Abstract
As organized criminals use instant messengers, it becomes increasingly important to obtain digital evidence from instant messengers. Recently, instant messengers apply end-to-end encryption, so all digital evidence can only be obtained from your mobile device. However, some instant messengers encrypt and store database and multimedia files, making forensic analysis of mobile devices difficult. In this paper, we present a methodology for analyzing the decryption algorithm of the messenger, and apply this methodology to Signal, Wickr, and Threema. We extracted data from both unrooted and rooted devices and performed static and dynamic analysis. As a result, we succeeded in decrypting all the encrypted database, multimedia, log, and preferences files of three messengers. We describe the decryption algorithms and disclose all decryption scripts.
Author supplied keywords
Cite
CITATION STYLE
Son, J., Kim, Y. W., Oh, D. B., & Kim, K. (2022). Forensic analysis of instant messengers: Decrypt Signal, Wickr, and Threema. Forensic Science International: Digital Investigation, 40. https://doi.org/10.1016/j.fsidi.2022.301347
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.