@article{REN2025, 
author = {Fengkai REN and Dong ZHANG and Ran PANG and Ran FENG},
title = {Forensic Clue Mining and Data Analysis of Malicious Instant Messaging Apps Involved in Cases},
year = {2025},
journal = {Forensic Science and Technology},
volume = {50},
number = {5},
pages = {457-462},
keywords = {instant messaging(IM), apk, static analysis, dynamic network packet capture, SQL, pseudo-encryption},
url = {https://www.sciopen.com/article/10.16467/j.1008-3650.2024.0059},
doi = {10.16467/j.1008-3650.2024.0059},
abstract = {In recent years, telecommunications fraud cases have become increasingly prevalent, with criminals continuously refining their fraud tactics. From initially exploiting mainstream instant messaging platforms like WeChat and QQ, perpetrators have shifted to luring victims into specially crafted apps. To streamline development and reduce costs, criminals embed third-party SDK interface codes into these illicit apps, with IM (Instant Messaging) services being a common type. In these novel fraud scenarios, conducting both dynamic and static analyses of the chat-focused apk files involved can yield valuable forensic leads regarding IM services and access databases containing crucial information for investigation and prosecution. This article, taking the Android system as an example, meticulously outlines the process of mining forensic clues from instant messaging apps and subsequent data analysis, encompassing technical principles, analysis and processing steps, and case applications. It emphasizes techniques such as extracting key values through apk static analysis, validating those keys via dynamic packet capture, and utilizing SQL queries to sift through and analyze chat logs, thereby offering a professional methodological reference for evidence gathering in related cases.}
}