# Scanned_20260730-1806 ## Archival orientation This note reconstructs all 27 PDF pages of `Scanned_20260730-1806.pdf`, including the blank opening page, sparse headings, uncertain handwriting, strike-throughs, highlighting, diagrams, package identifiers, file extensions, device build strings, and app-inspection legends. The source is an image-only scan; page interpretation therefore comes from visual inspection rather than extracted PDF text. Transcriptions preserve the notebook's spelling and capitalization. Apparent mistakes are retained in quotation and corrected only in the analysis. Ambiguous readings are marked `[uncertain: ...]`; obscured material is marked `[illegible]`; visible cancellations are marked `[crossed out: ...]`. The notebook is best understood as a **mobile-software and file-provenance investigation notebook**. Its first half inventories operating systems, storage and recovery products, file extensions, graphics and audio containers, registry and filesystem concepts, hardware vendors, and disk utilities. Its second half narrows decisively onto one [[Moto G Stylus (2021)]] running [[Android 10]], then documents its build fingerprint, Java runtime, APK internals, app provenance, package flags, permissions, trackers, manifests, system identities, and installed-package domains. The notebook's epistemic movement is from **heterogeneous format recognition** toward **on-device Android forensic cartography**. ## Source-owner corrections and normalization - The canonical notebook identity is exactly `Scanned_20260730-1806`; this file should remain `Scanned_20260730-1806.md`. - Obsidian links intentionally omit any folder prefix and use `[[Canonical Note Name|Visible Text]]`. - No password-equivalent secret is visible in this notebook. The iCloud address and case identifier on page 2 are retained under the project's default archival rules. - Several handwritten technical strings are demonstrably copied with small errors. They remain exact in transcription; the analysis separately identifies the probable normalized form. - Cross-notebook links are based on the visible neighboring scans in the same NOTEBOOKS corpus and should be refined if later reconstructions alter page headings or canonical entity names. ## Knowledge-graph navigation Closely related notebooks include [[Scanned_20260730-1756]] for [[UserLAnd]], [[Android 10|Android Q]], `com.vzw.apnlib`, and system-interface observations; [[Scanned_20260730-1802]] for cross-platform device and controller inventories; [[Scanned_20260730-1235]] for obscure Apple commands, status pages, and access pathways; [[Scanned_20260730-1720]] for storage controllers, McAfee, Windows Storage Spaces, and silent installation; [[Scanned_20260730-1719]] for cloud, AMD, data-center, MAC-address, and cryptographic infrastructure; and [[Scanned_20260730-1845]] for the later transition from software inspection toward [[OpenAI]], APIs, and concentric systems models. [[Index - Master Chronology|Master Chronology]] · [[Index - People|People]] · [[Index - Company and Institution|Companies and Institutions]] · [[Index - Acronym Dictionary|Acronym Dictionary]] · [[Index - Technology and Product Lineage|Technology and Product Lineage]] · [[Index - Domain and URL Index|Domain and URL Index]] · [[Index - Device Inventory|Device Inventory]] · [[Index - Project and Concept|Projects and Concepts]] · [[Index - Pattern Ledger|Pattern Ledger]] · [[Index - Unresolved Names and Identifiers|Unresolved Names and Identifiers]] · [[Index - Notebook Sources|Notebook Sources]] · [[Index - Events|Events]] · [[Index - Stages of Interception|Stages of Interception]] --- ## Page 1 — `Scanned_20260730-1806.pdf`, PDF page 1 ### Visible page A full ruled notebook page photographed straight-on. The paper is off-white with green horizontal rules, browned and shadowed along both vertical edges. There are a few faint tan stains near the upper center and lower-right quadrant, plus small specks and handling marks. No cover, label, handwriting, diagram, erasure, or pasted object is visible. This appears to be a genuinely unused interior page rather than a scan failure. ### Faithful transcription No visible text. ### Entities and references None. ### Reconstruction, research, and technical meaning The blank opening is archivally meaningful because the PDF begins **inside** a notebook rather than with a photographed cover. Either the physical cover was omitted, the first sheet served as a spacer, or the scan began after an earlier detached section. The edge wear and discoloration show that this page belonged to a used physical volume even though it carries no semantic content. ### Evidentiary status - **Visible evidence:** blank ruled paper with handling wear and minor stains. - **Strong inference:** this is an unused interior page, not an intentionally erased technical page. - **Unresolved ambiguity:** whether a cover or preceding pages were absent from the scan. ### Cross-notebook and corpus connections Several notebooks in the July 30 scan batch begin with a cover or pasted identifier; this one instead begins with a blank leaf. That difference should remain in the master physical-description ledger because it may indicate that `Scanned_20260730-1806` is a fragment or continuation rather than a complete bound notebook. ### Missed Signals and Open Leads Determine whether page 1 was originally adjacent to a detached cover, whether the physical notebook had identifying marks outside the scanned area, and whether its first written page was deliberately left after a blank separator. --- ## Page 2 — `Scanned_20260730-1806.pdf`, PDF page 2 ### Visible page A heavily used ruled page with black handwriting concentrated in the upper three quarters. The first two lines are written larger than the task list below. “To Do” is underlined twice. A long sweeping pen line begins beneath “Gadgets,” arcs across the lower page, and visually terminates near “App Manager Activity,” grouping or emphasizing the last task. There are no strike-throughs or pasted objects. ### Faithful transcription > "[email protected]" > "Case #101252772308" > "3:55 / 4:00" > "Benit" > "To Do" > "Update Roms" > "Dialer - Phones/Tablets" > "Lineage Info" > "Gadgets" > "App Manager Activity" ### Entities and references [[iCloud|iCloud]], an Apple account/support context, a case identifier, possible person or shorthand “Benit,” [[Read-Only Memory Image|ROMs]], [[Android Dialer|Dialer]], phones, tablets, [[LineageOS|Lineage]], gadgets, and [[Android Application Manager|App Manager]] activity. ### Reconstruction, research, and technical meaning This page functions as the notebook's **operational header**. The iCloud address and case number suggest a support interaction—possibly with Apple—timed or logged at “3:55 / 4:00.” The isolated “Benit” may be a name, a truncated “benefit,” or a phonetic reminder; no surrounding syntax resolves it. The task sequence then shifts to mobile-device maintenance: updating ROMs, comparing phone/tablet dialers, gathering LineageOS information, inventorying gadgets, and examining app-manager activity. “ROMs” in this context most plausibly means Android firmware or custom operating-system images rather than literal semiconductor read-only memory. The combination of “Lineage Info” and “App Manager Activity” foreshadows the later pages, which inspect package manifests, shared user IDs, package-state flags, code signatures, and system applications. This is not merely a list of apps to install; it is a plan to understand the **behavioral and provenance layer beneath the Android interface**. ### Evidentiary status - **Visible evidence:** exact address, case number, times, task labels, underlining, and grouping stroke. - **Independently verified context:** [[LineageOS]] is a community Android distribution descended from CyanogenMod; ROM-update language is conventional in Android modding. - **Strong inference:** the page was written during or immediately after a support session and became a task queue for device investigation. - **Unresolved ambiguity:** “Benit,” the organization attached to the case number, and whether “3:55 / 4:00” records appointment time, call duration, or a deadline. ### Cross-notebook and corpus connections The page's ROM and LineageOS focus directly anticipates [[Scanned_20260730-1756#Page 2|Scanned_20260730-1756, page 2]], where [[UserLAnd]], [[Android 10|Android Q]], System UI, and `com.vzw.apnlib` are mapped. It also echoes the “Commands / Features / Obscure Facts / ACCESS” rubric on [[Scanned_20260730-1235#Page 1|Scanned_20260730-1235, page 1]], showing a recurring method: convert device friction into an indexed technical investigation. ### Missed Signals and Open Leads Identify the case-number issuer from corroborating email or support records; resolve “Benit”; determine which device ROMs were to be updated; and connect “App Manager Activity” to the specific inspection tools later named—[[Dev Tools (Android)|Dev Tools]], [[apps_Packages Info]], [[Chairlock]], and [[ClassyShark3xodus]]. --- ## Page 3 — `Scanned_20260730-1806.pdf`, PDF page 3 ### Visible page An otherwise blank ruled page. At the upper left, a single phrase is written in medium black script. No underline, punctuation, diagram, or continuation is visible. ### Faithful transcription > "The Dagger Authors" ### Entities and references [[Dagger Dependency Injection|Dagger]] and “The Dagger Authors.” ### Reconstruction, research, and technical meaning In isolation this could look literary, but the rest of the notebook makes a software reading much stronger. “Copyright 2012 The Dagger Authors” is the standard copyright line visible in source and license files for [[Dagger Dependency Injection|Dagger]], the Java/Android dependency-injection framework originally developed at Square and later maintained in Google's ecosystem.[^dagger] The phrase was therefore likely copied from an APK's open-source notice, decompiled source, or embedded license while tracing libraries inside an Android application. This tiny page is an important bridge: it shows that the notebook was not only cataloging package names but reading the **legal and source-provenance residue inside APKs**. A copyright-holder string such as “The Dagger Authors” can reveal a bundled dependency even when the app's user interface never mentions Dagger. ### Evidentiary status - **Visible evidence:** the exact phrase only. - **Independently verified fact:** Dagger source and license texts use “Copyright 2012 The Dagger Authors.”[^dagger] - **Strong inference:** the phrase came from an Android dependency or open-source notice rather than a book title. - **Unresolved ambiguity:** which APK or notice produced the line. ### Cross-notebook and corpus connections The page connects to the later scrutiny of `AndroidManifest.xml`, GWT metadata, JSR 305 annotations, and tracker signatures. It also belongs to the larger corpus theme of **attribution through incidental metadata**: copyright strings, developer domains, package IDs, and certificate fingerprints are treated as forensic handles. ### Missed Signals and Open Leads Locate the exact APK whose notice contained the Dagger attribution; record the Dagger version; and test whether the same APK also contained the JSR 305/GWT resource noted on page 18. The co-occurrence could identify a specific dependency graph. --- ## Page 4 — `Scanned_20260730-1806.pdf`, PDF page 4 ### Visible page A ruled page containing a small hand-drawn four-direction arrow or compass-like symbol at upper left. Near the top, “Spy” is heavily crossed and underlined. The remaining entries form a vertical list, with several items separated by space rather than bullets. A hexadecimal-looking equality appears mid-page. Handwriting becomes smaller and less certain near the bottom. ### Faithful transcription > "[hand-drawn four-direction arrow symbol]" > "[crossed out and underlined: Spy]" > "Kolibri OS" > "Symbian OS" > "Spy com" > "shadow protect system" > "require" > "[uncertain: 0.0.0 = ffffff.ff]" > "Russia T22 TimeZone" > "CGM" > "Jem files" > "Gm4" > "Netwave -" ### Entities and references [[KolibriOS]], [[Symbian|Symbian OS]], a possible `spy.com` domain or “spy” category, [[ShadowProtect]], hexadecimal notation, a possible Russian timezone code, [[CGM (Unresolved Reference)|CGM]], “Jem files,” “Gm4,” and “Netwave.” ### Reconstruction, research, and technical meaning [[KolibriOS]] is a compact x86 operating system requiring only a few megabytes of storage and very little memory; its kernel and much of its software are written in FASM assembly.[^kolibri] [[Symbian|Symbian OS]] was the dominant smartphone operating system of the pre-iPhone era and was released as open source in 2010 before its commercial decline.[^symbian] Their juxtaposition suggests a comparison of **small, non-mainstream, or legacy operating systems** rather than ordinary consumer software. “shadow protect system” almost certainly refers to [[ShadowProtect]], StorageCraft's disk-imaging, backup, and recovery product line, now under Arcserve. ShadowProtect operates at the system/volume level and historically supported bare-metal recovery and image-based restoration.[^shadowprotect] Its presence beside obscure operating systems and a hex-looking value indicates that the page may combine search results from system tools, extension lists, or a security investigation rather than a single coherent architecture. The string rendered as “0.0.0 = ffffff.ff” resembles a handwritten association between zero values and hexadecimal all-ones/all-white notation, but it is not syntactically complete enough to normalize. “Russia T22 TimeZone” may be a copied timezone or locale label, but “T22” does not map cleanly to a standard IANA timezone name. “CGM,” “Jem files,” “Gm4,” and “Netwave” are unresolved. “CGM” could mean continuous glucose monitoring in another context, but nothing on this page supports that expansion; it may instead be a software acronym or file label. ### Evidentiary status - **Visible evidence:** named operating systems, ShadowProtect phrase, crossed “Spy,” and uncertain lower-page tokens. - **Independently verified fact:** KolibriOS's small x86 design and ShadowProtect's system-backup function.[^kolibri][^shadowprotect] - **Strong inference:** this is an exploratory list of obscure systems, security terms, and copied identifiers. - **Plausible interpretation:** the compass symbol and crossed “Spy” may mark a category or rejected search term. - **Unresolved ambiguity:** `spy.com`, “T22,” CGM, Jem, Gm4, and Netwave. ### Cross-notebook and corpus connections The page's interest in alternate operating systems connects to [[Scanned_20260730-1756#Page 2|UserLAnd and Android Q]] and to the multi-platform device list in [[Scanned_20260730-1802#Page 2|Scanned_20260730-1802, page 2]]. The crossed “Spy” also anticipates the corpus's broader concern with surveillance, package provenance, and hidden system components, although this page alone does not establish spyware. ### Missed Signals and Open Leads Search the surrounding corpus for “Gm4,” “Jem,” “Netwave,” and “T22”; determine whether `spy.com` was an actual domain encountered in package metadata; and identify the source list from which KolibriOS, Symbian, ShadowProtect, and the lower tokens were copied. --- ## Page 5 — `Scanned_20260730-1806.pdf`, PDF page 5 ### Visible page A dense ruled page of paired names and file extensions. Entries are written in two loose vertical columns, though alignment is irregular. Several readings are uncertain because letters are compressed or overwritten. There is no highlighting or diagram. ### Faithful transcription > "Musepad audio" > ".psf" > "[uncertain: Bluffy Title: Audio]" > "Window Clipboard" > ".clp" > "Widow national local" > ".nls" > "[uncertain: FaxTI] images" > ".fif" > "Audio desk" > "[uncertain: Annie] Pro" > "Audio packer" > ".caf" > "TL92 Calculator" ### Entities and references `.psf`, [[Microsoft Windows Clipboard File Format|CLP]], [[Microsoft National Language Support|NLS]], `.fif`, audio software, [[Apple Core Audio Format|CAF]], and probably the [[TI-92]] calculator. ### Reconstruction, research, and technical meaning This page appears to be a **file-extension reconnaissance sheet**, but the copied labels contain several conflations. `.clp` is associated with the legacy Microsoft Windows Clipboard format, while `.nls` commonly identifies Windows National Language Support data used for locale, character-set, and code-page behavior.