict in views between Hanefi Avcı (a former police chief) and Nedim Şener (a prominent investigative journalist). We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on August 16, 2010.
Sample Microsoft Word Metadata
Author: soner
Last Saved By: soner
Company: Conqueror
Embedded Create Time (UTC): 08/09/10 05:32 AM
Embedded Last Saved Time (UTC): 08/09/10 05:35 AM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Nedim.doc found on Barış Pehlivan’s Odatv computer.
Org mu.doc document purportedly contains directives from Soner Yalçın (Odatv co-founder) regarding how Odatv should be covering news related to Bilgin Balanlı (a Sledgehammer defendant). We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on January 11, 2011.
Sample Microsoft Word Metadata
Author: soner
Last Saved By: soner
Company: Conqueror
Embedded Create Time (UTC): 01/10/11 01:29 PM
Embedded Last Saved Time (UTC): 01/10/11 01:42 PM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Org mu.doc found on Barış Pehlivan’s Odatv computer.
Sabri Uzun.doc purportedly contains directives from Soner Yalçın (Odatv co-founder) regarding Nedim Şener (a prominent investigative journalist), Hanefi Avcı (a former police chief), and Sabri Uzun (another former police chief). We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on December 20, 2010.
Sample Microsoft Word Metadata
Author: soner
Last Saved By: soner
Company: Conqueror
Embedded Create Time (UTC): 12/20/10 09:29 AM
Embedded Last Saved Time (UTC): 12/20/10 09:35 AM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Sabri Uzun.doc found on Barış Pehlivan’s Odatv computer.
SY.doc purportedly contains directives from Soner Yalçın (Odatv co-founder) related to Odatv news coverage and mentions that some Sledgehammer and Ergenekon defendants are closely involved in shaping Odatv’s policies. We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 9, 2011, but its file system timestamps were tampered with to make it appear as if it was created on November 11, 2010. This document was also found on Müyesser Yıldız’s personal computer, created on February 14, 2011 - the same day Odatv was being raided by the Turkish National Police - but backdated to appear as if it was created on August 1, 2010.
Sample Microsoft Word Metadata
Author: soner
Last Saved By: TOSHIBA
Company: Conqueror
Embedded Create Time (UTC): 7/23/2010 12:20PM
Embedded Last Saved Time (UTC): 7/26/2010 6:05AM
Creating Application: Microsoft Office Word
Code Page: 1252 (Latin I)
Download native version of SY.doc found on both Barış Pehlivan’s Odatv computer and Müyesser Yıldız’s personal computer.
teRTEmiz.doc purportedly contains strategies regarding how Odatv news should oppose the AKP government. We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on July 26, 2010.
Sample Microsoft Word Metadata
Author: Your User Name
Last Saved By: soner
Embedded Create Time (UTC): 10/02/08 09:47 AM
Embedded Last Saved Time (UTC): 10/09/08 10:12 AM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of teRTEmiz.doc found on Barış Pehlivan’s Odatv computer.
toplantı.doc purportedly contains comments from Yalçın Küçük (writer and philosopher) on how the editorial policies of Odatv should be shaped. We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on April 26, 2010.
Sample Microsoft Word Metadata
Author: Barış
Last Saved By: Barış
Embedded Create Time (UTC): 04/25/10 10:19 AM
Embedded Last Saved Time (UTC): 04/25/10 10:33 AM
Creating Application: Microsoft Office Word
Code Page: 65001 (Unicode UTF-8)
Download native version of toplantı.doc found on Barış Pehlivan’s Odatv computer.
Ulusal Medya 2010.doc purportedly contains instructions on how various media outlets (Odatv, Halk Tv, Ulusal Tv, etc.) should discredit the Ergenekon cases and institutions pursuing them. We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 11, 2011, but its file system timestamps were tampered with to make it appear as if it was created on September 28, 2010. This document was also found on Müyesser Yıldız’s personal computer, created on February 14, 2011 - the same day Odatv was being raided by the Turkish National Police - but backdated to appear as if it was created on October 4, 2010.
Sample Microsoft Word Metadata
Author: pc
Last Saved By: soner
Company:
Embedded Create Time (UTC): 07/21/10 06:03 PM
Embedded Last Saved Time (UTC): 09/27/10 11:33 AM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Ulusal Medya 2010.doc found on Barış Pehlivan’s Odatv computer and Müyesser Yıldız’s personal computer.
Yalçın hoca.doc purportedly contains directives from Yalçın Küçük (writer and philosopher) on how Odatv’s editorial policies should be shaped to discredit the AKP government and Gülen movement. We know that this document was created and immediately deleted from Barış Pehlivan’s Odatv computer (see Anchors in Relative Time Table 8) the evening of February 9, 2011, but its file system timestamps were tampered with to make it appear as if it was created on November 11, 2010. This document was also found on Müyesser Yıldız’s personal computer, created on February 14, 2011 - the same day Odatv was being raided by the Turkish National Police - but backdated to appear as if it was created on September 9, 2010.
