
Forensic evidence dossier for Operation Black Hole - Investigating fraudulent Falla app ecosystem (TRON blockchain, admin panel exposure, infrastructure recon). CST regulatory submission portfolio.
Case ID: OBH-2025-CST-001 Analyst: Sulaiman Alshammari - GraTech Forensic Division Date: April 2026 Methodology: OSINT + Authorized Digital Forensics (ISO 27037, NIST SP 800-86)
DISCLAIMER: This is a public forensic research portfolio. All sensitive values (credentials, wallet addresses, API keys) have been REDACTED. This material is prepared for submission to the Communications, Space & Technology Commission (CST) of Saudi Arabia. No unauthorized access or exploitation was performed. All evidence was collected via OSINT and authorized methods only.
This repository documents Operation Black Hole, an investigation into a multi-publisher, multi-jurisdiction network of voice chat/gifting applications that share infrastructure, developer identities, and financial pipelines.
The investigation identified 5 applications (high confidence) and 1 additional application (medium confidence) operating as a single coordinated network under different publisher names across Hong Kong, Singapore, and Shenzhen.
iOS Publisher (shared): Shenzhen Yinguo Network Technology Co., Ltd. publishes Falla Lite, TooFun, Taeal, and JoyMi under one account.
Apps are linked based on: publisher identity match, package ID prefix patterns
(com.iyinguo.*), shared developer email addresses, shared physical addresses,
and shared iOS publisher accounts. See analysis/app-attribution-matrix.md
for full details.
/fallaadmin endpoint discovered via FFUF (47+ hidden endpoints)operation-black-hole/
├── README.md # This file
├── METHODOLOGY.md # Investigation methodology & ethical boundaries
├── evidence/
│ ├── admin-panels/
│ │ └── fallaadmin.js # Extracted admin panel source (REDACTED)
│ └── forensic-images/
│ └── disk-hashes.sha256 # SHA-256 chain of custody manifest
├── analysis/
│ ├── app-attribution-matrix.md # App-to-entity mapping with confidence levels
│ ├── infrastructure-map.md # Network topology (Mermaid diagrams)
│ ├── financial-flow.md # Money laundering flow analysis
│ └── technical-report.md # Full technical analysis
└── presentation/
└── cst-interview-deck.md # CST technical presentation
Key evidence files from the forensic workstation (SHA-256):
Note: The
fallaadmin.jsin this repository is a REDACTED version of the original. The original file (hash above) is preserved in the encrypted evidence archive. Hash difference is expected due to redaction of credentials and API keys.
See METHODOLOGY.md for full details on investigation methodology, tools, ethical boundaries, and chain of custody procedures.
Sulaiman Alshammari GraTech Forensic Division Case ID: OBH-2025-CST-001
| App | Platform | Package ID | Publisher | Confidence |
|---|
| Falla | Android | com.juhaoliao.vochat | Hong Kong Huanyu Interactive Network Technology Co., Ltd | High |
| Falla Lite | Android | com.iyinguo.fallalite | Hong Kong Huanyu Interactive Network Technology Co., Ltd | High |
| TooFun | Android | com.iyinguo.trchat | Hong Kong Huanyu Network Technology Co., Ltd | High |
| JoyMi | Android | com.joymi.seven | FALLA PTE. LTD. (Singapore) | High |
| Taeal | Android | com.taeal.mansur | FALLA PTE. LTD. (Singapore) | High |
| Boli | Android | com.iyinguo.silkroad | Boli Technology Ltd / HK Tingyin Network Technology Co., Ltd | Medium |
| Hilo | iOS | id1519958782 | PARTYCOME PTE. LTD. | Low (candidate) |
| ID | Vulnerability | Severity | CVSS |
|---|
| V-001 | Hardcoded Admin Credentials | Critical | 9.8 |
| V-002 | SQL Injection in Login | Critical | 9.1 |
| V-003 | No Rate Limiting on API | High | 7.5 |
| V-004 | Exposed MongoDB (No Auth) | Critical | 9.8 |
| V-005 | Unencrypted Payment Data | High | 8.1 |
| V-006 | Missing CSRF Protection | Medium | 6.5 |
| File | SHA-256 |
|---|
| falla_admin.js (original) | 71bf18bf6be88fc7afb4a0d5ae668148d0f75f080ec9e6a6956776bc865ad88d |
| falla_beautified.js | 121af874c746a024fad07c42265780668aa3439cbbd6e2d9bb92ec605b69348c |
| FULL_FORENSIC_REPORT.txt | 62edf4e153db0956f0594d2b3deb7ee680a53fdccc53d823bc544df7b0a72a0e |
| FRAUD_FINANCIAL_REPORT.txt | 9b82b3249535fa1c0f7515420cbb98ca16d36ea2057177aba24c7fc26647d95a |
| extracted_tron_addresses.json | f6037e04a9501fe094e70e2b5c5c6459a1cded2faef9422b9f689e102347018f |
| FORENSIC_CRYPTO_REPORT.json | 36e16cff90a446e7483ac7ecc20b25c026f4ad41891823074f5f4a8f2d07aa30 |
| final_hilo_falla_clean.txt | 800e09f3e651274ee63f299a614563a81ef342a81ae3f8c623422ef179111815 |