In recent years, telecommunications fraud cases have become increasingly prevalent, with criminals continuously refining their fraud tactics. From initially exploiting mainstream instant messaging platforms like WeChat and QQ, perpetrators have shifted to luring victims into specially crafted apps. To streamline development and reduce costs, criminals embed third-party SDK interface codes into these illicit apps, with IM (Instant Messaging) services being a common type. In these novel fraud scenarios, conducting both dynamic and static analyses of the chat-focused apk files involved can yield valuable forensic leads regarding IM services and access databases containing crucial information for investigation and prosecution. This article, taking the Android system as an example, meticulously outlines the process of mining forensic clues from instant messaging apps and subsequent data analysis, encompassing technical principles, analysis and processing steps, and case applications. It emphasizes techniques such as extracting key values through apk static analysis, validating those keys via dynamic packet capture, and utilizing SQL queries to sift through and analyze chat logs, thereby offering a professional methodological reference for evidence gathering in related cases.
Publications
- Article type
- Year
Article type
Year
Open Access
Research Article
Issue
Forensic Science and Technology 2025, 50(5): 457-462
Published: 19 August 2024
Downloads:0
Total 1
京公网安备11010802044758号