Lecture 13: Case study 3: IM Forensics Flashcards

1
Q

Skype - important databases/tables

A

main.db

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

Potential evidence Skype

A
  • Account information
  • Contact information
  • Call log
  • Chat logs
  • File Transfer
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Whatsapp - important databases/tables

A
  • ChatStorage.sqlite –> ZWAMESSAGE
  • Contacts.sqlite –> ZWAADDRESSOOKCONTACT

Android
- msgstore.db –> messages
- wa.db –> wacontacts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Viber - important databases/tables

A

Contacts.data –>
ZABCONTACT (All contacts found on the phone)
ZATTACHMENT (All the attachments exchanged)
ZCONVERSATION (List of unique conversations)
ZPHONENUMBER (List of phone numbers)
ZRECENT (List of recent calls)
ZSTICKER (Data related to the sticker icons)
ZSTICKERSPACKAGE (Data related to the available sticker packages)
ZVIBERLOCATION (Latitude and longitude of each
message sent_
ZVIBERMESSAGE (List of messages exchanged)

Android:
- viber_data (calls, phonebookcontact, phonebookdata, vibernumbers)
- viber_messages (messages, participants, participants_info)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly