In this study, we provide a descriptive explanation of the discovery of artifacts related to digital forensic evidence in the instant messenger applications WhatsApp and Telegram. We also try to obtain evidence containing information that is crucial for forensic analysis when investigating a cybercrime case that occurred in WhatsApp and Telegram applications based on Android OS. Experiments were carried out to obtain digital evidence in this study, by simulating the exchange of conversations from the victim with the perpetrator of an online crime in the case of fraudulent buying and selling of goods online, which then from the results of the experiment will obtain data such as the type of message sent, contact info user, timestamps chronology of conversations sent, etc.