Skype analysis

Skype is a voice/video calling app, as well as a messaging app owned by Microsoft. It has over 100,000,000 installs on Google Play.

Package name: com.skype.raider

Files of interest:

  • /cache/skype-4228/DbTemp
  • /sdcard/Android/data/com.skype.raider/cache/
  • /files/
    • shared.xml
    • <username>/thumbnails/
    • <username>/main.db
    • <username>/chatsync

The /cache/skype-4228/DbTemp directory contained multiple files with no extension. One of these files (temp-5cu4tRPdDuQ3ckPQG7wQRFgU on our device) was actually a SQLite database that contained the SSID and MAC of wireless access points it had been connected to.

The SD card path will contain any images or files received in a chat. If a file is downloaded, it will be in the Downloads folder in ...

Get Learning Android Forensics - Second Edition now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.