WeChat Desktop App ...
 
Notifications
Clear all

WeChat Desktop App Artefacts for macOS

2 Posts
2 Users
0 Reactions
1,314 Views
(@swastibhushan)
Active Member
Joined: 10 years ago
Posts: 8
Topic starter  

Hi Folks,

While working on an forensic investigation came across WeChat desktop app for OSX. To determine if any user data resides in an macOS High Sierra system,interesting databases were found to be located in the directory
/Users/UserName/Library/Containers/com.tencent.xinWeChat/Data/Library/Application Support/com.tencent.xinWeChat/2.0b4.0.9/5b5a7aaccfd17d9d0d535b56fa66abeb/Message/

But the DB’s seem to be encrypted with SQLCipher. Anyone have any idea on how to decrypt the DB’s.

Thanks In advance ) ) )


   
Quote
UnallocatedClusters
(@unallocatedclusters)
Honorable Member
Joined: 13 years ago
Posts: 576
 

ForensicFocus member gorvq7222 might be a good resource for WeChat - I would PM him.


   
ReplyQuote
Share: