# Identifying the owners, administrators and developers of web resources Igor Bederov · T.Hunter, Internet-Rozysk MOSCOW FORENSICS DAY ’25 · Day 1 — Thursday, 11 September 2025: digital forensics day · Scheduled 16:45–17:05 · In the recording 03:53:37–04:11:57 Talk summary · https://2025.moscow-forensics-day.workers.dev/en/summary/10-bederov Transcript: https://2025.moscow-forensics-day.workers.dev/en/transcript/10-bederov · Slides: https://2025.moscow-forensics-day.workers.dev/en/slides/09-bederov-vladelcy-veb-resursov · Watch from 03:53:37: https://youtu.be/4V7Wez3L_58?t=14017 --- ## In brief A how-to guide on OSINT: how to get to a site's owner, administrator and developer through the domain, the hosting, DNS, the content and the traffic. WHOIS is unreliable after GDPR, but there are plenty of side traces. A condensed version of an hour-and-a-half lecture for security services and investigators: ≈17 minutes, there were no questions from the audience. ## Key points - USB Type-C will be dropped from smartphones — forensics will have "simply nothing left" to plug into, and what will grow is data analysis. The roles: the owner (domain, hosting), the administrator (content), the developer (the engine). A portable Opera from T.Hunter: runs from a USB stick, "more than 2,000 sources", mostly free. - WHOIS has degraded: domains are "registered extremely sloppily", and after GDPR it says "a private person". The way out: WHOIS archives, the services on the slide. - "A bit off-topic": in August the Supreme Court of the Russian Federation, according to the speaker, obliged business to detect typosquatting and fraud on its own. Free of charge: DNSTwister, DNSTwist, a third one (not made out); IntelX, Have I Been Pwned — leaks involving the domain. - Cloudflare was created against DDoS, but it is "actively used by offenders"; "you can't always" strip it away: URLScan and VirusTotal (they indexed it earlier), "leaks of Cloudflare itself", DNS, verification in Yandex and Google, acquiring services, reuse of SSL and favicon. - DNS records hold the linked servers: some of them outside Cloudflare, some of them inside Russia — drug-trafficking and disinformation ones, "we came across quite a lot of that". October 2021: during the outage of a social network "banned and designated terrorist in Russia" he was getting in "to the IP address". - Contacts — in the body of the site and in leaks: archived WHOIS, "millions-strong leaks" on the domain (the email pattern, names, passwords); guessing by the pattern office, contact, admin, support, HR, PR with an SMTP check. - Files — VirusTotal and dorks, the metadata is what is valuable. A 2025 case: a site against a competitor, pictures taken on an iPhone — the geolocation turned out to be the suspect's home address. Also robots.txt, sitemap.xml and "the utterly trivial InfoApp application" by way of a VKontakte group — the admins. - The marketing add-ons (acquiring services, chatbots, analytics counters, advertising codes) are "a huge minus" for the owner. Metrica: "about 10%" of counters are public, and Yandex support discloses the email address by the identifier. Acquiring — "you can contact the bank" for the recipient. Web archives — the old code, contacts, "even files". - Petitions are "almost always" inflated by bots, but the author does the first seeding himself — they look for who was the first to post the link. The figure "in about 70–80%" was spoken, but what it refers to is unclear. ## Tools, artifacts, technologies - **A portable Opera (T.Hunter)** — free, the link is on the slide; **WHOIS** is criticized, **WHOIS archives** are recommended (the services are on the slide), ICANN — in passing. - **DNSTwister, DNSTwist** (+ a third one, not made out), **IntelX, Have I Been Pwned** — free; URLScan, VirusTotal, "leaks of Cloudflare itself" — bypassing Cloudflare. - Artifacts: DNS records, the SSL certificate, favicon, file metadata, robots.txt, sitemap.xml; ping, an SMTP check, dorks (examples on the slide). - **Yandex.Metrica**, **acquiring** — deanonymization; InfoApp (VKontakte) — by ear; chatbots, forms, advertising codes, web archives (the names were not spoken). ## Legal and organizational context - The Supreme Court of the Russian Federation, August: according to the speaker, "obliging commercial entities to detect typosquatting on their own, and online fraud"; the details of the act were not named. GDPR is the reason personal data disappeared from WHOIS; ICANN — in passing. - Yandex support approached on behalf of an administrator who "forgot which email is linked", and a request to the bank about the acquiring service — working techniques (in the conference-wide summary — pretexting). The case was "an invasion of privacy"; there are no references to the Code of Criminal Procedure or the Criminal Code. ## Questions from the audience There were no questions. The moderator: "Igor, you've apparently fired up the audience so much that it's all perfectly clear now" — applause, and on to the "roast". "No doubt about that" — by the context the moderator, the attribution is not obvious. ## The speaker's position OSINT is an equal neighbor of forensics. He names the limitations himself; the path is "not quite a linear story". The tone is a checklist with self-irony and two slides about his own browser. ## Quotes - "…domain names being registered extremely sloppily, the owners' details are not verified…" - "…Cloudflare is actively used by offenders to hide the actual location of their site." - "…for reconnaissance on domain names and sites it's, of course, a huge minus." - "Just ask them for a hint: I'm the site administrator, I forgot which email is linked to this Yandex.Metrica counter…" ## Closing of the online part of day 1 The moderator Dmitry Yankovoy says goodbye to the online viewers until day 2 and invites those present in the room "to the bar area". The "roast", the prize draw and the informal part were not streamed; what follows is day 2, after a pause in the recording.