International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 184 - Number 32 |
Year of Publication: 2022 |
Authors: Trisna Irawan, Imam Riadi |
10.5120/ijca2022922394 |
Trisna Irawan, Imam Riadi . Mobile Forensic Signal Instant Messenger Services in Case of Web Phishing using National Institute of Standards and Technology Method. International Journal of Computer Applications. 184, 32 ( Oct 2022), 30-40. DOI=10.5120/ijca2022922394
The increasing online dependence of the entire world creates opportunities for cybercrime to occur. One of the problems with instant messaging applications that trigger phishing cybercrimes is the Signal application.Phishing is a criminal activity that uses social engineering techniques.The purpose of this study is to carry out a forensic process on an android smartphone in the form of a web phishing case using the National Institute of Standards and Technology (NIST) method to obtain digital evidence on the Signal Instant Messenger application.This study uses the NIST method with four forensic stages, namely collection, examination, analysis, and reporting. Forensic tools used to collect digital evidence are MOBILedit Forensic Express Pro and Belkasoft Evidence Center. The process in obtaining evidence is by making acquisitions of two smartphones. The acquisition results are used as digital evidence to prove the occurrence of crimes that lead to web phishing cases.The results of this study show that the MOBILedit Forensic Express Pro and Belkasoft Evidence Center tools obtained evidence from the first smartphone in the form of contacts, account phone numbers, text messages, and picture messages. Meanwhile, the second smartphone did not get the expected evidence, either using the MOBILedit Forensic Express Pro or Belkasoft Evidence Center tools, because the smartphone was not rooted and the security of the encrypted storage device system failed at the acquisition stage for digital evidence retrieval.It is hoped that further research will be able to acquire on smartphones the state of the data intentionally or accidentally deleted by the perpetrators and be able to acquire the latest android version.