Decrypting WhatsApp...
 
Notifications
Clear all

Decrypting WhatsApp msgstore

6 Posts
4 Users
0 Reactions
4,397 Views
ForensicMeteor
(@forensicmeteor)
Trusted Member
Joined: 11 years ago
Posts: 60
Topic starter  

I have an android device that cannot boot. We went with a chipoff and have a physical bin of the phone and it parses fine in Cellebrite. However, we cannot parse the WhatsApp data. Usually, we would use a utility to pull the key from the running phone. Is there a way to accomplish this using the extraction?


   
Quote
Igor_Michailov
(@igor_michailov)
Honorable Member
Joined: 20 years ago
Posts: 529
 

Oxygen Software, UFED, XRY, Belkasoft can do it (extract WhatsApp messages from bin file)


   
ReplyQuote
ForensicMeteor
(@forensicmeteor)
Trusted Member
Joined: 11 years ago
Posts: 60
Topic starter  

The database is encrypted so parsing will not happen without the key.


   
ReplyQuote
 RonS
(@rons)
Reputable Member
Joined: 17 years ago
Posts: 358
 

if you have a chipoff, the key should be there and it should be decrypted.

Sent you a PM

RonS


   
ReplyQuote
SamBrown
(@sambrown)
Trusted Member
Joined: 10 years ago
Posts: 97
 

You are looking at the wrong folder. Don't use the "WhatsApp" folder on the internal sd card (/shared/0). This folder only contains the media files and the encrypted backup databases.

Instead use the "com.whatsapp" folder found in /data/data. This folder contains the plaintext database msgstore.db and the key file to decrypt the backups from the WhatsApp folder.


   
ReplyQuote
Igor_Michailov
(@igor_michailov)
Honorable Member
Joined: 20 years ago
Posts: 529
 

Extracting whatsapp database and the cipher key from a non rooted android device
http//www.weare4n6.com/extracting-whatsapp-database-and-the-cipher-key-from-a-non-rooted-android-device/

Decrypting encrypted whatsapp databases without the key
http//www.weare4n6.com/decrypting-encrypted-whatsapp-databases-without-the-key/


   
ReplyQuote
Share: