The use of facial recognition in an OSINT investigation
This Russian propaganda Military video posted on Telegram by what seems to be a Chechen Muslim fighter, triggered a full-on OSINT investigation.
You can watch how the investigation unfolds in the comment thread of this tweet:
https://twitter.com/OSINT_Tactical/status/1498694266754899978
This Russian propaganda Military video posted on Telegram by what seems to be a Chechen Muslim fighter, triggered a full-on OSINT investigation.
You can watch how the investigation unfolds in the comment thread of this tweet:
https://twitter.com/OSINT_Tactical/status/1498694266754899978
👍1
Here's how to quickly identify deep fake and diss information on image/video content with publicly available tool:
1️⃣ Reverse image search in Yandex, Google and TineEye reveals facts borrowing content that is not related to the events covered. To simplify the detection of fakes, there is even a special INVID Verification Plugin that connects to Chrome and Firefox browsers.
2️⃣ Examining metadata in Jeffrey's Image Metadata Viewer allows you to find out when, where and from what device a particular photograph was actually taken. Similar service - Image Edited
3️⃣ Identify changes (edits) have been made to the original image with Forensically . An alternative service for this is Ghiro.
4️⃣ Deepfake detection in KaiCatch allows you to detect abnormal facial distortions with 90% accuracy in photos and videos.
1️⃣ Reverse image search in Yandex, Google and TineEye reveals facts borrowing content that is not related to the events covered. To simplify the detection of fakes, there is even a special INVID Verification Plugin that connects to Chrome and Firefox browsers.
2️⃣ Examining metadata in Jeffrey's Image Metadata Viewer allows you to find out when, where and from what device a particular photograph was actually taken. Similar service - Image Edited
3️⃣ Identify changes (edits) have been made to the original image with Forensically . An alternative service for this is Ghiro.
4️⃣ Deepfake detection in KaiCatch allows you to detect abnormal facial distortions with 90% accuracy in photos and videos.
How to investigate and detect users identity on Telegram
Here are the search criteria, methodologies and sources that will allow you to identify users on Telegram:
ID:
@userinfobot (Find ID)
@CheckID_AIDbot (Find ID)
@username_to_id_bot (Find ID)
Phone Number:
checker (Phone Checker)
TgAnalyst_bot (Find Phone)
eyeofgod (Find Phone)
@anonimov_bot (Find Phone)
Name OR Nickname:
@maigret_osint_bot (Find Nickname)
whatsmyname (Find Nickname)
mail (Find Name)
Avatar Photo:
search4faces (Find Photo)
findclone (Find Photo)
yandex (Find Photo)
Participation in Chats:
@telesint_bot (Find Chats)
@tgscanrobot (Find Chats)
TelegramScraper (Chats Parser)
TeleParser (Chats Parser)
TG-Parser (Chats Parser)
Text & Messages:
commentgram (Find Messages)
telegago (Find Messages)
Location Data:
@locatortlrm_bot (Check Location)
telegram-nearby (Check Location)
IP & Device:
@FindStickerCreatorBot (Sticker Author)
canarytokens (Check IP)
iplogger (Check IP)
Here are the search criteria, methodologies and sources that will allow you to identify users on Telegram:
ID:
@userinfobot (Find ID)
@CheckID_AIDbot (Find ID)
@username_to_id_bot (Find ID)
Phone Number:
checker (Phone Checker)
TgAnalyst_bot (Find Phone)
eyeofgod (Find Phone)
@anonimov_bot (Find Phone)
Name OR Nickname:
@maigret_osint_bot (Find Nickname)
whatsmyname (Find Nickname)
mail (Find Name)
Avatar Photo:
search4faces (Find Photo)
findclone (Find Photo)
yandex (Find Photo)
Participation in Chats:
@telesint_bot (Find Chats)
@tgscanrobot (Find Chats)
TelegramScraper (Chats Parser)
TeleParser (Chats Parser)
TG-Parser (Chats Parser)
Text & Messages:
commentgram (Find Messages)
telegago (Find Messages)
Location Data:
@locatortlrm_bot (Check Location)
telegram-nearby (Check Location)
IP & Device:
@FindStickerCreatorBot (Sticker Author)
canarytokens (Check IP)
iplogger (Check IP)
❤1👍1🔥1
The Russian government has released a list of 17,576 IP addresses that were allegedly used to launch distributed denial of service (DDoS) attacks targeting Russian organizations and their networks.
Many of the IP addresses are owned by resident Internet users who could face legal charges if their government decides not to turn a blind eye to their cyber activity.
Read information security measures.
Many of the IP addresses are owned by resident Internet users who could face legal charges if their government decides not to turn a blind eye to their cyber activity.
Read information security measures.
How to track unfolding events in Russia-Ukraine war.
The Russia-Ukraine Monitor Map is a crowdsourced effort to map, document and verify information in order to provide reliable information for policymakers and journalists of the on-the-ground and online situation in and around Ukraine.
https://maphub.net/Cen4infoRes/russian-ukraine-monitor
The Russia-Ukraine Monitor Map is a crowdsourced effort to map, document and verify information in order to provide reliable information for policymakers and journalists of the on-the-ground and online situation in and around Ukraine.
https://maphub.net/Cen4infoRes/russian-ukraine-monitor
How to analyze videos on YouTube using OSINT tools.
YouTube is the most popular video hosting platform in the world, and knowing how to extract additional information about a video or it's origin can be very useful for combating fake news and documenting offenses.
Keep in mind, to identify fake photos/videos we published a separate selection https://t.me/espyOSINT/7
1️⃣ youtube-metadata (Metadata Analysis)
2️⃣ citizenevidence (Metadata Analysis)
3️⃣ invid-verification (Browser Extension)
4️⃣ anilyzer (Frame-by-frame Playback)
5️⃣ watchframebyframe (Frame-by-frame Playback)
6️⃣ youtube-geofind (Search by Geolocation)
7️⃣ savefrom (Download Video)
8️⃣ truepic (Video Authentication)
YouTube is the most popular video hosting platform in the world, and knowing how to extract additional information about a video or it's origin can be very useful for combating fake news and documenting offenses.
Keep in mind, to identify fake photos/videos we published a separate selection https://t.me/espyOSINT/7
1️⃣ youtube-metadata (Metadata Analysis)
2️⃣ citizenevidence (Metadata Analysis)
3️⃣ invid-verification (Browser Extension)
4️⃣ anilyzer (Frame-by-frame Playback)
5️⃣ watchframebyframe (Frame-by-frame Playback)
6️⃣ youtube-geofind (Search by Geolocation)
7️⃣ savefrom (Download Video)
8️⃣ truepic (Video Authentication)
❤1
Coinbase, one of the most popular cryptocurrency exchange platforms, has announced that it is blocking access to over 25,000 blockchains -addresses associated with Russian individuals and legal entities. Earlier, representatives of Binance and Coinbase added that while they will not block all Russian accounts on their platforms, cryptocurrency exchanges will take steps to identify all sanctioned entities and individuals and block their accounts and transactions.
https://blog.coinbase.com/using-crypto-tech-to-promote-sanctions-compliance-8a17b1dabd68
https://blog.coinbase.com/using-crypto-tech-to-promote-sanctions-compliance-8a17b1dabd68
New tool for Twitter followers/account link analysis
We got a tip for a new online tool by Brian Deterling called Tweepdiff. Using this tool anyone can look for followers or accounts that are followed by two or more Twitter accounts. The handy thing is, that no login is required, simply fill in the account names and off you go. https://tweepdiff.com/
We got a tip for a new online tool by Brian Deterling called Tweepdiff. Using this tool anyone can look for followers or accounts that are followed by two or more Twitter accounts. The handy thing is, that no login is required, simply fill in the account names and off you go. https://tweepdiff.com/
Experts Debunk Staged Pre-War ‘Provocation’ in the Donbas
With Russia’s invasion of Ukraine ongoing, it’s easy to forget the flurry of dubious provocations and staged events that appear to have been designed to implicate the Ukrainian armed forces and drum up military aggression in the days before the invasion.
Here's how a group of OSINT experts debunked the staged pre-war ‘provocation’ in the Donbas, using ‘Exploiting Cadavers’ and ‘Faked IEDs’.
