February 22, 2024 · 3 min read
On February 20th, the FBI and the U.K.’s National Crime Agency (NCA) Cyber Division reveiled the product of a years-long investigation they carried out on the ransomware group Lockbit. As a result, the individual Ivan Gennadievich Kondratyev, a.k.a. “Bassterlord” has been added to OFAC’s SDN list (an international sanctions list).
The official release gives us an email address for the individual, which triggered Predicta Lab’s @fs0c131y to pull the thread of open source investigation. Hence this article summarizes his thread where we see how much information can Predicta Search lead us to when starting with that email.
Let’s investigate !

According to Jon Di Maggio from Analyst1:
First things first, I searched the email [email protected] on predictasearch.com. It gives us a lot of online profiles.

In the data breaches tab of the report, we can see that his email was in a Twitter leak. It gives us his Twitter handle @It9111

The email is also in the 000webhost leak (2015) and it gives the following location in Bryanka, Luhansk Oblast, Ukraine

Also, he has a ok.ru profile linked to this email.
It gives us a new user name, a date of birth, a location and one of his previous school.

A user with the same name as the ok.ru profile left a reviewabout a dental clinic in Новомосковск.

The ok.ru profile states that he lives in Алексинский район. The dental clinic address is Россия, Тульская область, Новомосковск, Комсомольская улица, 36/14, 1 этаж.
This is pretty close!
In multiple leaks his personal address is available: Россия, Тульская обл, Новомосковский р-н, г Новомосковск, 301664, Маяковского ул, д. 10/2, кв. 59. And yes, it’s a 12 min walk to go the dental clinic.

This is why I love OSINT ! In multiple online profiles our guy used the name “Koyerd Uhvwi”. If you search this name, you find this Youtube channel.

If you go to the playlist tab, you will find an unlisted video. Look who has a nice new Lockbit tatoo!
After a bit more digging around in the leaks, a friendly Twitter user found his VK profile which, although it is now deleted, can be found in its older versions on the archiver vk.watch. A lot of infos can be found there : his name and DOB are identical to those we found in the leaks previously.

We can also find that our friend was looking for love. Face, name, age and region are consistent with what we found before.

With the help of the @PredictaLab relational graph, we mapped (almost) all the info found during our investigation:

This brief investigation shows how much information can be obtained from a single look up on Predicta Search and how quickly you get to an overview of the digital footprint attached to it.
THE END
Get the latest OSINT news, monthly recaps and product updates in your inbox.

August 29, 2024 · 3 min read
A second sequence of open-source discoveries leading from the hacker USDoD's Twitter profile to his real-life identity.

August 28, 2024 · 4 min read
Last week CrowdStrike revealed the identity of the famous hacker USDoD and today we will retrace how he was discovered with an open source investigation of our own.

May 15, 2024 · 4 min read
On May 7, 2024, the Office of Foreign Assets Control along with other american government agencies revealed several pieces of information about LockBit’s leader, Lockbitsupp. Let’s see what we can find out about him using this information.

December 1, 2021 · 4 min read
The New York Times reported that the amount of weekly flights from Middle Eastern locations to Minsk doubled from October to November 2021. Predicta Lab retraces this analysis step-by-step in order to verify the veracity of its findings.