Wickr Messenger Extraction And Decryption In Oxygen Forensic Detective

Wickr Messenger allows users to exchange end-to-end encrypted and content-expiring messages, and make end-to-end encrypted video conference calls. Wickr is regularly mentioned in various Internet sources as a secure messaging app. Let’s have a look at these secure features and at how Wickr data can be extracted from mobile devices, cloud, and PC. The first one that often makes it stand out among other Messengers, is the ability to be anonymous. Registration is done via username, and a phone number is not necessary. Contacts can be gathered through sending invitations to phonebook contacts.

The second, and in fact the most important feature, is message expiration. There are two expiration settings in Wickr. The first one is called the Expiration Timer that sets the life span of every message from 6 hours to 6 days; after this allotted time the message will disappear from the device. The second option is called Burn-On-Reader Timer that can be set from 3 seconds to 6 days. It sets the amount of time after a recipient views the content before it is destroyed on the receivers device. The time starts counting as soon as content is marked as "read" but will never extend the life of the content beyond the destruct time determined by the "Expiration" value. In both cases the Expiration Timer and Burn-On-Reader Timersettings can be also custom.

Bad news for investigators – all the user content is really wiped from the device after it expires so there are no traces to recover them currently.

Among other secure features of mention there is also screenshot detection. This feature can inhibit the recipient of making a screenshot of the transferred information. Furthermore, all data is (at rest and transit) encrypted with AES256. As if this was not secure enough, if “Require Authentication” option is enabled the messenger will ask for a password every time a user opens it.

There are several types of Wickr – Wickr Me for home users and Wicr Pro for businesses. Oxygen Forensic Detective focuses on the home user version.


Get The Latest DFIR News

Join the Forensic Focus newsletter for the best DFIR articles in your inbox every month.


Unsubscribe any time. We respect your privacy - read our privacy policy.

With all the security features mentioned it is no surprise that Wickr was reported to be a preferred tool by Islamic State (IS) as well as by drug dealers and users sharing child abuse images.

We at Oxygen Forensics do our best to extract the maximum amount of evidence even from this challenging app. So what can we can do with Wickr Me.

Wickr Me running on mobiles devices

Currently we do not support Wickr extraction from Apple iOS devices as the encryption key is stored in the inaccessible part of keychain but we are planning to add access to it and implement Wickr iOS decryption in an upcoming version. However, Oxygen Forensic® Detective fully supports Wickr Me decryption from Android devices acquired via physical extraction. The extracted evidence set will include account information, contacts, calls, private and group messages but only for a maximum 6 days.

Wickr from the cloud

Oxygen Forensic® Cloud Extractor offers the exclusive ability to extract data from Wickr cloud via username\password or token extracted from Android device (Please note that Wickr cloud has no 2FA). The evidence set will vary depending on the authorization method.

If username and password are used the software will only extract the account information, connected devices and contacts.
If the Wickr token is available from the extracted data of the Android device or found on PC by our Oxygen Forensic® KeyScout it will give also access to chats (maximum for the last 6 days), shared coordinates and calls. This wider access can be explained by the fact that chats are bound to the particular devices so only using a token gives access to them from the cloud.

Please note that you can access both Wickr Me and Wickr Pro accounts in our Oxygen Forensic® Cloud Extractor.

Wickr from PC

Oxygen Forensic® KeyScout can collect both user data and credentials from Wickr Me installed on Windows-based PC. The Messenger data is encrypted and the app has a password that is used for encryption. Oxygen Forensic® KeyScout offers several methods of decryption.

User data will be decrypted if:

1. If any password found by KeyScout on PC fits the one to Wickr Me.
2. A password to access the Messenger was saved in the app.
3. If during data collection the app was running.

Extracted evidence set will include the account info, contacts, calls, private and group messages with attachments and the token. Please note that due to the Wickr expiration feature messages within maximum 6 days can be extracted. There are certain cases where we can extract older messages. For example, if a message was sent 15 days ago but Wickr Messenger was not launched for 10 days the older messages are available for extraction by KeyScout. However, once the app is open, and the password for Wickr is entered, the app will wipe these expired messages from its databases.

As you see from the information above, Wickr Messenger extraction is often challenging.

The main challenges are:

• message expiration that cannot be overcome
• data encryption that often changes.
• data bound to the device means a token is needed and without that little data can be extracted from the cloud service.

Do not panic! Oxygen Forensics Inc will do our best to have you covered.

Leave a Comment

Latest Videos

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data. 