With Russia’s invasion of Ukraine ongoing, it’s easy to forget the flurry of dubious provocations and staged events that appear to have been designed to implicate the Ukrainian armed forces and drum up military aggression in the days before the invasion.
Here's how a group of OSINT experts debunked the staged pre-war ‘provocation’ in the Donbas, using ‘Exploiting Cadavers’ and ‘Faked IEDs’.
How To Find Timestamps For Verification Across Websites, YouTube, Instagram and Twitter
Being able to prove exactly when data was posted to the internet is a core skill for OSINT investigators.
Here is a quick guide on how to verify and prove when a video was first uploaded, when an account was created, or when an editorial change was made to a website, with as much precision as possible.
https://nixintel.info/osint/how-to-find-timestamps-for-verification/
Keep in mind, to identify fake photos/videos we published a separate selection https://t.me/espyOSINT/7
For investigating YouTube videos, we published a separate selection as well https://t.me/espyOSINT/12
Being able to prove exactly when data was posted to the internet is a core skill for OSINT investigators.
Here is a quick guide on how to verify and prove when a video was first uploaded, when an account was created, or when an editorial change was made to a website, with as much precision as possible.
https://nixintel.info/osint/how-to-find-timestamps-for-verification/
Keep in mind, to identify fake photos/videos we published a separate selection https://t.me/espyOSINT/7
For investigating YouTube videos, we published a separate selection as well https://t.me/espyOSINT/12
KillNet claim they hacked a database of SBU officers
This group of hackers claim they were able to access a database of SBU officers who are involved in crimes and torture in Donbas.
According to the hackers on their channel, they managed to get the following:
1️⃣ Database - 49.497 people (full file).
2️⃣ Secret documents about special operations in Donbas.
3️⃣ Measures of actions against political prisoners.
4️⃣ Registry of the right sector UNSO (banned in Russia).
This group of hackers claim they were able to access a database of SBU officers who are involved in crimes and torture in Donbas.
According to the hackers on their channel, they managed to get the following:
1️⃣ Database - 49.497 people (full file).
2️⃣ Secret documents about special operations in Donbas.
3️⃣ Measures of actions against political prisoners.
4️⃣ Registry of the right sector UNSO (banned in Russia).
🔥1
How to obtain subdomains and search for open ports.
Fast and reliable python script that makes active and/or passive scan to obtain subdomains and search for open ports. Used 21 different OSINT sources (including AlienVault, ThreatCrowd, Urlscan io etc)
https://github.com/v4d1/Dome
Fast and reliable python script that makes active and/or passive scan to obtain subdomains and search for open ports. Used 21 different OSINT sources (including AlienVault, ThreatCrowd, Urlscan io etc)
https://github.com/v4d1/Dome
How to Archive Telegram Content to Document Russia's Invasion
In recent days, Telegram has been a vitally important tool for documenting the Russian invasion of Ukraine – ordinary Ukrainians regularly post videos and photos attesting to the scale of destruction caused by the war. This material has allowed us to geolocate multiple attacks on civilians and establish the Russian military’s use of cluster munitions.
But the online media environment in Russia and Ukraine at present is highly volatile. Archiving content from the ground ensures it can still be used by researchers if a user deletes a post, if a channel is removed, or if an entire platform becomes inaccessible.
For any type of internet content, links stop working over time, a phenomenon known as “link rot.”
Here is how to archive content so it can be preserved for years.
In recent days, Telegram has been a vitally important tool for documenting the Russian invasion of Ukraine – ordinary Ukrainians regularly post videos and photos attesting to the scale of destruction caused by the war. This material has allowed us to geolocate multiple attacks on civilians and establish the Russian military’s use of cluster munitions.
But the online media environment in Russia and Ukraine at present is highly volatile. Archiving content from the ground ensures it can still be used by researchers if a user deletes a post, if a channel is removed, or if an entire platform becomes inaccessible.
For any type of internet content, links stop working over time, a phenomenon known as “link rot.”
Here is how to archive content so it can be preserved for years.