[^clp][^nls] `.caf` is Apple's Core Audio Format, a 64-bit audio container designed to store and transport digital audio without the size limitations of older formats.[^caf] The first line likely conflates `.psf` with “Musepack audio.” Musepack normally uses `.mpc`, while `.psf` has multiple unrelated meanings, including PlayStation Sound Format and Adobe Photoshop proof settings. Likewise “TL92 Calculator” is probably a handwritten miscopy of [[TI-92]], a Texas Instruments graphing calculator. `.fif` is highly ambiguous and has been used by different imaging and application formats; the handwritten “FaxTI images” cannot be verified as a standard pairing. The page therefore records not only formats but the **noise introduced by extension databases**, where one suffix can have multiple owners and short descriptions can be misread or stripped of context. That becomes relevant later when the notebook confronts APK internals: extensions and package labels are clues, not proof of function. ### Evidentiary status - **Visible evidence:** extension/name pairings exactly as written. - **Independently verified fact:** `.clp`, `.nls`, and `.caf` correspond to the Windows Clipboard, Windows National Language Support, and Apple Core Audio contexts described above.[^clp][^nls][^caf] - **Strong inference:** the page was copied from a file-extension reference source. - **Correction:** Musepack is normally `.mpc`, not `.psf`; “TL92” is probably TI-92. - **Unresolved ambiguity:** the intended `.psf` meaning, “Bluffy,” `.fif`, “Audio desk,” and “Annie Pro.” ### Cross-notebook and corpus connections The extension-cataloging method echoes [[Scanned_20260730-1235|Scanned_20260730-1235]], whose organizing principle is obscure commands and features. Across the corpus, the user repeatedly treats filenames and suffixes as **compressed provenance markers** capable of revealing otherwise hidden software lineage. ### Missed Signals and Open Leads Recover the original extension-reference source; distinguish PlayStation `.psf` from other PSF families; resolve `.fif`; and determine whether the page was created while inspecting a mixed directory, a forensic disk image, or an extension encyclopedia. --- ## Page 6 — `Scanned_20260730-1806.pdf`, PDF page 6 ### Visible page Another extension list, written in larger and more open script than page 5. Several terms are separated by blank lines. “Jem” is crossed out before “raster images.” The line “.Z Archived to fake” is followed by “fake archived IOS,” creating a visually linked correction or hypothesis. The final two lines pair `.mds` with playlists. ### Faithful transcription > "UTF8" > "* Omnis Studio Library" > ".lib" > ".edo files" > "ebook files?" > "java byte code" > ".efi files" > "[crossed out: Jem] raster images" > "GDI" > ".HA. compressed" > ".Z Archived to fake" > "fake archived IOS" > "Midstream .mds files" > "w/ playlists" ### Entities and references [[UTF-8]], [[Omnis Studio]], `.lib`, `.edo`, e-books, [[Java Bytecode]], [[Unified Extensible Firmware Interface|EFI]], raster images, [[Microsoft Graphics Device Interface|GDI]], `.HA`, Unix `.Z` compression, iOS, `.mds`, and playlists. ### Reconstruction, research, and technical meaning The page continues the extension survey while moving across **text encoding, development libraries, firmware, graphics, compression, disk images, and media playlists**. UTF-8 is a Unicode transformation format rather than a file extension. Omnis Studio uses libraries as application containers, making `.lib` plausible in that ecosystem, though `.lib` is also broadly used for compiled libraries on Windows and elsewhere. “java byte code” points to `.class` or JAR-contained class files, not to `.efi`; `.efi` is normally an executable image for UEFI firmware. This juxtaposition likely reflects separate copied rows whose line boundaries became ambiguous in handwriting. GDI is Microsoft's Windows Graphics Device Interface, a drawing and device-output subsystem, not itself a raster-image suffix. `.Z` conventionally denotes data compressed with the Unix `compress` utility, while `.mds` is commonly a media-descriptor sidecar for optical-disc images rather than a playlist format. “fake archived IOS” may record a suspicion that an archive was masquerading as an iOS-related file; no filename is supplied, so that cannot be verified. The page shows the researcher learning a critical forensic lesson: **suffix semantics are contingent**. A `.lib`, `.efi`, `.Z`, or `.mds` label only becomes meaningful when combined with magic bytes, directory context, originating application, and platform metadata. ### Evidentiary status - **Visible evidence:** the exact list and strike-through. - **Independently verified context:** UTF-8, Java bytecode, EFI executables, GDI, Unix `.Z`, and `.mds` are distinct technical families. - **Strong inference:** copied extension descriptions became partially interleaved during note-taking. - **Unresolved ambiguity:** `.edo`, `.HA`, “fake archived IOS,” and “Midstream” as an application or descriptor. ### Cross-notebook and corpus connections The page's interest in firmware and disguised archives anticipates the later Android APK work: APKs are ZIP-derived containers whose internal files frequently expose Java, XML, native libraries, resources, and signatures. The theme also resonates with [[Scanned_20260730-1719|Scanned_20260730-1719]], where storage, clouds, device identifiers, and cryptographic systems are mapped at infrastructure scale. ### Missed Signals and Open Leads Examine any surviving directory listing that may have produced these notes; identify `.edo` and `.HA` by file signature rather than extension; and determine whether “fake archived IOS” referred to spoofing, mislabeled backups, or an iOS firmware archive. --- ## Page 7 — `Scanned_20260730-1806.pdf`, PDF page 7 ### Visible page A short extension list on the upper half of the page. “Lotus” is crossed out before “Notes.” The bottom of the page contains “Unified Platform” as a larger concluding phrase. Some extension characters are written in a way that makes `I` and `L`, or `F` and `P`, difficult to distinguish. ### Faithful transcription > "Microsoft Paint" > "[uncertain: amit p]" > ".msp" > "[crossed out: Lotus] Notes" > ".wgl" > ".123" > ".xls" > "IDS Package file" > ".IFA" > "22 Files" > "[uncertain: 4HArch]" > ".UHA" > "Unified Platform" ### Entities and references [[Microsoft Paint]], `.msp`, [[Lotus Notes]], `.wgl`, [[Lotus 1-2-3|.123]], [[Microsoft Excel|.xls]], an IDS package, `.IFA`, `.UHA`, and “Unified Platform.” ### Reconstruction, research, and technical meaning The page mixes recognizable and uncertain extension families. `.123` is strongly associated with Lotus 1-2-3 spreadsheets, and `.xls` with legacy Microsoft Excel workbooks. The crossed “Lotus” before “Notes” may reflect a correction between **Lotus Notes** and **Lotus 1-2-3**, two distinct IBM/Lotus product lines. `.msp` can denote a Windows Installer patch package, while Microsoft Paint's native historical bitmap output is normally `.bmp`; therefore “Microsoft Paint” and `.msp` likely belong to different copied rows. `.UHA` is associated with the UHarc compressed archive format. `.wgl` and `.IFA` are ambiguous and used in multiple niche contexts. “IDS Package file” may refer to a vendor-specific package rather than the generic security acronym [[Intrusion Detection System|IDS]]. “Unified Platform” may be a source heading or a conceptual conclusion rather than another extension description. This is another page where **product-family adjacency can mislead**: Lotus Notes, Lotus 1-2-3, Excel, Microsoft Paint, installer patches, and archive formats share no single workflow unless they were encountered in a heterogeneous file corpus or reference database. ### Evidentiary status - **Visible evidence:** all labels and extensions, including the crossed “Lotus.” - **Verified normalization:** `.123` and `.xls` are spreadsheet formats; `.msp` commonly denotes a Windows Installer patch; `.UHA` is a UHarc archive. - **Strong inference:** several adjacent labels were copied from separate entries and should not be interpreted as direct equivalences. - **Unresolved ambiguity:** “amit p,” `.wgl`, IDS, `.IFA`, “22 Files,” and “4HArch.” ### Cross-notebook and corpus connections The move from isolated formats to “Unified Platform” resembles later corpus efforts to unify disparate systems under one conceptual map—cloud, device, identity, storage, and AI. At this early stage, however, unification is still being attempted through **extension taxonomies** rather than APIs or semantic knowledge graphs. ### Missed Signals and Open Leads Find the source list; determine whether `.IFA` belongs to a specific IDS/security product; resolve `.wgl`; and check whether “Unified Platform” names a product encountered elsewhere in the corpus. --- ## Page 8 — `Scanned_20260730-1806.pdf`, PDF page 8 ### Visible page A compact list with multiple extensions. The top phrase “Quantum Files” is followed by `.pak`, `.lzx`, and `.hyp`. Three Netpbm-style extensions occupy the middle. “Zsoft .pcx” is clear. The lower page contains “IA Node Graph,” “Unreal Animation .ANI,” and “Fallout 3 - Game.. (Not),” followed by a very small uncertain notation. ### Faithful transcription > "Quantum Files" > ".pak" > ".lzx" > ".hyp" > ".pbm" > ".ppm" > ".pgm" > "Zsoft .pcx" > "IA Node Graph" > "Unreal Animation .ANI" > "Fallout 3 - Game.. (Not)" > "[uncertain: BASS / BSA notation]" ### Entities and references `.pak`, [[LZX Compression|LZX]], `.hyp`, [[Netpbm|PBM/PGM/PPM]], [[PCX|ZSoft PCX]], a node graph, [[Unreal Engine]], `.ANI`, [[Fallout 3]], and probably [[Bethesda Softworks Archive|BSA]]. ### Reconstruction, research, and technical meaning `.pbm`, `.pgm`, and `.ppm` are the simple bitmap, grayscale, and pixmap members of the Netpbm family. `.pcx` is the ZSoft PC Paintbrush format.[^pcx][^netpbm] These are coherent raster-image references. The rest of the page moves into archive and game-asset territory. `.pak` is a generic package/archive suffix used by many engines and applications; `.lzx` denotes a compression family with Amiga and Microsoft lineages; `.hyp` has several unrelated uses. “Unreal Animation .ANI” is probably a mistaken association. `.ANI` is best known as a Windows animated-cursor format; Unreal Engine animation assets use engine-specific package/object formats. “Fallout 3 - Game.. (Not)” and the tiny lower notation likely mark the researcher's correction that a candidate extension was **not** the Fallout 3 game archive being sought. Bethesda games including Fallout use BSA archives, making the uncertain “BSA” reading plausible.[^bsa] “Quantum Files” and “IA Node Graph” remain unresolved. They could be product descriptions copied from an extension database. The page's real structure is a comparison between **generic package suffixes** and **application-specific asset containers**. ### Evidentiary status - **Visible evidence:** exact extension list and explicit “(Not)” correction. - **Verified fact:** PBM/PGM/PPM are Netpbm raster formats and PCX is a ZSoft format.[^pcx][^netpbm] - **Strong inference:** the lower note is an attempt to identify a Fallout/Bethesda archive and reject a false match. - **Correction:** `.ANI` is not the standard Unreal animation-asset extension. - **Unresolved ambiguity:** “Quantum Files,” `.hyp`, “IA Node Graph,” and the tiny final token. ### Cross-notebook and corpus connections This page aligns with the gaming/device inventory in [[Scanned_20260730-1650|Scanned_20260730-1650]] and [[Scanned_20260730-1802|Scanned_20260730-1802]], where PlayStation, Wii, Switch, and controller ecosystems appear. The common concern is not gaming alone but the **containers, interfaces, and hidden data structures beneath consumer platforms**. ### Missed Signals and Open Leads Confirm the final token as BSA from the original scan at higher resolution; identify “IA Node Graph”; and determine whether the extension list came from files physically recovered from a game installation or from general research. --- ## Page 9 — `Scanned_20260730-1806.pdf`, PDF page 9 ### Visible page A ruled page divided into short conceptual clusters. “Windows Registry Hive” sits at the top with `.dat` and `.hiv`. A crossed or overwritten prefix precedes “Timzeit.” “Explorer” is preceded by a crossed-out extension. The lower half centers “Mac Roman,” with an arrow toward “not a font,” then “HFS Volumes encoding” and a final uncertain phrase. ### Faithful transcription > "Windows Registry Hive" > ".dat" > ".hiv" > "[crossed out or overwritten prefix: OK] Timzeit" > "use" > ".OZV" > "[crossed out: .OZI] Explorer" > ".mip" > "Mac Roman" > "not a font" > "HFS Volumes encoding" > "relies on" > "[uncertain: Sector fail]" ### Entities and references [[Windows Registry Hive]], `.dat`, `.hiv`, “Timzeit,” `.OZV`, Explorer, `.mip`, [[MacRoman]], [[Hierarchical File System|HFS]], and a possible sector-failure note. ### Reconstruction, research, and technical meaning Windows stores registry data in hive files; `.dat` appears in well-known files such as `NTUSER.DAT`, while `.hiv` is commonly used for exported or offline hive data. A registry hive is a logical group of keys, subkeys, and values backed by files on disk.[^registry] The lower section captures a useful correction: [[MacRoman]] is a character encoding, not a font. Classic HFS used legacy script-dependent filename behavior whose case-insensitive comparison effectively assumed MacRoman; HFS Plus replaced this with Unicode filenames.[^hfs] Thus “HFS Volumes encoding” is directionally correct for classic HFS but should not be generalized to HFS Plus. The final phrase may read “Sector fail” or “Sector fault,” but HFS does not *rely* on sector failure; the line is either incomplete, copied from another source, or associated with a different preceding item. `.mip` is ambiguous and can refer to image pyramids, mapping products, or vendor-specific data. `.OZV`/`.OZI` and “Timzeit” could be software-specific extension notes; they cannot be securely identified from this page alone. ### Evidentiary status - **Visible evidence:** clear registry and MacRoman/HFS labels, plus uncertain extension cluster. - **Independently verified fact:** registry hives are file-backed structures; classic HFS's filename comparison assumed MacRoman, whereas HFS Plus uses Unicode.[^registry][^hfs] - **Strong inference:** “not a font” is the user's own correction to a source or earlier misunderstanding. - **Unresolved ambiguity:** Timzeit, `.OZV`, `.OZI`, `.mip`, and the final “Sector” phrase. ### Cross-notebook and corpus connections The page contributes to the corpus's recurring **encoding and identity** thread: a name is not merely text but is interpreted through an encoding, filesystem, registry, locale, or package manager. This concern later scales into semantic-web and continuity questions across the broader archive. ### Missed Signals and Open Leads Resolve “Timzeit” and the `.OZV/.OZI` pair; identify whether `.mip` came from a map, image, or package; and determine whether the “Sector” line belongs to HFS or was visually displaced from another entry. --- ## Page 10 — `Scanned_20260730-1806.pdf`, PDF page 10 ### Visible page A page of network, hosting, virtualization, and storage references. “Remote Services” appears at the top. “Port 31.74” and “.Vmware” are followed by “port 8080.” The middle contains two paired lines beginning with “1 and 1” and “0 and 0.” The lower section groups Western Digital's Passport and Elements names with “Russian names / software products.” ### Faithful transcription > "Remote Services" > "Port 31.74" > ".Vmware" > "port 8080" > "1 and 1 Host being used" > "0 and 0 call themselves" > "Alive system" > "- Western Digital" > "Passport/Elements" > "Russian names" > "software products" ### Entities and references Remote services, a possible TCP/UDP port `3174`, [[VMware]], port `8080`, [[IONOS|1&1]], “0 and 0,” “Alive system,” [[Western Digital]], [[WD My Passport|Passport]], [[WD Elements|Elements]], Russian naming, and software-product names. ### Reconstruction, research, and technical meaning The literal “Port 31.74” may represent `3174`, but the punctuation must be preserved because it could also be a version or copied notation. IANA assigns TCP/UDP port 3174 to `armi-server`, not to VMware.[^iana3174] VMware products use many ports, and Broadcom maintains a product-specific port matrix; port 8080 can be used by web services and some VMware-related components but is not sufficient to identify a VMware service by itself.[^vmwareports] The page therefore records an observed association, not a verified protocol mapping. “1 and 1 Host being used” probably refers to the German hosting company 1&1, now represented in the cloud/hosting market by [[IONOS]]. The adjacent “0 and 0 call themselves / Alive system” is too ambiguous to normalize; it may be a binary metaphor, a hostname, or a copied slogan. Western Digital's My Passport and Elements are external-storage product families. The final note—“Russian names / software products”—seems to initiate the list that continues on pages 11–13, where disk utilities and hardware brands are inventoried. The page marks a transition from generic file formats to **live infrastructure attribution**: ports, remote services, hosts, virtualization, and storage-device ecosystems. It is an early attempt to determine what software is listening, who owns the host layer, and which product names belong to which vendor or national development context. ### Evidentiary status - **Visible evidence:** exact port notation, VMware, 1&1, Western Digital product names, and the “Russian names” heading. - **Independently verified fact:** IANA's assignment for port 3174 is `armi-server`, while VMware's ports are product-specific and must be checked against the Broadcom matrix.[^iana3174][^vmwareports] - **Strong inference:** “1 and 1” means the hosting company 1&1/IONOS. - **Unresolved ambiguity:** whether the port is 3174, what “0 and 0” means, and what “Alive system” names. ### Cross-notebook and corpus connections This page anticipates the cloud and data-center mapping in [[Scanned_20260730-1719#Page 2|Scanned_20260730-1719, page 2]], where AMD, cloud, EPIC data center, MAC addresses, and cryptographic services are linked. It also complements the storage-controller and Microsoft Storage Spaces research in [[Scanned_20260730-1720#Page 2|Scanned_20260730-1720, page 2]]. ### Missed Signals and Open Leads Determine whether a port scanner, VMware log, router interface, or remote-service list produced the page; search device logs for 3174 and 8080; identify “Alive system”; and establish whether “0 and 0” is a hostname, product, or binary-state observation. --- ## Page 11 — `Scanned_20260730-1806.pdf`, PDF page 11 ### Visible page A software-product list occupies most of the page. “IBM SuperSmart” is at the top, and “IBM HOST” is circled beneath it. “SCT - Gold Standard” follows. The lower half is a dash-led list of product-like names, with “Software HDD.BY” written to the right of “B-Smart compatible.” “Boot Rom Management / Software” spans two lines. ### Faithful transcription > "IBM SuperSmart" > "IBM HOST" > "SCT - Gold Standard" > "Russian names" > "B-Smart compatible" > "Software HDD.BY" > "- Victoria" > "- SMYG" > "- Boot Rom Management" > " Software" > "- Sable" > "- Doomer" > "- Izyum" ### Entities and references [[IBM]], “SuperSmart,” an IBM host, SCT Gold Standard, B-Smart compatibility, `hdd.by`, [[Victoria HDD]], SMYG, boot-ROM management software, Sable, Doomer, and Izyum. ### Reconstruction, research, and technical meaning The strongest identification is `HDD.BY`, the Belarusian site associated with [[Victoria HDD]], a low-level HDD/SSD diagnostic and surface-testing utility developed by Sergey Kazansky. Version 5.37 was released on October 14, 2021, making it a useful temporal anchor for this notebook's software environment.[^victoria] “Victoria” is therefore not merely a Russian-sounding product name; it is a verified disk-diagnostic tool whose provenance explains the page's “Russian names / software products” framing. The remaining names do not resolve into a single documented platform. “IBM SuperSmart,” “SCT - Gold Standard,” and “B-Smart compatible” may be copied capability labels, SMART-diagnostic terminology, or product descriptions. `S.M.A.R.T.`—Self-Monitoring, Analysis and Reporting Technology—is a drive-health standard, and the repeated “Smart” language may orbit that domain, but the notebook does not write the acronym with periods. “SMYG,” “Sable,” “Doomer,” and “Izyum” could be utilities, code names, malware-family labels, or mistranscriptions. “Izyum” is also a Ukrainian place name, but nothing here supports a geographic interpretation. The page appears to be mapping a **regional ecosystem of disk diagnostics, firmware tools, and compatibility labels**. The circled “IBM HOST” may point backward to mainframe or host-storage terminology, but no exact IBM product named “SuperSmart” has been verified. ### Evidentiary status - **Visible evidence:** all names, the circled IBM host, and the explicit `HDD.BY` association. - **Independently verified fact:** Victoria HDD/SSD is a drive diagnostic and surface-test utility; version 5.37 dates to October 14, 2021.[^victoria] - **Strong inference:** the list was assembled while researching Eastern European or Russian-language storage utilities. - **Plausible interpretation:** “Smart” may refer to disk S.M.A.R.T. data. - **Unresolved ambiguity:** every name except Victoria/HDD.BY. ### Cross-notebook and corpus connections The page joins the corpus's extensive device-inventory and recovery thread: external drives on page 10, controller research in [[Scanned_20260730-1720]], hardware labels in [[Scanned_20260730-1230]], and repeated concern with lost or degraded storage. It is a practical precursor to the later continuity archive: **drive health is memory survival**. ### Missed Signals and Open Leads Search old download folders, browser history, and screenshots for `hdd.by`, “SuperSmart,” “SCT Gold Standard,” “SMYG,” “Sable,” “Doomer,” and “Izyum.” Determine whether these were utilities listed on the same Russian-language disk-repair page or names extracted from a firmware bundle. --- ## Page 12 — `Scanned_20260730-1806.pdf`, PDF page 12 ### Visible page The page is divided by headings “Software” and “Hardware.” Software names are written first, some with uncertain capitalization and overwritten letters. The hardware list contains familiar manufacturers mixed with unclear names. At the far right margin are small, isolated notes including “2.5” and “.450.” ### Faithful transcription > "Software" > "- Reset" > "- [scribbled prefix] Citrix Getrix?" > "- SFinXx" > "- Serg-T" > "Hardware" > "- B Smart Compatible" > " Devices" > " (need for this to" > " work)" > "- Tecton" > "- Corsair" > "- Datex" > "- Intel" > "- Kingston" > "- Lighte-On" > "- LMT" > "- DCZ (country)" > "[right margin, uncertain: vector]" > "[right margin, uncertain: wmv?]" > "2.5" > ".450" ### Entities and references Reset software, [[Citrix]], “Getrix,” SFinXx, Serg-T, B-Smart-compatible devices, Tecton, [[Corsair]], Datex, [[Intel Corporation|Intel]], [[Kingston Technology|Kingston]], probably [[Lite-On Technology|Lighte-On]], LMT, DCZ, and numeric/version notes. ### Reconstruction, research, and technical meaning The page continues page 11's compatibility research by separating **software names** from **hardware required for the software to work**. Corsair, Intel, Kingston, and likely Lite-On are recognizable component or storage-device manufacturers. Their presence supports a disk-diagnostic or firmware-tool context. “Citrix” is a major virtualization and remote-application company, but the adjacent “Getrix?” suggests either uncertainty about the name or a different utility with similar spelling. “Reset,” “SFinXx,” “Serg-T,” “Tecton,” “Datex,” “LMT,” and “DCZ” cannot be reliably mapped without the source context. “B Smart Compatible Devices (need for this to work)” may refer to a tool requiring SMART-capable drives, a specific “B-Smart” interface, or an erroneous transcription of “S.M.A.R.T.-compatible devices.” The latter is technically plausible because drive-diagnostic tools depend on SMART support, but it remains inference. The marginal “2.5” may refer to a 2.5-inch drive form factor; `.450` may be a version, capacity, or measurement. ### Evidentiary status - **Visible evidence:** explicit software/hardware division and known manufacturer names. - **Strong inference:** the page is a compatibility matrix or requirements list for a disk/firmware utility. - **Plausible interpretation:** “B Smart” is a malformed reference to S.M.A.R.T.-compatible devices; “2.5” is a drive size. - **Unresolved ambiguity:** the non-major-brand names and marginal notes. ### Cross-notebook and corpus connections The explicit separation between software and required hardware recurs throughout the corpus: device identifiers, chipsets, controllers, ROMs, system packages, and cloud services are repeatedly mapped as **interdependent layers rather than isolated products**. [[Scanned_20260730-1720]] similarly couples a Lenovo system, MMC/SD controller, McAfee driver, and Windows storage configuration. ### Missed Signals and Open Leads Resolve “SFinXx,” “Serg-T,” “Tecton,” “Datex,” “LMT,” and “DCZ” from the original source; determine whether “DCZ (country)” is a country-code note; and inspect whether `2.5` and `.450` correspond to drive dimensions or software versions. --- ## Page 13 — `Scanned_20260730-1806.pdf`, PDF page 13 ### Visible page A sparse upper-page list under an underlined “Hardware” heading. Six manufacturer or platform names are written vertically with no bullets. “SamSune” is an evident handwritten spelling rather than a silent correction. The rest of the page is blank. ### Faithful transcription > "Hardware" > "PlexTro" > "PNY" > "SamSune" > "Wonder Tool" > "Playstation Platform" > "Sandisk" ### Entities and references “PlexTro,” [[PNY Technologies|PNY]], probably [[Samsung Electronics|SamSune]], “Wonder Tool,” [[PlayStation]], and [[SanDisk]]. ### Reconstruction, research, and technical meaning PNY, Samsung, PlayStation, and SanDisk all belong to the storage, flash-memory, console, or peripheral ecosystem. “PlexTro” may be a misspelling of [[Plextor]], historically known for optical drives and later SSDs. “Wonder Tool” could be a utility name or a generic descriptor. The list therefore likely extends the page 12 hardware-compatibility matrix into removable media, flash storage, optical storage, and console platforms. The “Playstation Platform” entry is significant because page 5 includes `.psf`, which can denote PlayStation Sound Format, and page 8 explores game archives. The notebook may be cross-referencing file extensions with the hardware or platform that creates them. ### Evidentiary status - **Visible evidence:** exact list and underlined heading. - **Strong inference:** “PlexTro” means Plextor and “SamSune” means Samsung. - **Plausible interpretation:** the page extends a drive/media compatibility list. - **Unresolved ambiguity:** “Wonder Tool” and whether PlayStation is a supported diagnostic target or merely a platform category. ### Cross-notebook and corpus connections The PlayStation reference connects directly to the PSP device labels in [[Scanned_20260730-1650#Page 2|Scanned_20260730-1650, page 2]] and the broader platform-controller matrix in [[Scanned_20260730-1802#Page 2|Scanned_20260730-1802, page 2]]. ### Missed Signals and Open Leads Verify Plextor from another page or source; identify “Wonder Tool”; and determine whether the list represents devices tested, products owned, or advertised compatibility for a particular recovery application. --- ## Page 14 — `Scanned_20260730-1806.pdf`, PDF page 14 ### Visible page An otherwise blank ruled page with one large word at the upper left. No underline, arrows, qualifiers, or continuation are visible. ### Faithful transcription > "Surveillance" ### Entities and references [[Surveillance]]. ### Reconstruction, research, and technical meaning This single-word page acts as a category divider. In the pages that follow, the notebook stops cataloging generic storage and file formats and begins examining Android build identity, APK contents, package flags, permissions, trackers, system UIDs, and developer domains. “Surveillance” therefore likely names the **interpretive question** motivating the technical inspection: what installed software can observe, profile, persist, share identifiers, or operate as a privileged system component? The word does not prove that any named app was malicious or that the device was compromised. It records the researcher's concern and the analytical frame applied to ordinary and extraordinary package metadata. ### Evidentiary status - **Visible evidence:** the single heading. - **Strong inference:** section divider introducing Android package and privacy analysis. - **Important limitation:** no specific surveillance actor, capability, or incident is named on this page. ### Cross-notebook and corpus connections This heading resonates with recurrent corpus themes of counter-surveillance, identity, device control, cloud-mediated behavior, and hidden system layers. It should also be cross-indexed with the canonical rule that “RT Buddy,” when encountered elsewhere, is identified by the user as [[Pegasus Spyware|Pegasus spyware]] by [[NSO Group]]; that phrase does **not** appear in this notebook. ### Missed Signals and Open Leads Determine whether this heading separated a planned surveillance section from the preceding storage section; correlate the following package-inspection notes with any contemporaneous security incident or device concern. --- ## Page 15 — `Scanned_20260730-1806.pdf`, PDF page 15 ### Visible page A nearly blank ruled page. At the upper left, an initial word or prefix is heavily blackened. The remaining phrase “Amazing Android MODS” is legible. A short horizontal dash appears beneath it. No other content is visible. ### Faithful transcription > "[crossed out and blackened: illegible] Amazing Android MODS" > "-" ### Entities and references [[Android Modding|Android MODS]] and an unresolved preceding name or qualifier. ### Reconstruction, research, and technical meaning The phrase may be a copied title, website name, video title, forum heading, or personal category. In the notebook's sequence it signals a move toward modified Android software—custom ROMs, APKs, system tools, or privileged packages. The crossed-out initial token may have been a site or author name the user chose not to retain. “Amazing” should not be read as an evidentiary judgment. It is part of the source wording. No specific mod or package is identified on this page. ### Evidentiary status - **Visible evidence:** “Amazing Android MODS” and an intentionally obscured prefix. - **Strong inference:** a source/title heading for the Android section. - **Unresolved ambiguity:** the blackened word and whether the dash began a list that continued on page 16. ### Cross-notebook and corpus connections This page follows the “Update Roms / Lineage Info” agenda from page 2 and connects to [[Scanned_20260730-1756|Scanned_20260730-1756]], where alternate Android environments and system packages are explicitly explored. ### Missed Signals and Open Leads Recover the obscured title from browser history or screenshots; identify which Android mods were being evaluated; and determine whether the following “Virtual Machine Art” notes came from one of those modified environments. --- ## Page 16 — `Scanned_20260730-1806.pdf`, PDF page 16 ### Visible page A technical page with small marginal symbols at upper left. “Virtual Machine” heads the page. “Art” and “v.2.1.0” are highlighted in yellow. A crossed-out “Boot” precedes “Class Path,” then “boot class path” is rewritten. Several path strings are written across multiple lines, including `/apex/com.android.runtime/` and `java/lib/core-oj.jar`. A long arrow links the build string at right to the lower device description. ### Faithful transcription > "[left margin, uncertain: 60]" > "[left margin: @-like symbol]" > "Virtual Machine" > "Art" > "v.2.1.0" > "Java home: /system" > "[crossed out: Boot] Class Path" > "boot class path" > "/apex/com.android.runtime/" > "java/lib/core-oj.jar" > "Build/QPCS30.Q4-31-26-" > "1-9" > "(Linux; U; Android 10;" > "moto g stylus (2021) Build" ### Entities and references [[Virtual Machine]], [[Android Runtime|ART]], Dalvik user-agent version `2.1.0`, Java home `/system`, [[Java Class Path|boot class path]], [[Android Runtime APEX|com.android.runtime APEX]], `core-oj.jar`, build `QPCS30.Q4-31-26-1-9`, [[Linux]], [[Android 10]], and [[Moto G Stylus (2021)]]. ### Reconstruction, research, and technical meaning The notebook is now reading **runtime telemetry** from an Android system-information or developer tool. “ART” is Android Runtime, the managed execution environment that replaced the original Dalvik VM as Android's primary runtime. The string `Dalvik/2.1.0` still appears in many Android HTTP user agents even on ART-based systems; it identifies the Java-layer user agent convention, not proof that the device is running the old Dalvik runtime. `/apex/com.android.runtime/.../core-oj.jar` reflects Android's modular runtime packaging through APEX. `core-oj.jar` contains core Java/OpenJDK-derived classes used by the platform. The exact build `QPCS30.Q4-31-26-1-9` is independently associated with Motorola's `minsk` device family, including the 2021 Moto G Stylus; external records preserve the same build and a bootloader/build date suffix ending `210628`.