Facebook Messenger analysis

Facebook Messenger is a messaging app separate from the main Facebook application. It has over 500,000,000 downloads in the Play Store.

Package name: com.facebook.orca

Version: 18.0.0.27.14

Files of interest:

  • /cache/
    • audio/
    • fb_temp/
    • image/
  • /sdcard/com.facebook.orca
  • /files/ rti.mqtt.analytics.xml
  • /databases/
    • call_log.sqlite
    • contacts_db2
    • prefs_db
    • threads_db2

The /cache/audio directory contains audio messages sent through the application. The files have a .cnt file extension, but are actually .riff files that can be played with Windows Media Player, VLC media player, and other programs.

The /cache/fb_temp path contains temp files for images and video sent through the application. It is unclear how long these files will remain. In our ...

Get Learning Android Forensics now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.