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

Subscribe to the Forensic Focus Podcast: https://www.forensicfocus.com/podcast/

Si and Desi are joined by Brittany and Ailsa from digital forensics software company ADF Solutions. They discuss how ADF is addressing key challenges for digital forensics practitioners, including handling the massive volumes of data from mobile devices and the cloud.

The guests outline ADF's focus on developing their software as an easy-to-use onsite triage tool that can help quickly identify pertinent evidence. Key features include advanced handling of video files, AI-assisted classification of images, and new screen recording capabilities for mobile devices that allow suspects to safely share relevant data.

The hosts and guests also explore ADF's ongoing research into areas like facial recognition, handling new device types like games consoles and smart watches, and identifying deepfake media.

00:00 – Introduction to Ailsa and Brittany
03:00 – The challenge of vast amounts of data
05:50 – Recovering data from Chromebooks
08:50 – Triaging using ADF tools
12:30 – Benefits of using ADF Solutions’ tools
15:50 – Limitations in types of apps
17:20 – Keeping up with technological advancements
19:15 – ADF customer base
21:00 - Artificial intelligence in classifying images
30:00 – ADF Solutions’ triaging kit
37:00 – Training with ADF
40:00 – Target user
44:50 – Roadmap of future devices to examine
51:30 – Main focus for ADF Solutions going forwards

Show Notes:
AI-generated CSAM article on Sky News - https://news.sky.com/story/thousands-of-ai-generated-child-abuse-images-being-shared-online-research-finds-12991727

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_4z-EgH54KZk

The Power Of Digital Forensics: How ADF Solutions Is Revolutionizing The Digital Forensics Industry

Forensic Focus 12 hours ago

Si and Desi interview Emi Polito from Amped about how to become an Amped FIVE Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification 

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

Si and Desi interview Emi Polito from Amped about their new certification called Amped Five Certified Examiner (AFCE). They discuss the exam requirements, format, timeline for certification, and Amped’s future plans. Emi explains that the certification is aimed at demonstrating competency with the Amped FIVE video analysis software after completing training. The exam consists of multiple choice questions on theory and practical exercises using the software. Emi talks about the online exam format and process for passing or failing.

Emi also discusses the broader challenges many organizations face with validation and accreditation. He emphasizes Amped's commitment to developing tools that facilitate that process. The hosts reflect on the confusing accreditation landscape and Amped’s passion for improving training and certification in forensics. This episode provides an overview of Amped's new certification and perspective on challenges in the field of video forensics.

Show Notes:

Introducing The AFCE Certification (Amped FIVE Certified Examiner) - https://www.forensicfocus.com/news/introducing-the-afce-certification-amped-five-certified-examiner/

Video Evidence Principles With Amped Software - https://www.forensicfocus.com/podcast/video-evidence-principles-with-amped-software/

Digital Image Authenticity And Integrity With Amped Authenticate - https://www.forensicfocus.com/podcast/digital-image-authenticity-and-integrity-with-amped-authenticate/

File Analysis And DVR Conversion Training From Amped Software - https://www.forensicfocus.com/reviews/file-analysis-and-dvr-conversion-training-from-amped-software/

Amped FIVE Speed Estimation 2d Filter And Training From Amped Software - https://www.forensicfocus.com/reviews/amped-five-speed-estimation-2d-filter-and-training-from-amped-software/

Amped Software’s Martino Jerian on Key Challenges and Opportunities for Video Evidence - https://www.forensicfocus.com/podcast/amped-softwares-martino-jerian-on-key-challenges-and-opportunities-for-video-evidence/

LEVA 2023 Training Symposium - https://www.leva.org/

Forensic Collision Investigation & Reconstruction Ltd - https://www.fcir.co.uk/

Amped FIVE Certified Examiner - https://ampedsoftware.com/afce-certification

Introducing the Amped FIVE Certification Program - https://blog.ampedsoftware.com/2023/10/04/introducing-the-amped-five-certification-program

Amped Software YouTube - https://www.youtube.com/ampedsoftware
How to Use the Validation Tool in Amped FIVE - https://blog.ampedsoftware.com/2023/03/29/how-to-use-the-validation-tool-in-amped-five

YouTube Video UCQajlJPesqmyWJDN52AZI4Q_atEaNas9xnE

The Amped FIVE Certified Examiner (AFCE)

Forensic Focus 29th November 2023 10:28 am

This error message is only visible to WordPress admins

Important: No API Key Entered.

Many features are not available without adding an API Key. Please go to the YouTube Feed settings page to add an API key after following these instructions.

Latest Articles