[^phonecopy][^motorolabuild] The page's correction from “Boot Class Path” to “boot class path” suggests the user was transcribing a field label from a diagnostic app and then normalizing the phrase. The highlighted “Art v.2.1.0” may conflate ART with the Dalvik user-agent version; the later page clarifies the actual HTTP UserAgent label. ### Evidentiary status - **Visible evidence:** exact paths, device model, Android version, and build string. - **Independently verified fact:** the build belongs to the Moto G Stylus 2021 `minsk` family.[^phonecopy][^motorolabuild] - **Strong inference:** values were copied from a system-information app, likely [[Dev Tools (Android)|Dev Tools]]. - **Correction:** `Dalvik/2.1.0` is a user-agent/runtime compatibility string and should not be equated simplistically with the active ART version. ### Cross-notebook and corpus connections The Motorola `minsk` and Android Q environment directly overlaps [[Scanned_20260730-1756#Page 2|Scanned_20260730-1756, page 2]], where Android Q, System UI, and Verizon's APN library appear. Together the notebooks identify a specific device investigation rather than an abstract Android study. ### Missed Signals and Open Leads Identify the exact app screen that displayed Java home and boot class path; preserve the complete user-agent string; and correlate the device build with carrier, SKU, security-patch level, and installed ROM state. --- ## Page 17 — `Scanned_20260730-1806.pdf`, PDF page 17 ### Visible page A dense continuation page headed by an underlined “Moto.” “DevTools Sys Info” appears beneath it. `MINSK_NA_CUST` and “Http UserAgent: Dalvik/2.1.0” are highlighted yellow. The build fingerprint is split across lines. A small “Plus 5:54” with a downward arrow appears in the right margin. ### Faithful transcription > "Moto" > "DevTools Sys Info" > "Android 10/Q/Api29" > "MINSK_NA_CUST" > "Build=" > "QPCS30.Q4-31-26-1-9" > "Build Fingerprint:" > "motorola/minsk_retail" > "minsk:10/" > "QPCS30.Q4-31-21-1-9:/" > "bb626:user/release-keys" > "Plus 5:54" > "Linux Kernel Version:" > "4.14.117-perf+" > "Http UserAgent: Dalvik/2.1.0 ->" ### Entities and references [[Motorola Mobility|Motorola]], [[Dev Tools (Android)|DevTools]], [[Android 10]], Android Q, [[Android API Level 29|API 29]], `MINSK_NA_CUST`, build and fingerprint strings, `user/release-keys`, Linux kernel `4.14.117-perf+`, and the Dalvik HTTP user agent. ### Reconstruction, research, and technical meaning This page is the notebook's strongest device-identification record. `minsk_retail/minsk`, Android 10, `QPCS30.Q4-31-26-1-9`, and `bb626:user/release-keys` form a Motorola production build fingerprint. The notebook appears to contain one copying discrepancy—`31-21` inside the split fingerprint versus `31-26` in the build field and external records. The exact external fingerprint is `motorola/minsk_retail/minsk:10/QPCS30.Q4-31-26-1-9/bb626:user/release-keys`.[^motorolabuild] This correction should not replace the quoted notebook text. `user/release-keys` indicates a production-signed user build rather than an engineering `eng` or `userdebug` build. `MINSK_NA_CUST` appears to be the North American customization/build channel. Kernel `4.14.117-perf+` fits the Qualcomm-based Android 10 device generation. “Plus 5:54” may record the time, a battery state, or a continuation cue and remains unresolved. The page confirms that the research was **hands-on and device-specific**. The user was not simply reading Android documentation; they were extracting the exact build identity needed to compare firmware, inspect system apps, and evaluate whether an observed package belonged to stock Motorola/carrier software or a modification. ### Evidentiary status - **Visible evidence:** complete build, model family, API level, kernel, and partial fingerprint. - **Independently verified fact:** external firmware records match the `31-26-1-9` `minsk_retail` fingerprint.[^motorolabuild] - **Strong inference:** copied from Trinea's Dev Tools system-information screen. - **Correction:** the handwritten `31-21` is likely a transcription error. - **Unresolved ambiguity:** “Plus 5:54.” ### Cross-notebook and corpus connections This device fingerprint should be added to the cumulative [[Index - Device Inventory|Device Inventory]]. It is the same technical neighborhood as the `com.vzw.apnlib` entry in [[Scanned_20260730-1756#Page 2|Scanned_20260730-1756, page 2]] and the package IDs on page 26 here. The combination strongly suggests investigation of an unlocked or retail Motorola handset carrying carrier-related packages. ### Missed Signals and Open Leads Recover the security-patch date, baseband, bootloader status, carrier channel, and serial-neutral hardware SKU; compare all stock package hashes against the matching Motorola firmware image; and determine whether the device had been updated beyond this Android 10 build when the notebook was written. --- ## Page 18 — `Scanned_20260730-1806.pdf`, PDF page 18 ### Visible page A highly technical page with yellow highlighting on `Jsr305`, `jsr305_annotations`, “Gwt,” “jsr,” and an APK filename. A large left bracket groups an XML comment copied over several lines. One word before “autogenerated” is blackened; “the” is crossed out before “target.” An arrow points from `//` toward “HTTP/HTTPS url.” The bottom names an APK and the number 8833. ### Faithful transcription > "Some \"apk\" seem to contain" > "with Jsr305_annotations.gwt.xml" > "<!-- Gwt module description or," > "[blackened: illegible] autogenerated for [crossed out: the] target" > "//third_party/java/jsr305_" > "annotations: jsr305_annotations -->" > ".<module>. </module>." > "What is Gwt and jsr ?" > "// <- appears to be HTTP/HTTPS url" > "Found inside SuperSUF1.012.apk" > "on 8833" ### Entities and references [[Android Package|APK]], `Jsr305_annotations.gwt.xml`, [[Google Web Toolkit|GWT]], [[Java Specification Request|JSR]], [[JSR 305]], XML comments and module tags, a source-tree path, HTTP/HTTPS URLs, and an uncertain `SuperSUF1.012.apk` filename. ### Reconstruction, research, and technical meaning The file name `Jsr305_annotations.gwt.xml` is a GWT module descriptor bundled with the JSR 305 annotations library. GWT modules use `.gwt.xml` configuration files to describe inherited modules, source paths, public resources, and compilation behavior.[^gwt] JSR 305 was a Java Specification Request for annotations such as nullness metadata to support defect-detection tools; the JCP lists it as dormant since 2012.[^jsr305] The copied XML comment points to a third-party Java dependency path. Its presence inside an APK does **not** mean the app actively uses a remote GWT web application, and `//third_party/...` is not an HTTP or HTTPS URL. In source trees, `//` often denotes a repository-root-relative path, particularly in build systems such as Bazel. The resource may have entered the APK transitively through a Java library and remained as harmless packaging residue. Similar `jsr305_annotations` directories have been observed in APKs because libraries are packaged into the final archive even when their metadata is not user-facing.[^jsr305apk] The APK filename is uncertain; it visually resembles `SuperSUF1.012.apk`, possibly a renamed SuperSU-related package. “on 8833” could be a device, directory, build, or count. No conclusion about malware or remote communication follows from this page. ### Evidentiary status - **Visible evidence:** exact resource name, XML fragment, questions, and uncertain APK filename. - **Independently verified fact:** `.gwt.xml` files configure GWT modules; JSR 305 defines defect-detection annotations and is dormant.[^gwt][^jsr305] - **Strong inference:** the file was found during APK extraction or decompilation. - **Correction:** `//third_party/...` is a source/build path, not an HTTP/HTTPS URL. - **Unresolved ambiguity:** exact APK filename and meaning of “8833.” ### Cross-notebook and corpus connections This page makes the page 3 phrase “The Dagger Authors” more intelligible: both are likely dependency-provenance artifacts recovered from APK internals. It also anticipates page 24's inspection of `AndroidManifest.xml` and declared activities. The recurring pattern is **reading what an application carries, not merely what it displays**. ### Missed Signals and Open Leads Preserve the original APK and compute its hash without executing it; list all embedded libraries, certificates, and resources; identify the exact dependency version that supplied `Jsr305_annotations.gwt.xml`; and determine whether Dagger, JSR 305, and GWT metadata co-occur in the same package. --- ## Page 19 — `Scanned_20260730-1806.pdf`, PDF page 19 ### Visible page A sparse research page with the app version at top, an arrow from “on github Real name” toward a yellow-highlighted title, and developer/source references below. The title “Android-Dev-Tools” is highlighted. The lower-right question asks what else the developer makes. ### Faithful transcription > "DevTools 6.3.8-gp" > "on github Real name" > "Android-Dev-Tools" > "Made by Trinea" > "github.com/trinea" > "https://codekk.com" > "What else do they" > "make?" ### Entities and references [[Dev Tools (Android)|DevTools 6.3.8-gp]], [[Dev Tools (Android)|Android-Dev-Tools]], [[Trinea]], [[GitHub]], and [[codeKK]]. ### Reconstruction, research, and technical meaning This page identifies the diagnostic app that generated much of pages 16–17. Dev Tools 6.3.8-gp was distributed under Trinea's name as an Android developer assistant capable of showing device and app information, activity history, manifests, decompilation views, APK extraction, and developer-option shortcuts.[^devtools][^codekk] The notebook is performing **developer provenance resolution**: moving from a Play Store-facing name (“DevTools”) to the repository or project identity (“Android-Dev-Tools”), the developer handle (`Trinea`), and the related open-source index (`codeKK`). The question “What else do they make?” is analytically important. It shows the user was not satisfied with identifying one app; they wanted the surrounding developer ecosystem, reusable libraries, affiliated sites, and possible relationships among tools. Trinea is associated with Android common libraries and the codeKK open-source indexing community, so the page begins a **relationship map rather than a single-app lookup**. ### Evidentiary status - **Visible evidence:** exact version, project title, handle, repository path, and domain. - **Independently verified fact:** the 6.3.8-gp release exists and the app is described as an Android development assistant; codeKK records Trinea-associated Android projects.[^devtools][^codekk] - **Strong inference:** the user was verifying the app's real developer identity and related output. - **Unresolved ambiguity:** whether “Real name” asks for Trinea's personal identity or the repository's formal project name. ### Cross-notebook and corpus connections The provenance method recurs on page 27, where developer domains are extracted from package metadata, and throughout the NOTEBOOKS project in the repeated pursuit of **ownership, lineage, and hidden institutional relationships**. ### Missed Signals and Open Leads Archive the exact 6.3.8-gp APK and source snapshot; identify Trinea's release-signing key; enumerate related repositories and libraries; and determine whether codeKK supplied any of the extension or package descriptions copied elsewhere in the notebook. --- ## Page 20 — `Scanned_20260730-1806.pdf`, PDF page 20 ### Visible page A page divided between a vertical browser list and a long URI. Four browser names appear at upper left. A Twitter version follows. The content URI is written across three lines, ending with `legal.htm`. No arrows are present, but the layout suggests the browsers were options presented for opening the URI or document. ### Faithful transcription > "FOSS Browser" > "Lightning" > "Privacy Browser" > "Tor" > "v.9.18.0-release.00" > "com." > "content://com.twitter.android." > "internal/fileprovider/cache/" > "legal.htm" ### Entities and references [[FOSS Browser]], [[Lightning Browser]], [[Privacy Browser Android|Privacy Browser]], [[Tor Browser]], [[Twitter for Android]] version `9.18.0-release.00`, Android package authority `com.twitter.android.internal`, [[Android Content URI|content URI]], [[Android FileProvider|FileProvider]], cache storage, and `legal.htm`. ### Reconstruction, research, and technical meaning The page almost certainly records an Android **“open with” or intent-resolver event**. FOSS Browser, Lightning, Privacy Browser, and Tor were installed browser candidates. Lightning is a lightweight open-source Android browser; Privacy Browser is designed to minimize data sent to the internet and retained on-device.[^lightning][^privacybrowser] Their coexistence indicates active comparison of privacy-oriented browsing environments rather than default-browser use. `content://com.twitter.android.internal/fileprovider/cache/legal.htm` is not a public web URL. It is an Android content URI whose authority resolves to Twitter's internal FileProvider. FileProvider is specifically designed to share files securely between apps by issuing `content://` URIs and temporary permissions rather than exposing raw filesystem paths.[^fileprovider][^contenturi] The path suggests Twitter cached a local legal-information HTML file and invoked another app to display it. Twitter version `9.18.0-release.00` was released on November 2, 2021, establishing a firm **terminus post quem** for this page and probably for the notebook's Android section.[^twitter918] The page documents ordinary Android inter-process file sharing, not by itself an exfiltration channel or remote endpoint. ### Evidentiary status - **Visible evidence:** exact browsers, version, package authority, and content URI. - **Independently verified fact:** Twitter 9.18.0 dates to November 2, 2021; FileProvider uses content URIs for controlled inter-app file sharing.[^twitter918][^fileprovider] - **Strong inference:** the browser names were choices for opening Twitter's local `legal.htm` file. - **Correction:** the URI is local/provider-mediated, not an HTTP/HTTPS address. ### Cross-notebook and corpus connections The page connects privacy-oriented browsers to the “Surveillance” divider on page 14. It also advances the corpus's concern with **interfaces that look like networks but are actually local namespaces**—a distinction equally important in cloud, filesystem, and semantic-web investigations. ### Missed Signals and Open Leads Recover the `legal.htm` content and metadata; determine which action launched the chooser; compare Twitter's FileProvider declaration in the exact APK manifest; and identify whether the four browsers were installed through F-Droid or another repository. --- ## Page 21 — `Scanned_20260730-1806.pdf`, PDF page 21 ### Visible page A sparse page with an upper note about “Fire Kindle” and settings permissions. The permission word after the colon is difficult to read. The main question “What is a ‘Magic Window’?” occupies the center, followed by “some app?” The word “appbrain” appears alone near the bottom. ### Faithful transcription > "on Fire Kindle/" > "on settings perm: [illegible]" > "What is a \"Magic Window\" ?" > "some app?" > "appbrain" ### Entities and references [[Amazon Fire Tablet|Fire/Kindle]], Android settings permissions, [[Magic Window (Android)|Magic Window]], and [[AppBrain]]. ### Reconstruction, research, and technical meaning This page appears to record a package label or permission encountered on an Amazon Fire/Kindle device and then searched through AppBrain, an Android app-discovery and market-intelligence service. “Magic Window” could be an app title, system feature, vendor overlay, live wallpaper, window-management component, or translated label. The page provides no package ID, so identification by display name alone would be unreliable. The researcher's question is methodologically sound: visible app labels are frequently non-unique, localized, or detached from the canonical Android package name. The correct next step would be to capture the package ID, signing certificate, installation path, version, installer source, and manifest—not simply search the label. ### Evidentiary status - **Visible evidence:** Fire/Kindle context, “Magic Window,” and AppBrain. - **Strong inference:** AppBrain was used to identify an unfamiliar package or feature. - **Unresolved ambiguity:** the unreadable permission and every technical detail of “Magic Window.” ### Cross-notebook and corpus connections The page's package-label ambiguity is precisely what pages 23–27 attempt to solve with manifest viewers, package IDs, system flags, and developer domains. It also connects to the broader device inventory, in which Amazon, Android, Apple, Sony, and Nintendo platforms are treated as different surfaces over related package and identity problems. ### Missed Signals and Open Leads Find the package ID for “Magic Window”; inspect Amazon Fire system-package lists from the relevant firmware; resolve the permission word; and locate the AppBrain search or screenshot that generated the note. --- ## Page 22 — `Scanned_20260730-1806.pdf`, PDF page 22 ### Visible page A legend-like page translating colors and symbols into package states. Each line begins with a color name or a symbol. “blue” is overwritten before “Stopped.” The phrase that resolves as `usesCleartextTraffic` is split and partly crossed. Symbols at the bottom include an X-like mark, a barred-circle or lollipop-like mark, a dot, and a tilde. ### Faithful transcription > "red: noAllowClear UserData" > "magenta: Persistant" > "[crossed out or overwritten color word: blue]: Stopped" > "orange Data: READ_LOGS" > "orange UID: shared" > "green I Inactive" > "(+ Oreo) orange SDK: usesClear" > "[crossed out or overwritten: text]Traffic" > "[uncertain symbol/number: 2], resourceOverlay" > "X: Multiarch" > "[barred-circle symbol]: no HasCode" > ".: Suspended" > "~: TestOnly" ### Entities and references [[Android ApplicationInfo]], `allowClearUserData`, persistent apps, stopped apps, `READ_LOGS`, shared UID, inactive apps, Android Oreo, SDK/target behavior, `usesCleartextTraffic`, resource overlays, multiarch, `hasCode`, suspended apps, and `testOnly`. ### Reconstruction, research, and technical meaning This page is a handwritten **legend for the visual encoding used by `apps_Packages Info` or a closely related oF2pks tool**. The F-Droid description explicitly lists color-coded states including persistent, stopped, inactive, suspended, shared UID, READ_LOGS, SDK sorting, overlays, test/debug flavors, and other `ApplicationInfo` features.[^applicationsinfo] The close correspondence is too specific to be coincidental. The flags are Android package metadata, not verdicts of maliciousness. `allowClearUserData` concerns whether application data can be cleared; persistent identifies apps the system may keep running; stopped marks packages placed in the stopped state; shared UID indicates packages configured to share a Linux UID; inactive and suspended are package-usage/administrative states. `usesCleartextTraffic` is a manifest attribute controlling whether an app intends to use unencrypted network traffic, subject to platform and network-security configuration.[^applicationelement] Resource overlays substitute resources without replacing base code; multiarch indicates support for more than one native ABI; `hasCode=false` marks resource-only packages or overlays; `testOnly` identifies packages intended for testing. The notebook is decoding the tool's interface so that color and icon signals can be translated back into **formal Android package-state semantics**. This is a decisive shift from browsing app labels to reading platform ontology. ### Evidentiary status - **Visible evidence:** full color/symbol legend and copied attribute names. - **Independently verified fact:** the listed states match the published feature set of `apps_Packages Info`; Android documents relevant manifest and package attributes.[^applicationsinfo][^applicationelement] - **Strong inference:** this page was copied directly from the app's UI or documentation. - **Correction:** “Persistant” is preserved but normalized analytically as “persistent”; “usesClear / Traffic” is `usesCleartextTraffic`. - **Unresolved ambiguity:** the exact color preceding “Stopped” and the symbol used for `resourceOverlay`. ### Cross-notebook and corpus connections This legend supplies the decoding key for pages 25–26 and likely for package observations in [[Scanned_20260730-1756]]. It should be linked into the cumulative [[Android Package State Legend]] because later notebooks may use the same colors without re-explaining them. ### Missed Signals and Open Leads Capture screenshots from the exact app version to map every color and icon conclusively; distinguish static from dynamic overlays; and record which packages on the Motorola device triggered each state. --- ## Page 23 — `Scanned_20260730-1806.pdf`, PDF page 23 ### Visible page A page of interaction instructions and source provenance. `#LongClick` appears at top beside a small flower/command-like symbol. “dynamic manifest” follows. A phrase resembling `fdroid-applications-info` and an uncertain “prim-origin” line lead to a Bitbucket URL split across multiple lines. The lower half records a two-click permission action, “Tag Info,” and the kDI package ID. ### Faithful transcription > "#LongClick" > "[flower or command-like symbol]" > "dynamic manifest" > "fdroid-applications-info" > "[uncertain: priv-origin]" > "https://bitbucket.org/" > "oF2pks/MajeurAndroid/" > "Applications-Info" > "Two Clicks On User Permissions" > "=" > "Tag Info" > "(F-Droid) kDI/" > "com.oF2pks.kalturadeviceinfos" ### Entities and references Long-click UI action, dynamic Android manifest, [[F-Droid]], [[apps_Packages Info|Applications Info]], [[Bitbucket]], `oF2pks`, [[MajeurAndroid Android Applications Info]], user permissions, tag information, [[kDI Device Info]], and package `com.oF2pks.kalturadeviceinfos`. ### Reconstruction, research, and technical meaning This page is an operational instruction sheet for the oF2pks application-inspection family. `apps_Packages Info` exposes a dynamic manifest on long press and permission information through additional taps; the F-Droid listing explicitly traces its “prim-origin” to MajeurAndroid's Android-Applications-Info project.[^applicationsinfo] [[Chairlock]] embeds package information into a permissions explorer and documents long-press/tap interactions, while kDI uses the package ID written here.[^chairlock][^kdi] “Dynamic manifest” likely means a runtime-generated or PackageManager-derived view of manifest information, distinct from the static `AndroidManifest.xml` stored inside the APK. That distinction matters: overlays, enabled states, granted permissions, and package-manager changes can alter runtime visibility without rewriting the archive. The page also demonstrates an emerging **tool lineage map**: MajeurAndroid → oF2pks forks/extensions → F-Droid distributions → kDI/Chairlock/ClassyShark integrations. The user's interest is not only what the app reports, but where the reporting code originated. ### Evidentiary status - **Visible evidence:** interaction labels, Bitbucket lineage, and exact package ID. - **Independently verified fact:** F-Droid documentation confirms the long-click/dynamic-manifest behavior, MajeurAndroid origin, and kDI package identity.[^applicationsinfo][^kdi] - **Strong inference:** “priv-origin” is a handwritten `prim-origin` copied from the F-Droid description. - **Unresolved ambiguity:** the precise meaning of the top symbol and “Tag Info.” ### Cross-notebook and corpus connections This page extends the project-wide concern with **genealogy of tools**: predecessor, fork, rebrand, and embedded component. It is the software equivalent of the device and corporate lineages mapped in other notebooks. ### Missed Signals and Open Leads Archive the Bitbucket repository and its commit history; compare static versus dynamic manifest output on the same package; identify the exact app version whose gesture instructions were copied; and determine whether “Tag Info” is an app screen, XML-tag viewer, or permission tag. --- ## Page 24 — `Scanned_20260730-1806.pdf`, PDF page 24 ### Visible page A page headed “ClassyShark3xodus 2.” The package/repository path is written over three lines. `AndroidManifest.xml` appears clearly in the lower half, with an arrow pointing to “declared activities.” A large curved arrow from an uncertain phrase near the bottom-left points upward toward the manifest area. ### Faithful transcription > "ClassyShark3xodus 2" > "com.oF2pks." > "classyshark3xodus/com.google." > "classysharkandroid" > "AndroidManifest.xml" > "declared activities" > "[uncertain: Selling Storage]" ### Entities and references [[ClassyShark3xodus]], `com.oF2pks.classyshark3xodus`, [[Google ClassyShark|com.google.classysharkandroid]], [[AndroidManifest.xml]], Android activities, and an uncertain “Selling Storage” phrase. ### Reconstruction, research, and technical meaning ClassyShark3xodus is an oF2pks extension of Google's ClassyShark APK-analysis tool. It checks APK code signatures against Exodus Privacy's tracker definitions, lists classes, displays static and dynamic manifests, and exposes certificate and fingerprint information.[^classyshark] The handwritten package lineage—`com.oF2pks.classyshark3xodus` alongside `com.google.classysharkandroid`—captures the fork's ancestry directly. `AndroidManifest.xml` is the canonical package declaration file. It names components such as activities, services, broadcast receivers, providers, permissions, features, and compatibility constraints.[^manifest] “declared activities” indicates the user was drilling into one component class to understand what screens or entry points an app registered, including activities not exposed by the normal launcher. The uncertain lower phrase could be “Setting Storage,” “Selling Storage,” or another label. It may point to an activity name or package category, but the scan does not support a firm reading. ### Evidentiary status - **Visible evidence:** tool name, package lineage, manifest, and activity focus. - **Independently verified fact:** ClassyShark3xodus is based on Google's ClassyShark and scans for known tracker signatures while exposing classes and manifests.[^classyshark] - **Strong inference:** the page records a decompilation/inspection workflow rather than app usage. - **Unresolved ambiguity:** the final curved-arrow phrase and which APK's activities were being inspected. ### Cross-notebook and corpus connections This page is the practical realization of the page 2 task “App Manager Activity.” It also links to page 3's Dagger attribution and page 18's embedded JSR/GWT resource: all three derive identity from **static package contents invisible at the interface level**. ### Missed Signals and Open Leads Identify the inspected APK; export its full manifest and declared component list; compare ClassyShark tracker results against Exodus's versioned database; and preserve the signing-certificate hashes. --- ## Page 25 — `Scanned_20260730-1806.pdf`, PDF page 25 ### Visible page A symbol-mapping page. “System” sits at top, followed by a blackened or crossed token before “User#.” The central area lists variants of “User,” “System#,” “System0,” “System²0,” and “SystemX0.” The lower area adds “System (magenta),” “SystemX,” and “System².” Superscripts and final symbols are visually ambiguous. ### Faithful transcription > "System" > "[crossed out or blackened: illegible] User#" > "User" > "System#" > "System0" > "System²0" > "SystemX0" > "System (magenta)" > "SystemX" > "System²" ### Entities and references Android system apps, user apps, icon/symbol variants, color coding, and package classification. ### Reconstruction, research, and technical meaning This page likely decodes **system/user app REDACTED** in the same package-information interface documented on page 22. The hash, circle/zero, superscript-like mark, X, and magenta color probably distinguish system application, updated system application, disabled state, shared identity, overlay, or related status combinations. Because the exact UI legend has not been recovered, the marks should not be assigned fixed meanings yet. The important conceptual distinction is between an app installed in `/data` as a user application and a package provisioned in `/system`, `/product`, or `/vendor`. Updated system apps can have a factory copy in a read-only partition and a newer copy in `/data`, creating mixed classifications. Resource overlays and code-less packages further complicate a binary “system versus user” model. ### Evidentiary status - **Visible evidence:** repeated system/user labels and symbol combinations. - **Strong inference:** a handwritten icon/color legend from `apps_Packages Info`, Chairlock, or ClassyShark3xodus. - **Unresolved ambiguity:** exact semantic mapping of every symbol. ### Cross-notebook and corpus connections This page should be interpreted with page 22 and page 26, not independently. Together they form a local ontology of Android package privilege, persistence, code presence, shared identity, and provenance. That ontology is directly relevant to the system-package observations in [[Scanned_20260730-1756]]. ### Missed Signals and Open Leads Recover screenshots from the exact tool version; map each symbol to source-code constants; and create a canonical [[Android Package State Legend]] note that distinguishes system, updated-system, overlay, disabled, suspended, and user packages. --- ## Page 26 — `Scanned_20260730-1806.pdf`, PDF page 26 ### Visible page A page divided by two horizontal separators. The top contains shared-user and core-app properties. The middle contains a crossed/underlined “android Intelligence” phrase and a version/source line. The bottom lists three Android package/application references, including exact package IDs. ### Faithful transcription > "shared user id" > "android.uid.system" > "coreApp=True" > "[crossed out and underlined: android Intelligence]" > "5.8. playstore. pixel4.t" > "[uncertain: permission automaticia]" > "AndSys ~ Apps" > "net.sourceforge.andsys" > "com.vzw.apnlib" > "Apollo com.andrew.apollo" ### Entities and references [[Android sharedUserId|shared user ID]], `android.uid.system`, `coreApp=True`, an “Android Intelligence” app or label, version `5.8`, Play Store, Pixel 4, permissions, [[AndSys]], package `net.sourceforge.andsys`, [[Verizon APN Library|com.vzw.apnlib]], and [[Apollo Music Player|com.andrew.apollo]]. ### Reconstruction, research, and technical meaning `android.uid.system` is a highly privileged shared UID historically used by platform-signed system components. Android deprecated manifest `sharedUserId` beginning with API level 29 because it creates nondeterministic package-manager behavior and tightly couples packages through a shared Linux identity.