Forensic Analysis of Artifacts of Giant Instant Messaging “WhatsApp” in Android Smartphone

  • Hussein Abed Ghannam Swiss German University
Keywords: Whatsapp, Android, Android Forensics Analysis, Artifacts, Encryption, Instant Message, Digital Crime

Abstract

WhatsApp is a giant mobile instant message IM application with over 1billion users. The huge usage of IM like WhatsApp through giant smart phone “Android” makes the digital forensic researchers to study deeply. The artefacts left behind in the smartphone play very important role in any electronic crime, or any terror attack. “WhatsApp” as a biggest IM in the globe is considered to be very important resource for information gathering about any digital crime. Recently, end-to-end encryption and many other important features were added and no device forensic analysis or network forensic analysis studies have been performed to the time of writing this paper. This paper explains how can we able to extract the Crypt Key of “WhatsApp” to decrypt the databases and extract precious artefacts resides in the android system without rooting the device. Artefacts that extracted from the last version of WhatsApp have been analysed and correlate to give new valuable evidentiary traces that help in investigating. Many hardware and software tools for mobile and forensics are used to collect as much digital evidence as possible from persistent storage on android device. Some of these tools are commercial like UFED Cellebrite and Andriller, and other are open source tools such as autopsy, adb, WhatCrypt. All of these tools that forensically sound accompanied this research to discover a lot of artefacts resides in android internal storage in WhatsApp application.

Published
2018-10-28
How to Cite
Ghannam, H. A. (2018). Forensic Analysis of Artifacts of Giant Instant Messaging “WhatsApp” in Android Smartphone. Journal of Applied Information, Communication and Technology, 5(2), 63-72. https://doi.org/10.33555/ejaict.v5i2.55
Section
Articles