Hackers compromised critical US infrastructure
Hackers from a group with the ironic name Ragnar Locker have compromised the networks of at least 52 organizations among critical US infrastructure. The government, energy, financial and IT sectors are under threat.
The FBI sent out urgent notices to organizations about possible attacks and requested any information that could lead to the group's trail. It has been operating since 2019, but frequently changing it's methods makes it difficult to catch them.
So for now, the raiders of the 21st century continue their raids.
Hackers from a group with the ironic name Ragnar Locker have compromised the networks of at least 52 organizations among critical US infrastructure. The government, energy, financial and IT sectors are under threat.
The FBI sent out urgent notices to organizations about possible attacks and requested any information that could lead to the group's trail. It has been operating since 2019, but frequently changing it's methods makes it difficult to catch them.
So for now, the raiders of the 21st century continue their raids.
Part of Fotostrana.ru dating service database got leaked
The number of lines is exactly 800 thousand (relevant for 10.2021), which indicates that this a piece of data is certainly part of a more complete drain. The database contains complete information on users:
⭕️ Name;
⭕️ Date of birth;
⭕️ Phone;
⭕️ IP address;
⭕️ VKontakte profile;
⭕️ Odnoklassniki profile;
⭕️ Facebook profile;
⭕️ and other technical information.
The number of lines is exactly 800 thousand (relevant for 10.2021), which indicates that this a piece of data is certainly part of a more complete drain. The database contains complete information on users:
⭕️ Name;
⭕️ Date of birth;
⭕️ Phone;
⭕️ IP address;
⭕️ VKontakte profile;
⭕️ Odnoklassniki profile;
⭕️ Facebook profile;
⭕️ and other technical information.
This media is not supported in your browser
VIEW IN TELEGRAM
Interesting tool for automating Instagram likes, follows, and comments
Go-instabot automates Instagram user following, liking pictures, commenting, and unfollowing people that don't follow you back on Instagram.
It uses the unofficial but excellent Go Instagram API, goinsta (v2).
They claim, that the script is coded so that your Instagram account will not get banned ; it waits between every call to simulate human behavior.
Go-instabot automates Instagram user following, liking pictures, commenting, and unfollowing people that don't follow you back on Instagram.
It uses the unofficial but excellent Go Instagram API, goinsta (v2).
They claim, that the script is coded so that your Instagram account will not get banned ; it waits between every call to simulate human behavior.
New list of countries in which Israeli infosec companies can export their products.
Following NSO's Pegasus incident, The Israeli Ministry of Defense greatly undercut the list of countries in which Israeli infosec companies can export their products.
The new list included only democratic countries, including countries that are members of the EU and Five Eyes. Now the list looks like this: Australia, Austria, Belgium, UK, Bulgaria, Germany, Greece, Denmark, Iceland, Spain, India, Ireland, Italy, Canada, Cyprus, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, New Zealand, Norway, Portugal, Romania, Slovakia, Slovenia, USA, Finland, France, Croatia, Czech Republic, Sweden, Switzerland, Estonia, South Korea and Japan.
https://thehackernews.com/2021/11/israel-bans-sales-of-hacking-and.html
Following NSO's Pegasus incident, The Israeli Ministry of Defense greatly undercut the list of countries in which Israeli infosec companies can export their products.
The new list included only democratic countries, including countries that are members of the EU and Five Eyes. Now the list looks like this: Australia, Austria, Belgium, UK, Bulgaria, Germany, Greece, Denmark, Iceland, Spain, India, Ireland, Italy, Canada, Cyprus, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, New Zealand, Norway, Portugal, Romania, Slovakia, Slovenia, USA, Finland, France, Croatia, Czech Republic, Sweden, Switzerland, Estonia, South Korea and Japan.
https://thehackernews.com/2021/11/israel-bans-sales-of-hacking-and.html
👍1
Attacks on Ukraine's network infrastructure increased tenfold
The number of attacks on Ukraine's network infrastructure has recently increased tenfold, as noted by observational researcher Brian Krebs.
Government networks are under attack by vipers, phishing attacks on mailboxes of civilians and military servants, banks are after a series of DDOS attacks, and providers are being hit in the same way.