[^shareduserid] `coreApp=True` is an internal/platform flag associated with core packages required early in boot or package management. These properties can indicate privileged system integration, but they do not independently prove maliciousness; signature lineage and firmware provenance are decisive. “AndSys ~ Apps,” package `net.sourceforge.andsys`, is an older open-source package-information tool described as a beta “Package Information Tool.”[^andsys] `com.vzw.apnlib` is Verizon's APN library package and appears as a preinstalled system component on some devices, including non-Verizon or unlocked configurations where carrier bundles are retained.[^apnlib] `com.andrew.apollo` is the package for Apollo, the music player bundled with CyanogenMod 10-era ROMs.[^apollo] The crossed “android Intelligence” and “5.8. playstore. pixel4.t” may refer to Android System Intelligence or another Pixel-specific package, but the wording is incomplete. The page is effectively comparing **privileged stock packages, legacy inspection tools, carrier libraries, and ROM-era user applications** on one package-information surface. ### Evidentiary status - **Visible evidence:** exact shared UID, core-app property, and package IDs. - **Independently verified fact:** shared user IDs are deprecated at API 29; AndSys is a package-information tool; `com.vzw.apnlib` is a Verizon APN package; Apollo belongs to the CyanogenMod music-player lineage.[^shareduserid][^andsys][^apnlib][^apollo] - **Strong inference:** the page records package-detail views from the Motorola/Android environment. - **Unresolved ambiguity:** “android Intelligence,” version 5.8, Pixel 4 notation, and “permission automaticia.” ### Cross-notebook and corpus connections `com.vzw.apnlib` is a direct recurrence from [[Scanned_20260730-1756#Page 2|Scanned_20260730-1756, page 2]]. Apollo connects back to the page 2 “Lineage Info” task because Apollo was bundled with CyanogenMod, LineageOS's predecessor. This creates a concrete lineage chain: [[CyanogenMod]] → [[LineageOS]] and Apollo-era ROM software → later package inspection. ### Missed Signals and Open Leads Determine which package displayed `android.uid.system` and `coreApp=True`; verify its platform signing certificate against stock firmware; identify the exact “Android Intelligence” package; and document why Verizon's APN library was present on the device's retail firmware. --- ## Page 27 — `Scanned_20260730-1806.pdf`, PDF page 27 ### Visible page The final page contains a loose list of F-Droid/device-information terms and domains. “Chairlock =” is followed by `=1023`, a magnifying-glass-like search symbol, and “search.” “System #Decode” appears below. “nathan.org” is underlined. Four domains occupy the bottom half. ### Faithful transcription > "Fdroid android.codes" > "DeviceInfo" > "[uncertain: Long prism]" > "packages Info" > "Chairlock =" > "=1023 [magnifying-glass-like symbol] search" > "System #Decode" > "nathan.org" > "swisscodemonkeys." > "appspot.com" > "bombusmod.org" > "bytehamster.com" ### Entities and references [[F-Droid]], `android.codes`, device information, package information, [[Chairlock]], numeric value `1023`, search/decode functions, `nathan.org`, [[Swiss Codemonkeys|swisscodemonkeys.appspot.com]], `bombusmod.org`, and [[ByteHamster|bytehamster.com]]. ### Reconstruction, research, and technical meaning This is a **provenance and developer-domain residue page**. Chairlock is an F-Droid permissions explorer that embeds `apps_Packages Info` and can launch ClassyShark3xodus scans.[^chairlock] `DeviceInfo` likely points to kDI, whose F-Droid description emphasizes device characteristics, Widevine, Treble, A/B partitions, media decoders, and package information.[^kdi] The domains probably came from installed-app metadata, developer websites, or market listings rather than from a single organization. `swisscodemonkeys.appspot.com` was associated with Swiss Codemonkeys/AppTornado, the company behind AppBrain and various early Android apps.[^swisscodemonkeys] `bytehamster.com` is associated with an Android developer identity that appears in F-Droid/open-source contexts. `bombusmod.org` likely refers to the BombusMod messaging project or its developer provenance. `nathan.org` and `android.codes` are too broad to assign without a package ID. The notebook correctly treats domains as clues but has not yet completed the entity-resolution step. “=1023” may be a UID, permission count, result count, or numeric code displayed by Chairlock. On Unix-like systems 1023 is the last traditionally privileged port number, but nothing here proves that interpretation. “System #Decode” may mean decoding a system-package REDACTED or a source/category hash. The notebook ends not with a conclusion but with a list of unresolved origins—appropriate for an investigation whose endpoint is a **distributed graph of package names, forks, domains, signatures, and system privileges**. ### Evidentiary status - **Visible evidence:** exact tool/domain list and numeric note. - **Independently verified fact:** Chairlock and kDI have the functions described; Swiss Codemonkeys/AppTornado is connected to AppBrain.[^chairlock][^kdi][^swisscodemonkeys] - **Strong inference:** domains were harvested from app metadata or inspection results. - **Important limitation:** adjacency does not establish affiliation among all listed domains. - **Unresolved ambiguity:** `android.codes`, “Long prism,” `1023`, `nathan.org`, and “System #Decode.” ### Cross-notebook and corpus connections This page completes the movement begun on page 19 from app name to developer identity, repository, domain, and lineage. It also links directly to the package-oriented research in [[Scanned_20260730-1756]] and the larger corpus practice of **turning incidental identifiers into a knowledge graph**. ### Missed Signals and Open Leads Map each domain to the exact package that exposed it; preserve signing certificates and installer sources; resolve `android.codes` and `nathan.org`; identify “Long prism”; and determine what value `1023` represented in Chairlock or the package-information UI. --- # Notebook-level synthesis ## Probable date range ### Explicit and externally anchored dates The PDF scan itself was created on **July 30, 2026**, but that is only the digitization date. The handwritten software environment is much earlier. Twitter for Android `9.18.0-release.00`, copied on page 20, was released **November 2, 2021**.[^twitter918] The Motorola build on pages 16–17 carries a `210628` lineage marker and is independently recorded for the 2021 Moto G Stylus `minsk` family.[^phonecopy][^motorolabuild] Victoria HDD/SSD 5.37, named on page 11, was released **October 14, 2021**.[^victoria] The exact `apps_Packages Info` features documented on pages 22–23 appear in F-Droid versions added in **January–March 2022**, while ClassyShark3xodus 2.0-32 and kDI 2.12-24 were added in **May 2022**.[^applicationsinfo][^classyshark][^kdi] ### Best-supported notebook interval The strongest reconstruction places the active Android-inspection portion between **November 2021 and May 2022**, probably in early or mid-2022. Some copied concepts—Symbian, HFS, Lotus formats, GDI, old compression formats, Apollo, and AndSys—are much older, but they are objects of research rather than reliable composition dates. The notebook may have been assembled episodically, with the extension and disk-utility pages preceding the focused Motorola/Android work. ## Executive reconstruction `Scanned_20260730-1806` records a transition from **file-type and systems archaeology** into **mobile package forensics**. The opening task list identifies ROM updates, LineageOS, dialers, gadgets, and app-manager activity. The next pages inventory compact operating systems, backup software, file extensions, legacy application formats, archive containers, registry hives, encodings, remote-service ports, external drives, disk-diagnostic tools, and hardware compatibility. This material appears to have been gathered while trying to interpret heterogeneous files or utilities whose names were unfamiliar, regionally sourced, or poorly documented. The notebook then declares “Surveillance” and turns to a particular Moto G Stylus (2021). The user copies the Android runtime path, build number, fingerprint, kernel, API level, and Dalvik user-agent string; identifies Trinea's Dev Tools and its GitHub/codeKK lineage; inspects an APK containing JSR 305/GWT metadata; records privacy browsers and a Twitter FileProvider content URI; and learns the state/color/icon vocabulary of `apps_Packages Info`. The final pages map oF2pks tools, F-Droid, Chairlock, kDI, ClassyShark3xodus, Google ClassyShark, static and dynamic manifests, declared activities, shared UIDs, `android.uid.system`, `coreApp=True`, carrier libraries, CyanogenMod-era Apollo, developer domains, and package provenance. The notebook's governing question is not “Which app should I use?” but **“What is this component, where did it come from, what privileges does it hold, what else is bundled inside it, and which larger lineage does it belong to?”** It is an early manual implementation of what would now be called a software bill of materials, package-provenance graph, mobile attack-surface inventory, and device attestation record. ## Chronological and conceptual trajectory ### Phase 1 — Operational agenda Page 2 establishes a support context and a mobile-research queue: ROMs, dialers, LineageOS, gadgets, and app-manager activity. Page 3's “The Dagger Authors” suggests that APK license or source metadata had already begun surfacing unfamiliar entities. ### Phase 2 — Format and platform reconnaissance Pages 4–9 move through KolibriOS, Symbian, ShadowProtect, legacy file extensions, Unicode, Java bytecode, firmware, graphics, compression, spreadsheets, game archives, Windows registry hives, and HFS/MacRoman encoding. The notes are exploratory and include several misassociations. Their value lies less in individual accuracy than in revealing the method: **enumerate every unfamiliar suffix and name, then search for the underlying system**. ### Phase 3 — Storage, remote services, and regional utilities Pages 10–13 connect ports, VMware, hosting, Western Digital, `hdd.by`, Victoria, S.M.A.R.T.-like compatibility, and component brands. The research shifts from abstract formats to hardware/software ecosystems, especially disk-health and recovery tooling with Eastern European provenance. ### Phase 4 — Surveillance as analytical frame Pages 14–15 function as section dividers. “Surveillance” and “Amazing Android MODS” frame the subsequent package inspection. The notebook is not yet asserting a specific compromise; it is defining the reason to inspect hidden software layers. ### Phase 5 — Device attestation Pages 16–17 identify the physical/software target: Moto G Stylus (2021), Android 10/API 29, `minsk`, build `QPCS30.Q4-31-26-1-9`, `user/release-keys`, kernel `4.14.117-perf+`, and Android runtime paths. This establishes the baseline needed to distinguish stock firmware from anomalies. ### Phase 6 — APK dependency and provenance analysis Pages 18–20 inspect embedded Java/GWT metadata, identify Dev Tools and its developer, and decode a Twitter FileProvider URI. The investigation learns to separate source-tree paths from network URLs and local content-provider namespaces from public web addresses. ### Phase 7 — Package-state ontology and tool lineage Pages 21–27 map unfamiliar labels, color-coded ApplicationInfo states, long-click dynamic manifests, oF2pks/MajeurAndroid lineage, ClassyShark3xodus and Google ClassyShark, declared activities, system/user REDACTED, shared UIDs, privileged package properties, carrier components, ROM-era apps, and developer domains. The notebook closes with unresolved identifiers because the analysis has become a **graph-construction process** rather than a linear troubleshooting session. ## Master entity index ### Operating systems, runtimes, and firmware | Entity | Canonical note | Pages | Archival interpretation | |---|---|---:|---| | Kolibri OS | [[KolibriOS]] | 4 | Tiny x86 hobby OS; likely part of obscure-system research. | | Symbian OS | [[Symbian\|Symbian OS]] | 4 | Legacy mobile OS, juxtaposed with compact/alternate systems. | | Windows | [[Microsoft Windows]] | 5–9 | Clipboard, NLS, Paint, GDI, registry, and legacy formats. | | HFS / HFS Plus | [[Hierarchical File System]], [[HFS Plus]] | 9 | Filesystem/encoding investigation. | | Android 10 / Q / API 29 | [[Android 10]], [[Android API Level 29]] | 16–17 | Exact operating environment of the investigated Motorola handset. | | ART / Dalvik 2.1.0 | [[Android Runtime]], [[Dalvik Virtual Machine]] | 16–17 | Runtime and HTTP user-agent fields. | | Linux kernel 4.14.117-perf+ | [[Linux Kernel]] | 17 | Device kernel baseline. | | CyanogenMod / LineageOS | [[CyanogenMod]], [[LineageOS]] | 2, 26 | ROM lineage inferred through task list and Apollo. | ### Devices and hardware | Entity | Canonical note | Pages | Archival interpretation | |---|---|---:|---| | Moto G Stylus (2021) | [[Moto G Stylus (2021)]] | 16–17 | Primary inspected Android device; codename `minsk`. | | Amazon Fire/Kindle | [[Amazon Fire Tablet]] | 21 | Context for unfamiliar “Magic Window” label/permission. | | Western Digital Passport / Elements | [[WD My Passport]], [[WD Elements]] | 10 | External-storage product families. | | PNY | [[PNY Technologies]] | 13 | Flash/storage hardware vendor. | | Samsung | [[Samsung Electronics\|Samsung]] | 13 | Written as “SamSune”; likely hardware list. | | Plextor | [[Plextor]] | 13 | Probable normalization of “PlexTro.” | | SanDisk | [[SanDisk]] | 13 | Flash storage. | | Corsair | [[Corsair]] | 12 | Hardware/component vendor. | | Intel | [[Intel Corporation\|Intel]] | 12 | Processor/storage/platform vendor. | | Kingston | [[Kingston Technology]] | 12 | Memory and storage vendor. | | Lite-On | [[Lite-On Technology\|Lite-On]] | 12 | Probable normalization of “Lighte-On.” | | PlayStation | [[PlayStation]] | 13 | Console platform connected to PSF/game-format research. | ### Applications, services, and utilities | Entity | Canonical note | Pages | Archival interpretation | |---|---|---:|---| | ShadowProtect | [[ShadowProtect]] | 4 | System image backup/recovery utility. | | Victoria HDD/SSD | [[Victoria HDD]] | 11 | Verified HDD/SSD diagnostic utility from `hdd.by`. | | Dev Tools 6.3.8-gp | [[Dev Tools (Android)]] | 17, 19 | Source of system/app telemetry; Trinea project. | | Dagger | [[Dagger Dependency Injection]] | 3 | Dependency attribution