Sample Microsoft Word Metadata
Author: soner
Last Saved By: soner
Company: Conqueror
Embedded Create Time (UTC): 06/18/10 08:23 AM
Embedded Last Saved Time (UTC): 09/08/10 06:31 AM
Creating Application: Microsoft Word 10.0
Code Page: 1254 (Turkish)
Download native version of Yalçın hoca.doc found on Barış Pehlivan’s Odatv computer or native version of Yalçın hoca.doc found on Müyesser Yıldız’s personal computer.
On November 22, 2015, while the Odatv trial was ongoing, Arsenal was asked about our expert report related to a criminal case involving a Türk Telekom auditor. The expert report was apparently emailed by the defendant to journalists at Odatv, who then distributed it to others before it arrived back at Arsenal for our comment.
Arsenal had never heard of the case or the defendant. The report was not ours.
We believe this situation is unprecedented in the digital forensics community. We are aware of expert reports having been copied and weaponized, but never forged in the manner which you will see here. There are a variety of reasons we have held off on publishing this information, but those reasons are no longer as compelling as they were in the past.
The email chain between defendant Adem Cetinkaya and Odatv, which included the forged Arsenal report and other attachments.
Download email in Rich Text Format.
Draft English Translation from Adem Cetinkaya email: Annex-1 is the report prepared by Istanbul IT Unit (Arsenal note: Turkish National Police), which says that the hard disk was formatted and no content could be found.
Turkish from Adem Cetinkaya email: Ek-1 de İstanbul Bilişim Şube Müdürlüğü tarafından hazırlanan rapor, harddiske format atıldığını hiçbir içeriğie ulaşılamadığını ifade ediyor.
Draft English Translation from Adem Cetinkaya email: Annex-2 is the report we have obtained (Arsenal note: Apparently, from us!) to find out the date when the hard disk was formatted and when the deletions and modifications were made. This report establishes that the deletions were done two days after 12/07/2010, when the hard disk was seized, and it identifies a large number of logs that are related to my illegal wiretapping activities through Türk Telekom.
Turkish from Adem Cetinkaya email: EK-2 de Harddiske hangi tarihte format atıldığını hangi tarihte silme değiştirme işlemlerinin yapıldığını tespit etmek amacıyla yeni bir bilirkişi raporu alıyoruz. Bu raporda silme işleminin 07.12.2010 tarihinde bilgisayara el konulduktan 2 sonra yapıldığını tespit ediyor ve silinen Türk Telekom üzerinde yürrüttüğüm yasadışı dinleme faaliyetlerine ilişkin logların büyük bir kısmını geri getiyor.
Read the Full Report - Converted from PDF to PNG
Draft English Translation from Adem Cetinkaya email: Annex-3 The digital data related to the illegal wiretaps and memos are delivered to Istanbul Unit for Organized Crimes (Arsenal note: Turkish National Police).
Turkish from Adem Cetinkaya email: Ek-3 Söz konusu yasadışı dinleme ve bilgi notlarına ilişkin dijital veriler İstanbul Organize Suçlarla mücadele şube müdürlüğüne teslim ediliyor.
Draft English Translation from Adem Cetinkaya email: The memos on the tapped IMEI addresses located in a zipped file located in the @212.1.209.zip folder, the IP address to which Istanbul Police Intelligence Unit has been sending the data, the logs of the foreign IP addresses that are originated in North Carolina, the IP addresses that are used to send emails that contain malicious codes and attachments, the file named H.avciirtibatlarbilginotu.bfa, the “analyzed” versions of these files are available in the file at the Organized Unit, which I mentioned in my earlier mail address.
Turkish from Adem Cetinkaya email: klasöründe yer alan zipli dosya içinde dinlenen imei adresleri bilgi notları, İstanbul Emniyet İstihbarat Şube Müdürlüğü’nün verileri göndermekte olduğu IP adresi, Kuzey Karolanya menşeili yurt dılşı Ip adreslerine ait loglar, zararlı kod ve eklenti içeren e-posta gönderilmesinde kullanılan Ip adresleri, H.avciirtibatlarbilginotu.bfa isimli dosya, bu dosyaların çözümlü hali Organize Şubedeki onceki mail adresimde belirttiğim dosyada mevcut.
Arsenal will make the contents of @212.1.209.zip available soon.
Important events during the final stages of the Odatv trial.
Arsenal prepared these 17 questions for Turkish digital forensics experts on June 29, 2015 after being asked to take a “quick look” at Barış Pehlivan’s Odatv Computer. A Turkish court then ordered local experts to answer Arsenal’s questions, essentially forcing them to confront the true nature of the evidence tampering involving Barış Pehlivan’s Odatv Computer. Please keep in mind that Arsenal learned much more about Barış Pehlivan’s Odatv Computer (and others) after preparing these questions on June 29, 2015 - for example, we learned his computer was attacked four times locally (rather than two) and there was a better combination of $LogFile file system transactions on the second partition unique to Windows shutdowns.
Download the 17 questions.