Burner - Android
Application | Burner |
Version | 7.24.0.3642.3605452 |
Device | Samsung Galaxy A16 5G [SM-S166V] |
Android Version | 16 |
Build Number | BP2A.250605.031.A3 |
For this round of testing, I chose the application, "Burner." Burner describes itself as "The original second phone number app, built to maintain your privacy, organize your social circles, and protect your anonymity." Burner functions similarly to other "second phone number" apps that allow a user to send/received calls and text messages from a phone number other than the one assigned by their cellular provider.
On Android devices, the Burner package is found at data/data/com.adhoclabs.burner.
Inside, you will find several subdirectories:

Part of the way through my creation of the test data, I switched to a new Burner phone number to see what this would do to the data. When I did this, Burner stated that it would delete all of the conversation/call history associated with my old Burner number. This did delete the messages and calls that were visible to me on the phone, but after reviewing the data extracted from the device I am able to see that the "deleted" messages associated with the old phone number are still present in the database. I will go into better detail later.
It is unknown how long this data remains in the database after it is "deleted." Further testing on this may be completed at a later time.
The bulk of the useful data is within the database at com.adhoclabs.burner/databases/db-burner.
BurnerEntity - provides information about the account.
dateCreated - unixepoch time that the phone number became active on the account
expirationDate - unixepoch time the number expires (appears to be set approxiamtely 31 days after the dateCreated
id - GUID specific to a phone number - this will change if the phone number is changed
incomingCallNumberDisplay - this has two options:
BurnerNumber - "If your Burner number is saved as a contact, the contact name will show as the caller ID"
CallerNumber - "If the caller's number is saved as a contact, the contact name will show as the caller ID"
name - Name given by the user for the burner number (often "Virtual" by default)
notifactionsEnabled - 1 (True), 0 (False)
phoneNumber - Burner number assigned to the id (see above)
My previous Burner phone number (prior to switching numbers) was not listed in the BurnerEntity table. From previous testing, I know that a user can have two phone numbers assigned to their account. If the user has multiple active phone numbers, they will both appear hear with their associated GUIDs. It appears however that if the phone number is simply "switched," then the only GUID and phone number that will be provided is the most recent one. The calllog.db (data/data/com.samsung.android.providers.contacts/databases/calllog.db) can assist in identifying the Burner number however. More on this later.
ConversationMessageBoundaryEntity
This table appears to show a list of conversations the Burner account had and will include previous GUIDs, but not their phone numbers.
burnerID - This is the GUID associated with a phone number (see id from the BurnerEntity table).
conversationID - other party's phone number associated with the conversation (not the user)
latestDateCreated - In my testing data, for the first number, this shows to be the time I switched to the second number. For the second number, this shows to be the same time as the last interaction between the two (a declined call).
oldestDateCreated - first recorded message between the user and the other party
lastUpdated - for both numbers in the test data, this shows to be shortly (as in milliseconds) after the oldestDateCreated
MessageEntity - This is the table you're looking for
burnerID - This is the GUID associated with a phone number.
dateCreated - timestamp of text message
direction - incoming/outgoing
groupMessageFrom - [Will need to test further]
id - GUID associated with that specific message
lastUpdatedDate - in every single message in the test data, this value is exactly the same as dateCreated (it does not appear messages can be edited in Burner so I'm not sure why this column exists.
mediaUrl - This is a URL in "https://s3.amazonaws.com/burner-mms/prod/[image GUID].jpg" format. This URL can simply be typed into any browswer to view the image
messageType - Text/Voice (Text for any text message even if it's a media file, Voice for call)
read - Was message read? 1 (True), 0 (False)
state - state of the communication
Delivered
CallCompleted
Voicemail
CallMissed
text - text message content
previewText - This is NULL for ever message in the test data
userID - This is the User ID for the entire account (not specific to a phone number). This can also be found in the userID column of the AccountEntity Table
durationMinutes This is the duration in minutes of a call (rounded up to the nearest minute)
conversationID - phone number of the other party involved in the conversation
isGroupConversation - 1 (True), 0 (False)
audioUrl - URL for voicemail (associated with a row containing "voicemail" as the state) in "https://s3.amazonaws.com/burner-voicemail/prod/[voicemail GUID].wav" format. Can be listened to using a browser.
durationSeconds - only appears to be associated with a voicemail. Is the length in seconds of a received voicemail
In com.adhoclabs.burner there is also a directory called "cache." The images in this directory, all with filenames like "Burner_[string of numbers].jpg," appear to all be images sent from the device.
The cache directory also has a subdirectory called "image_manager_disk_cache." Here there are files with a "0" file extension. These files can be opened in a tool such as IrfanView, or my python script can be used to identify the appropriate file extension based on headers/footers. These images are both sent and received images.
Calllog.db
As described above, the calllog.db can assist in identifying the actual call times, the Burner phone number, and the direction (at least on this Samsung device).
When making a Burner call, the calllog.db shows the device to be calling the actual Burner phone number for the account (not the other party). So when viewing the number column of the calls table within calllog.db, that number is the Burner number associated with the account at that time. The date column can be compared to the call times (dateCreated) within MessageEntity to identify the number being used by the Burner account holder at that time.
The duration column also provides a much more accurate call duration in seconds rather than being rounded up to the nearest minute.



Comments