copied from license/source metadata. | | apps_Packages Info | [[apps_Packages Info]] | 22–23 | Color-coded installed-package state viewer. | | Chairlock | [[Chairlock]] | 23, 27 | Permissions explorer embedding package information and scan launch. | | ClassyShark3xodus | [[ClassyShark3xodus]] | 24 | APK tracker/signature/class/manifest analysis. | | Google ClassyShark | [[Google ClassyShark]] | 24 | Upstream APK-analysis tool. | | kDI Device Info | [[kDI Device Info]] | 23, 27 | Device diagnostics and system-capability reporting. | | AndSys | [[AndSys]] | 26 | Legacy open-source package information tool. | | Apollo | [[Apollo Music Player]] | 26 | CyanogenMod-era music player, package `com.andrew.apollo`. | | Verizon APN Library | [[Verizon APN Library]] | 26 | Package `com.vzw.apnlib`, preinstalled carrier networking component. | | FOSS Browser | [[FOSS Browser]] | 20 | Privacy/open-source browser option. | | Lightning Browser | [[Lightning Browser]] | 20 | Lightweight open-source browser. | | Privacy Browser | [[Privacy Browser Android]] | 20 | Privacy-focused WebView browser. | | Tor | [[Tor Browser]] | 20 | Privacy/anonymity browser option. | | Twitter 9.18.0 | [[Twitter for Android]] | 20 | Source of local FileProvider `legal.htm` URI; dating anchor. | | AppBrain | [[AppBrain]] | 21, 27 | App identification/market service; linked to Swiss Codemonkeys/AppTornado. | | VMware | [[VMware]] | 10 | Remote-service/port research. | | 1&1 / IONOS | [[IONOS]] | 10 | Likely hosting provider. | ### Standards, protocols, package properties, and software concepts | Entity | Canonical note | Pages | Archival interpretation | |---|---|---:|---| | UTF-8 | [[UTF-8]] | 6 | Text encoding. | | Java bytecode | [[Java Bytecode]] | 6 | Compiled Java representation. | | EFI | [[Unified Extensible Firmware Interface\|Extensible Firmware Interface]] | 6 | Firmware executable context. | | GWT | [[Google Web Toolkit]] | 18 | `.gwt.xml` module descriptor system. | | JSR 305 | [[JSR 305]] | 18 | Dormant defect-detection annotation proposal/library. | | APK | [[Android Package]] | 18, 24 | Android application archive under inspection. | | AndroidManifest.xml | [[AndroidManifest.xml]] | 24 | Static app component/permission declaration. | | FileProvider | [[Android FileProvider]] | 20 | Controlled inter-app file sharing via `content://`. | | Content URI | [[Android Content URI]] | 20 | Local provider namespace, not HTTP. | | ApplicationInfo flags | [[Android ApplicationInfo]] | 22, 25 | Persistent/stopped/inactive/suspended/system/test/overlay states. | | `usesCleartextTraffic` | [[Android Cleartext Traffic Policy]] | 22 | Manifest/network-security policy indicator. | | `sharedUserId` | [[Android sharedUserId]] | 22, 26 | Shared Linux UID mechanism, deprecated at API 29. | | `android.uid.system` | [[android.uid.system]] | 26 | Platform-level shared UID. | | `coreApp=True` | [[Android Core App Flag]] | 26 | Core platform package attribute. | | Dynamic manifest | [[Dynamic Android Manifest View]] | 23–24 | Runtime/package-manager-derived component view. | | Declared activities | [[Android Activity]] | 24 | Manifest-registered UI/entry components. | | S.M.A.R.T. | [[Self-Monitoring Analysis and Reporting Technology]] | 11–12 | Plausible domain behind “Smart compatible” notes. | | Port 3174 | [[TCP and UDP Port 3174]] | 10 | Possible reading; IANA assignment does not establish VMware usage. | | Port 8080 | [[TCP Port 8080]] | 10 | Common alternate web-service port; context-specific. | ### File extensions and formats | Notebook form | Likely or verified meaning | Pages | Confidence | |---|---|---:|---| | `.psf` | Multiple meanings; possibly PlayStation Sound Format, not Musepack | 5 | Low-to-medium | | `.clp` | Windows Clipboard file | 5 | High | | `.nls` | Windows National Language Support data | 5 | High | | `.fif` | Vendor-specific/ambiguous image or application format | 5 | Low | | `.caf` | Apple Core Audio Format | 5 | High | | `.lib` | Omnis Studio or compiled library container; context dependent | 6 | Medium | | `.edo` | Unresolved | 6 | Low | | `.efi` | UEFI executable image | 6 | High | | `.HA` | Possible HA archive/compression family | 6 | Low | | `.Z` | Unix `compress` archive | 6 | High | | `.mds` | Media Descriptor sidecar for optical-disc images | 6 | Medium-high | | `.msp` | Windows Installer patch, not Microsoft Paint native format | 7 | High | | `.wgl` | Ambiguous | 7 | Low | | `.123` | Lotus 1-2-3 spreadsheet | 7 | High | | `.xls` | Legacy Microsoft Excel workbook | 7 | High | | `.IFA` | Unresolved vendor-specific package | 7 | Low | | `.UHA` | UHarc archive | 7 | Medium-high | | `.pak` | Generic package/archive used by many applications and engines | 8 | High but nonspecific | | `.lzx` | LZX compression/archive family | 8 | High | | `.hyp` | Multiple meanings | 8 | Low | | `.pbm` | Portable Bitmap | 8 | High | | `.pgm` | Portable Graymap | 8 | High | | `.ppm` | Portable Pixmap | 8 | High | | `.pcx` | ZSoft PC Paintbrush format | 8 | High | | `.ANI` | Windows animated cursor; notebook's Unreal association doubtful | 8 | High correction | | BSA | Bethesda Softworks Archive, likely final Fallout reference | 8 | Medium | | `.dat` | Generic data; used by some registry hive files | 9 | Medium-high | | `.hiv` | Registry hive/export/offline-hive extension | 9 | High | | `.OZV/.OZI` | Unresolved | 9 | Low | | `.mip` | Multiple image/map/vendor meanings | 9 | Low | ### Domains, repositories, and identifiers | Identifier | Pages | Interpretation | |---|---:|---| | `github.com/trinea` | 19 | Trinea developer/repository identity. | | `codekk.com` | 19 | Android open-source project index/community. | | `bitbucket.org/oF2pks/MajeurAndroid/Applications-Info` | 23 | Tool/fork lineage, as transcribed. | | `com.oF2pks.kalturadeviceinfos` | 23 | kDI Device Info package ID. | | `com.oF2pks.classyshark3xodus` | 24 | ClassyShark3xodus package ID. | | `com.google.classysharkandroid` | 24 | Upstream Google ClassyShark package lineage. | | `net.sourceforge.andsys` | 26 | AndSys package ID. | | `com.vzw.apnlib` | 26 | Verizon APN library package ID. | | `com.andrew.apollo` | 26 | Apollo music-player package ID. | | `com.twitter.android.internal/fileprovider` | 20 | Twitter FileProvider authority/path context. | | `hdd.by` | 11 | Victoria HDD/SSD provenance. | | `android.codes` | 27 | Unresolved domain/source. | | `nathan.org` | 27 | Unresolved developer/source domain. | | `swisscodemonkeys.appspot.com` | 27 | Swiss Codemonkeys/AppTornado app domain. | | `bombusmod.org` | 27 | Probable BombusMod project domain. | | `bytehamster.com` | 27 | Android/open-source developer domain. | ## Technology and systems map ```text Physical device └── [[Moto G Stylus (2021)]] / Motorola `minsk` ├── Android 10 / API 29 │ ├── Linux 4.14.117-perf+ │ ├── ART runtime and Dalvik/2.1.0 HTTP identity │ ├── APEX runtime path / `core-oj.jar` │ └── Production build: `user/release-keys` ├── Firmware and carrier layer │ ├── `MINSK_NA_CUST` │ ├── `com.vzw.apnlib` │ └── stock/system/core packages ├── Package identity layer │ ├── package ID │ ├── signing certificate │ ├── installer source │ ├── shared UID / `android.uid.system` │ ├── `coreApp` │ └── system/user/overlay/code-state REDACTED ├── Static package contents │ ├── `AndroidManifest.xml` │ ├── declared activities │ ├── Dagger attribution │ ├── JSR 305 annotations │ ├── GWT module descriptor │ └── classes, resources, and tracker signatures ├── Runtime sharing layer │ ├── content providers │ ├── FileProvider │ └── `content://.../cache/legal.htm` └── Inspection toolchain ├── Dev Tools / Trinea ├── AndSys ├── apps_Packages Info ├── Chairlock ├── ClassyShark3xodus ├── kDI Device Info └── F-Droid / AppBrain / developer-domain research ``` The earlier extension and storage pages form a parallel system map: ```text Unknown file or device artifact ├── Extension lookup │ ├── text/encoding (`UTF-8`, `.nls`) │ ├── graphics (`PBM`, `PGM`, `PPM`, `PCX`) │ ├── audio (`CAF`, uncertain PSF) │ ├── archives (`.Z`, `.UHA`, `.pak`, `.lzx`) │ ├── firmware (`.efi`) │ ├── application data (`.123`, `.xls`, `.msp`) │ └── game assets (BSA/Fallout, Unreal confusion) ├── Filesystem/registry interpretation │ ├── Windows registry hives │ └── HFS/MacRoman encoding ├── Storage hardware │ ├── Western Digital, SanDisk, PNY, Kingston, Plextor │ └── PlayStation/removable-media contexts └── Diagnostic/recovery software ├── ShadowProtect ├── Victoria HDD/SSD └── unresolved Eastern European utilities ``` ## People, companies, institutions, and relationship map - [[Google]] appears through Android, ART/APEX, Dagger stewardship, Google ClassyShark, GWT, JSR 305 expert-group participation, and Android manifest/package semantics. - [[Motorola Mobility]] supplies the `minsk` device and firmware baseline. - [[Verizon Communications|Verizon]] appears through `com.vzw.apnlib`, a carrier component present in the inspected package set. - [[Trinea]] publishes Dev Tools and connects to [[codeKK]], providing the first system-information and app-inspection surface. - [[MajeurAndroid Android Applications Info]] is identified as a predecessor/origin for the Applications Info lineage. - `oF2pks` extends that lineage into [[apps_Packages Info]], [[Chairlock]], [[ClassyShark3xodus]], and [[kDI Device Info]], distributed through [[F-Droid]]. - [[Exodus Privacy]] supplies tracker signatures used by ClassyShark3xodus. - [[CyanogenMod]] supplies the lineage for [[Apollo Music Player]] and precedes [[LineageOS]], which appears in the opening task list. - [[Swiss Codemonkeys]] / AppTornado is connected to [[AppBrain]], explaining the developer domain on the final page. - [[StorageCraft]] / [[Arcserve]] supplies ShadowProtect; [[Western Digital]], [[SanDisk]], [[PNY Technologies]], [[Kingston Technology]], [[Plextor]], [[Samsung Electronics|Samsung]], [[Corsair]], [[Intel Corporation|Intel]], and [[Lite-On Technology|Lite-On]] populate the hardware/storage layer. - Sergey Kazansky is the documented developer/publisher associated with [[Victoria HDD]] and `hdd.by`. - “The Dagger Authors” is a collective copyright attribution, not an identified person. ## Cross-notebook pattern analysis ### 1. From device inventory to software-bill-of-materials thinking The nearby notebooks repeatedly catalog physical hardware labels, model numbers, controllers, ROMs, cloud providers, and package IDs. `Scanned_20260730-1806` adds a crucial intermediate layer: **the internal composition of software artifacts**. Dagger, JSR 305, GWT descriptors, manifests, classes, tracker signatures, and developer domains are treated as evidence of lineage. This is recognizably an informal software bill of materials before SBOM practice became broadly normalized outside specialist security contexts. ### 2. Identity beneath display names Across the collection, visible names are distrusted as incomplete. Here “Magic Window,” “DevTools,” “Apollo,” “Twitter,” and “System” are translated into package IDs, fingerprints, authorities, UIDs, and repositories. The same ontological move appears elsewhere when brands are decomposed into owners, acquisitions, cloud infrastructure, chipsets, and domains. The recurring question is **what stable identity persists beneath a mutable label?** ### 3. Storage as continuity substrate Pages 5–13 may initially look like miscellaneous extension research, but they belong to the collection's deeper continuity architecture. File formats, registry hives, filesystem encodings, archive containers, drive diagnostics, and external-storage brands are all conditions of whether memory can be preserved, interpreted, and migrated. The later corpus's concern with digital continuity is already materially present here. ### 4. Surveillance reframed as privilege and provenance Rather than stopping at a suspicion label, the notebook moves toward inspectable properties: `android.uid.system`, `coreApp`, persistent/stopped states, cleartext policy, overlays, code presence, signatures, developer origins, and carrier libraries. This is the stronger analytic trajectory: surveillance risk is not inferred from strangeness alone but decomposed into **capabilities, trust roots, persistence, data access, and provenance**. ### 5. Manual semantic-web behavior The final pages are a hand-built knowledge graph: app → package ID → developer → repository → predecessor → fork → F-Droid record → runtime privilege → embedded dependency → domain. This directly anticipates the user's later Obsidian and semantic-web practices. The notebook is not merely recording facts; it is constructing **navigable relations among heterogeneous identifiers**. ### 6. Early correction discipline The notebook contains visible self-corrections—MacRoman “not a font,” Fallout “(Not),” crossed “Lotus,” rewritten boot class path, and questions about GWT/JSR. This matters because it shows an investigative style willing to preserve uncertainty and revise hypotheses. The current reconstruction continues that discipline by separating exact transcription from normalized technical interpretation. ## What I Was on the Trail Of You were on the trail of **software identity as a layered forensic object**. At the surface was an app label or file extension. Beneath it were containers, manifests, package IDs, UIDs, signing relationships, runtime paths, build fingerprints, developer handles, repository origins, carrier customizations, and embedded third-party libraries. You were approaching several now-familiar disciplines simultaneously: - **Mobile device attestation:** establishing device, firmware, kernel, build channel, and production-signature state. - **Software composition analysis:** recognizing that an APK contains a dependency graph whose copyright notices and XML resources reveal its ancestry. - **SBOM construction:** enumerating libraries, packages, developers, and versions even before formal SBOM exchange became routine. - **Package provenance and supply-chain analysis:** tracing Play Store names to GitHub/Bitbucket projects, forks, original authors, F-Droid builds, and signing identities. - **Privilege-surface analysis:** distinguishing system/user/core/shared-UID/overlay/test/code-less package states. - **Local namespace literacy:** learning that `content://`, source-tree `//`, file paths, and public URLs are ontologically different even when their syntax looks similar. - **Continuity engineering:** understanding that files survive only when formats, encodings, filesystems, archives, and storage media remain interpretable. The notebook's deepest unifying insight is that **a digital object is never only the object presented to the user**. It is a nested historical system whose hidden metadata carries origin, capability, dependency, and trust. ## What I Missed or Could Not Yet See The most consequential missing layer was **cryptographic verification**. The notebook records package names and origins but does not preserve APK hashes, signing-certificate digests, verified-boot state, bootloader lock state, or comparisons against stock firmware manifests. Those would have converted many suspicions into decisive provenance findings. The extension research also relied too heavily on suffix descriptions. File extensions are weak evidence because they are ambiguous, mutable, and easily spoofed. Magic bytes, container parsing, MIME detection, entropy, internal structure, and originating-application metadata would have produced a more reliable classification system. The package-state legend was being decoded manually, but the next step—exporting a machine-readable package inventory—was not yet visible. A single structured dataset containing package ID, version, install path, installer, UID, shared UID, signature, requested/granted permissions, components, native ABIs, target SDK, hashes, and network endpoints would have unified most of the later pages. The notebook also approached but did not fully name **transitive dependency noise**. The JSR 305/GWT resource was probably present because a library bundled it, not because the app intentionally implemented GWT behavior. Modern software analysis must distinguish first-party code, third-party libraries, dead resources, generated metadata, and dynamically loaded modules. Finally, the “Surveillance” frame could have been strengthened by a formal capability model. Strange names, Russian provenance, system privileges, or carrier packages are not equivalent to surveillance. The decisive questions are: what data can the component access, under what conditions, through which APIs, with what network behavior, signed by whom, installed by what trust root, and compared against which known-good baseline? ## Prioritized unresolved research agenda 1. **Reconstruct the exact Motorola baseline.