Solution: Indeed it was EncFs file level encryption.
Thanks a lot for everyone helping!
Original post below:
Hope it is ok to ask technical questions in this channel!
I found a folder of files on one of my back drives which was copied from a very old cell phone or a SAMSUNG Galaxy S2.
The folder is called DCIM and in a sub folder called Camera there are files with a .jpg extension.
This files are not standard JPG files. They start with the following header:
0000000 0000 0000 3900 c0d8 ac5f d196 2d63 2421
0000010 0003 0200 0000 0010 0200 2d8c 0904 0103
0000020 0000 0000 0000 0000 e960 2861 7025 ba0e
0000030 2424 dcfa 3e3b ee64 0800 c87b a43a a90d
0000040 7287 b815 7ca4 9680 ed65 6216 5f08 4f43
0000050 534e 4c4f 0045 0000 9000 b3e9 1333 92b9
0000060 0002 0000 0000 0000 0000 0000 0000 0000
0000070 0000 0000 0000 0000 0000 0000 0000 0000
(obtained via hexdump -n 1024 filename.jpg).
The file command just returns ‘data’. The jpgrecovery command simply does not process this files. If I open the file in a file viewer (shotwell), I get the error that the file starts with 0 0, which is correct, as seen in the above hexdump.
All this commands were executed on Debian 12.
I have hundreds of files with this JPG extension and for each file the header isstarting with 0 0 in this folder, so I assume the problem is not corruption of one file.
My questions:
- What kind of file format is this?
- How can I convert the files to JPGs?
or, if it was a LG phone, could they be encrypted?
if so, perhaps this will help https://github.com/kamicater/LG-Gallery-Decryptor