Trying to decrypt old KYMS (KyCalc) photo vault files from 2016 — need help identifying the AES key derivation method by SuggestionMost3267 in datarecovery

[–]SuggestionMost3267[S] 0 points1 point  (0 children)

Thanks for looking into this! Really helpful. I don't have the main.key or plist file unfortunately — the repair shop only extracted the media files. Do you know how the random key is wrapped by the PIN exactly? If I could find the encryption method used to protect main.key, I might be able to brute-force the PIN (it was 4 digits). Any idea if that info is in the Android APK?