** Obtain the matching stock firmware for `QPCS30.Q4-31-26-1-9`, enumerate its factory packages, and compare package hashes/signatures against any surviving device backup. 2. **Resolve package-specific observations.** Identify which package displayed `android.uid.system`, `coreApp=True`, every page-22 state, and the page-25 REDACTED variants. 3. **Recover the inspected APK on page 18.** Determine the exact filename, hash, certificate, dependency tree, and whether Dagger and JSR 305/GWT resources coexist in it. 4. **Map every final-page domain to a package.** Resolve `android.codes`, `nathan.org`, `bombusmod.org`, `bytehamster.com`, and Swiss Codemonkeys against package metadata and archived market listings. 5. **Identify “Magic Window.”** Recover package ID, version, installer, and permission list from the Fire/Kindle environment. 6. **Reconstruct the oF2pks tool versions.** Match the handwritten legends to exact versions of apps_Packages Info, Chairlock, ClassyShark3xodus, and kDI, preserving source commits and F-Droid build metadata. 7. **Resolve the storage-utility list.** Trace “IBM SuperSmart,” “SCT Gold Standard,” “B-Smart,” “SMYG,” “Sable,” “Doomer,” “Izyum,” “SFinXx,” “Serg-T,” “Tecton,” “Datex,” “LMT,” and “DCZ” to the source page or download collection. 8. **Identify the extension-reference source.** Rebuild pages 5–9 against the original database and separate miscopied rows from genuine equivalences. 9. **Locate the support case context.** Match the page-2 case number and time notation to email or account records without exposing credentials. 10. **Integrate findings into the cumulative chronology and device inventory.** Add the Motorola `minsk` build, package toolchain, and probable 2021–2022 date bracket to the master NOTEBOOKS indexes. ## Self-contained archival narrative A future reader without the scans should understand this notebook as the record of a researcher moving from a support-related task list into a layered examination of mobile systems. The notebook begins with an iCloud address, a case number, times, and a to-do list concerning ROM updates, phone/tablet dialers, LineageOS, gadgets, and app-manager activity. A fragment reading “The Dagger Authors” likely comes from an Android library license. The researcher then catalogs obscure operating systems, backup software, file extensions, encodings, graphics and audio formats, archives, spreadsheet files, game assets, registry hives, HFS/MacRoman behavior, remote-service ports, virtualization, hosting, external drives, disk diagnostics, and hardware brands. Some entries are accurate, others are copied imperfectly, and several remain unresolved. A single-word page—“Surveillance”—marks the conceptual pivot. The researcher begins interrogating a Moto G Stylus (2021), copying its Android 10/API 29 identity, `minsk` customization, build `QPCS30.Q4-31-26-1-9`, production fingerprint, Linux kernel, Java home, boot class path, APEX runtime path, and Dalvik HTTP user agent. They identify the system-information tool as Trinea's Dev Tools 6.3.8-gp and trace it to GitHub and codeKK. While inspecting an APK, they find `Jsr305_annotations.gwt.xml`, copy its XML comment and source-tree path, and ask what GWT and JSR mean. This reveals an emerging understanding that packaged applications contain inherited third-party histories. Next they record four privacy-oriented browsers and a Twitter `content://` FileProvider URI to a cached `legal.htm` file, then investigate an unfamiliar “Magic Window” on a Fire/Kindle device. They decode the color and symbol system of an installed-package viewer: persistent, stopped, inactive, suspended, shared UID, READ_LOGS, resource overlay, multiarch, no-code, test-only, and cleartext-traffic states. They trace the tool family through F-Droid, MajeurAndroid, oF2pks, Bitbucket, Chairlock, kDI, ClassyShark3xodus, and Google's original ClassyShark. They inspect Android manifests and declared activities, distinguish user and system package symbols, and record highly privileged attributes such as `android.uid.system` and `coreApp=True`. Finally they list package IDs for AndSys, Verizon's APN library, and the CyanogenMod Apollo player, followed by developer domains including Swiss Codemonkeys/AppTornado, BombusMod, and ByteHamster. The notebook does not establish that the phone was compromised. Its historical importance is methodological: it shows the construction of a manual device and software provenance graph from fragments that ordinary interfaces conceal. It is an early record of the user's movement toward systems archaeology, supply-chain analysis, privilege mapping, and continuity-oriented knowledge reconstruction. # Linked Notes Created or Referenced ## Notebooks [[Scanned_20260730-1235]], [[Scanned_20260730-1650]], [[Scanned_20260730-1719]], [[Scanned_20260730-1720]], [[Scanned_20260730-1756]], [[Scanned_20260730-1802]], [[Scanned_20260730-1845]] ## Operating systems, platforms, and runtimes [[Android]], [[Android 10]], [[Android API Level 29]], [[Android Runtime]], [[Android Runtime APEX]], [[CyanogenMod]], [[Dalvik Virtual Machine]], [[Unified Extensible Firmware Interface|Extensible Firmware Interface]], [[HFS Plus]], [[Hierarchical File System]], [[KolibriOS]], [[LineageOS]], [[Linux Kernel]], [[Microsoft Windows]], [[PlayStation]], [[Symbian|Symbian OS]], [[UTF-8]] ## Devices and hardware [[Amazon Fire Tablet]], [[Corsair]], [[Intel Corporation|Intel]], [[Kingston Technology]], [[Lite-On Technology|Lite-On]], [[Moto G Stylus (2021)]], [[Plextor]], [[PNY Technologies]], [[Samsung Electronics|Samsung]], [[SanDisk]], [[WD Elements]], [[WD My Passport]], [[Western Digital]] ## Android packages, applications, and toolchains [[Android Application Manager]], [[AndSys]], [[Apollo Music Player]], [[AppBrain]], [[apps_Packages Info]], [[Chairlock]], [[ClassyShark3xodus]], [[Dev Tools (Android)]], [[F-Droid]], [[FOSS Browser]], [[Google ClassyShark]], [[kDI Device Info]], [[Lightning Browser]], [[Privacy Browser Android]], [[Tor Browser]], [[Twitter for Android]], [[Verizon APN Library]] ## Standards, code, and package semantics [[Android Activity]], [[Android ApplicationInfo]], [[Android Build Fingerprint]], [[Android Cleartext Traffic Policy]], [[Android Content URI]], [[Android Core App Flag]], [[Android FileProvider]], [[Android Package]], [[Android Package State Legend]], [[Android sharedUserId]], [[AndroidManifest.xml]], [[android.uid.system]], [[Dagger Dependency Injection]], [[Dynamic Android Manifest View]], [[Google Web Toolkit]], [[Java Bytecode]], [[Java Class Path]], [[Java Specification Request]], [[JSR 305]], [[Microsoft Graphics Device Interface]], [[Microsoft National Language Support]], [[Self-Monitoring Analysis and Reporting Technology]] ## File formats and storage technologies [[Apple Core Audio Format]], [[Bethesda Softworks Archive]], [[LZX Compression]], [[Microsoft Windows Clipboard File Format]], [[Netpbm]], [[PCX]], [[Read-Only Memory Image]], [[ShadowProtect]], [[UHA Compression]], [[Victoria HDD]], [[Windows Registry Hive]] ## People, companies, projects, and institutions [[Apple]], [[Arcserve]], [[Bitbucket]], [[codeKK]], [[Exodus Privacy]], [[GitHub]], [[Google]], [[IBM]], [[IONOS]], [[MajeurAndroid Android Applications Info]], [[Motorola Mobility]], [[oF2pks]], [[StorageCraft]], [[Swiss Codemonkeys]], [[Trinea]], [[Verizon Communications|Verizon]] ## Concepts and recurring themes [[Android Modding]], [[Device Attestation]], [[Index - Device Inventory|Device Inventory]], [[File Provenance]], [[Mobile Application Forensics]], [[Package Provenance]], [[Software Bill of Materials]], [[Software Composition Analysis]], [[Software Supply-Chain Provenance|Software Supply Chain]], [[Surveillance]], [[System Privilege]], [[Technical Continuity]] # Research sources [^dagger]: Google, “Dagger - A fast dependency injector for Android and Java,” GitHub, https://github.com/google/dagger. The repository's license text includes “Copyright 2012 The Dagger Authors.” [^kolibri]: KolibriOS Project, official site, https://kolibrios.org/. Describes KolibriOS as a tiny x86-compatible operating system requiring only a few megabytes of storage and 12 MB RAM. [^symbian]: Wired, “Symbian Operating System, Now Open Source and Free,” February 2010, https://www.wired.com/2010/02/symbian-operating-system-now-open-source-and-free/. [^shadowprotect]: Arcserve, “Windows Installation - ShadowProtect SPX,” https://documentation.arcserve.com/Arcserve-ShadowProtect/Available/ENU/SPX_ug/Content/ShadowProtect_SPX_UG/SPX-Windows-Installation.htm; Arcserve, ShadowProtect product page, https://www.arcserve.com/products/arcserve-shadowprotect. [^clp]: LEADTOOLS, “Microsoft Windows Clipboard (CLP) File Format,” https://www.leadtools.com/help/sdk/dh/to/file-formats-microsoft-windows-clipboard-clp.html. [^nls]: Microsoft Learn, “National Language Support,” https://learn.microsoft.com/en-us/windows/win32/intl/national-language-support. [^caf]: Apple, “Apple Core Audio Format Specification 1.0,” https://developer.apple.com/library/archive/documentation/MusicAudio/Reference/CAFSpec/CAF_intro/CAF_intro.html. [^pcx]: Library of Congress, “PiCture eXchange (PCX),” https://loc.gov/preservation/digital/formats/fdd/fdd000585.shtml. [^netpbm]: Netpbm documentation overview and format description, https://netpbm.sourceforge.net/doc/; Paul Bourke, “PPM/PGM/PBM image files,” https://paulbourke.net/dataformats/ppm/. [^bsa]: GECK Wiki, “BSA Files,” https://geckwiki.com/index.php/BSA_Files; AlexxEG, “BSA Browser,” GitHub, https://github.com/AlexxEG/BSA_Browser. [^registry]: Microsoft Learn, “Registry Hives,” https://learn.microsoft.com/en-us/windows/win32/sysinfo/registry-hives. [^hfs]: Apple, “Technical Note TN1150: HFS Plus Volume Format,” https://developer.apple.com/library/archive/technotes/tn/tn1150.html. [^iana3174]: Internet Assigned Numbers Authority, “Service Name and Transport Protocol Port Number Registry,” https://www.iana.org/assignments/service-names-port-numbers/; the registry lists `armi-server` for TCP/UDP 3174. [^vmwareports]: Broadcom, “VMware Ports and Protocols,” https://ports.broadcom.com/. [^victoria]: MajorGeeks, “Victoria for Windows 5.37,” dated October 14, 2021, https://m.majorgeeks.com/files/details/victoria_for_windows.html; Microsoft winget package request identifying Sergey Kazansky, `hdd.by`, and version 5.37, https://github.com/microsoft/winget-pkgs/issues/151058. [^phonecopy]: PhoneCopy, “Synchronize Motorola Moto G Stylus 2021,” https://www.phonecopy.com/en/phones/view/motorola_moto_g_stylus_2021. The confirmed versions include `qpcs30.q4-31-26-1-9` for the `minsk` family. [^motorolabuild]: Cfirmware, Motorola `minsk_retail` firmware record, https://www.cfirmware.com/index.php?a=downloads&b=file&id=46824. It records `motorola/minsk_retail/minsk:10/QPCS30.Q4-31-26-1-9/bb626:user/release-keys` and a `210628` bootloader/build lineage marker. [^gwt]: GWT Project, “Organizing Projects,” https://www.gwtproject.org/doc/latest/DevGuideOrganizingProjects.html. Documents `.gwt.xml` module configuration files. [^jsr305]: Java Community Process, “JSR 305: Annotations for Software Defect Detection,” https://www.jcp.org/en/jsr/detail?id=305. Status: dormant since May 2012. [^jsr305apk]: Stack Overflow, “jsr305_annotations folder inside apk file,” https://stackoverflow.com/questions/17486721/jsr305-annotations-folder-inside-apk-file; example preserved source resource, https://github.com/isnuryusuf/ingress-indonesia-dev/blob/master/source/ingress-1.37.2-broot-1.0.2.13/unknown/jsr305_annotations/Jsr305_annotations.gwt.xml. [^devtools]: APKMirror, “Dev Tools(Developer)-Decompile 6.3.8-gp - Trinea,” https://www.apkmirror.com/apk/trinea/dev-toolsandroid-developer-tools/dev-toolsandroid-developer-tools-6-3-8-gp-release/. [^codekk]: codeKK, “AndroidCommon / Android Developer Tools,” https://p.codekk.com/detail/Android/Trinea/AndroidCommon; Dev Tools FAQ, https://mlhao1.p.codekk.com/developer-tools/faq. [^lightning]: Anthony Restaino, “Lightning Browser,” GitHub, https://github.com/anthonycr/Lightning-Browser. [^privacybrowser]: Stoutner, “Privacy Browser Android,” https://www.stoutner.com/privacy-browser-android/. [^fileprovider]: Android Developers, “Setting up file sharing,” https://developer.android.com/training/secure-file-sharing/setup-sharing; “Sharing files,” https://developer.android.com/training/secure-file-sharing. [^contenturi]: Android Developers, “Content provider basics,” https://developer.android.com/guide/topics/providers/content-provider-basics. [^twitter918]: APKMirror, “Twitter 9.18.0-release.00,” released November 2, 2021, https://www.apkmirror.com/apk/x-corp/twitter/twitter-9-18-0-release-00-release/. [^applicationsinfo]: F-Droid, “apps_Packages Info - Updated ApplicationsInfos,” https://f-droid.org/packages/com.oF2pks.applicationsinfo/. The feature list includes persistent, stopped, inactive, suspended, shared UID, READ_LOGS, overlays, manifests, and ClassyShark integration; versions 1.7-17 through 1.7-19 were added January–March 2022. [^applicationelement]: Android Developers, “`<application>` manifest element,” https://developer.android.com/guide/topics/manifest/application-element; Android Developers, `ApplicationInfo` API reference, https://developer.android.com/reference/android/content/pm/ApplicationInfo. [^chairlock]: F-Droid, “Chairlock,” https://f-droid.org/packages/com.oF2pks.chairlock/. Describes the permissions explorer, embedded apps_Packages Info, dynamic manifest access, and ClassyShark launch. [^kdi]: F-Droid, “kDI Device Info system permission,” https://f-droid.org/packages/com.oF2pks.kalturadeviceinfos/. Describes device diagnostics, Widevine, Treble, A/B partitions, media decoders, and the rebranding from KalturaDeviceInfo. [^classyshark]: F-Droid, “ClassyShark3xodus - Scan apps for warnings,” https://f-droid.org/packages/com.oF2pks.classyshark3xodus/. Describes tracker-signature scans, class listing, static/dynamic manifests, signatures, and its basis in Google's ClassyShark. [^manifest]: Android Developers, “App manifest overview,” https://developer.android.com/guide/topics/manifest/manifest-intro. [^shareduserid]: Android Developers, “`<manifest>` element,” https://developer.android.com/guide/topics/manifest/manifest-element. Android deprecates shared user IDs at API level 29 because of package-manager behavior and coupling. [^andsys]: F-Droid historical forum record, “AndSys,” https://f-droid.org/forums/index.html?p=6270.html. Identifies `net.sourceforge.andsys` as a 2012–2013 beta Package Information Tool. [^apnlib]: APKMirror, “apnlib” by Verizon Consumer Group, package `com.vzw.apnlib`, https://www.apkmirror.com/apk/verizon-vz/apnlib/; Samsung Knox application inventory showing `com.vzw.apnlib` as a system application, https://docs.samsungknox.com/CCMode/N975U_Q.pdf. [^apollo]: F-Droid historical mirror, “Apollo,” https://huftis.gitlab.io/fdroid-website/en/packages/com.andrew.apollo/. Describes it as the music app bundled with CyanogenMod 10. [^swisscodemonkeys]: Uwe Maurer/AppTornado profile connecting AppBrain and Swiss Codemonkeys, https://ch.linkedin.com/in/uwemaurer; historical app references use `swisscodemonkeys.appspot.com` as the developer site.