All these are just symptoms of the inevitable digitalization of conflicts in the 21st century.
The number of attacks on Ukraine's network infrastructure has recently increased tenfold, as noted by observational researcher Brian Krebs.
Government networks are under attack by vipers, phishing attacks on mailboxes of civilians and military servants, banks are after a series of DDOS attacks, and providers are being hit in the same way.
All these are just symptoms of the inevitable digitalization of conflicts in the 21st century.
Researchers discovered a Trojan-infected apps, that have been installed by at least 9.3 million users
Researchers from Doctor Web studied AppGallery, a standard catalog of applications in Huawei devices, and found dozens of games that contain the Android.Cynos.7.origin Trojan. The infected games have been installed by at least 9.3 million users.
Everything is pretty standard: some harmless app about a cute cat with unexpected access requests to making phone calls and geolocation. The child, quickly approves all the permissions to please himself with the game. Meanwhile, a cute game about another cat is transmitting to a remote server:
⋅ phone number,
⋅ geolocation,
⋅ network code and country code,
⋅ device characteristics,
⋅ parameters from the metadata of applications in which the Trojan is embedded.
It's especially disturbing, since the main target audience of such games is children
Researchers from Doctor Web studied AppGallery, a standard catalog of applications in Huawei devices, and found dozens of games that contain the Android.Cynos.7.origin Trojan. The infected games have been installed by at least 9.3 million users.
Everything is pretty standard: some harmless app about a cute cat with unexpected access requests to making phone calls and geolocation. The child, quickly approves all the permissions to please himself with the game. Meanwhile, a cute game about another cat is transmitting to a remote server:
⋅ phone number,
⋅ geolocation,
⋅ network code and country code,
⋅ device characteristics,
⋅ parameters from the metadata of applications in which the Trojan is embedded.
It's especially disturbing, since the main target audience of such games is children
❤1
Top OSINT Tools for Facebook Investigation
Here are the main sources of data that we use when conducting OSINT research on the Facebook social network:
login (Restore Access)
lookup-id (Find ID)
@usersbox_bot (Search by VK)
@getfb_bot (Search by Phone)
whopostedwhat (Find Posts)
sowdust (Find Posts)
maigret (Find Nickname)
whatsmyname (Find Nickname)
search4faces (Find Photo)
findclone (Find Photo)
yandex (Find Photo)
phantombuster (Parser)
archive (Archive Page)
fuckfacebook (Find Phone)
eyeofgod (Find Phone)
canarytokens (Check IP)
iplogger (Check IP)
facebook.com/browse/fanned_pages/?id=USERID (Find Likes)
facebook.com/friendship/USERID/USERID (Users Connections)
Here are the main sources of data that we use when conducting OSINT research on the Facebook social network:
login (Restore Access)
lookup-id (Find ID)
@usersbox_bot (Search by VK)
@getfb_bot (Search by Phone)
whopostedwhat (Find Posts)
sowdust (Find Posts)
maigret (Find Nickname)
whatsmyname (Find Nickname)
search4faces (Find Photo)
findclone (Find Photo)
yandex (Find Photo)
phantombuster (Parser)
archive (Archive Page)
fuckfacebook (Find Phone)
eyeofgod (Find Phone)
canarytokens (Check IP)
iplogger (Check IP)
facebook.com/browse/fanned_pages/?id=USERID (Find Likes)
facebook.com/friendship/USERID/USERID (Users Connections)
Script for automatically starting Vkontakte conversations
VKMSSG is a python script aimed at creating endless conversations on VKontakte according to the parameters you specified. Can be used as wrapping messages. Can be used to make money on traffic arbitration.
https://github.com/TermuxGodd/vkmssg
Keep in mind, to work with the script, we need 2 accounts - the sender and the addressee. First you need to get the sender token.
VKMSSG is a python script aimed at creating endless conversations on VKontakte according to the parameters you specified. Can be used as wrapping messages. Can be used to make money on traffic arbitration.
https://github.com/TermuxGodd/vkmssg
Keep in mind, to work with the script, we need 2 accounts - the sender and the addressee. First you need to get the sender token.
❤1