Last week a key ransomware threat actor was arrested in Kiev, Ukraine.

I wondered if it was possible to do a little geolocation and find out where he was living the high life.

The source video is the official release from the Ukranian Police:

Using YouTube-dl to download the video and FFMPEG to split into a series of stills makes finding clues a little easier.

(Guide here: nixintel.info/osint-tools/us…)

You can also use Frame-by-Frame to do this in your browser (HT @salaheldinaz)

watchframebyframe.com/watch/yt/I20fa…
Here are the key images with exterior detail:

1) Yellow/Green pipe construction outside.
2) "Autograph" sign on the wall. ImageImage
So we know the building is in Kiev - but where?

A search for businesses called "Autograph" only brings one plausible match in Kiev - a beauty salon on Yevhena Konvaltsia Street.

g.page/autographfashi…

Verifying the location is not so easy though...
The Google Street View coverage is 6 years out of date. Here's where Autograph should appear.

We need to find an alternate image source. Image
Mapillary often has coverage where Street View does not. Here's the location in 2019.

The distinctive yellow pipe and tall background buildings are very similar the ones in the arrest video. ImageImage
Business Facebook pages can also be useful for localised images. This is from the Autograph salon Facebook page.

The sign from the police video is in the green square. The orange arrow is likely the door they entered through. ImageImage
There might be little Street View coverage, but photos uploaded to Google Maps help to fill the gaps with local detail.

Here's the perfect picture that explains the yellow/green pipes in the first frame of the video:

google.com/maps/@50.42719… ImageImage
Notice the green pipes/slide reflected in the window when the police enter the apartment block. Image
So all this means that the arrested ransomware suspect was living in the "Aristocrat" apartment complex in Kiev. Image
Apartments there currently selling for the equivalent of beween $170k and $220k.

(Avg UKR salary is approx $700 US per month)

blagovist.ua/eng/search/apa…

(There might be another one for sale very soon...)

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with nixintel

nixintel Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @nixintel

24 Jul 20
[THREAD] OSINT/Opsec tip:

Twitter accounts list profiles that they are following / followed by in chronological order.

The first few accounts that a Twitter user chooses to follow offer a great insight into who the account might belong to.
So if I want to know who might be associated to a Twitter account, looking at the fist 5-10 accounts they chose to follow offer more insights than, say, the 500th account they chose to follow.
Where the same few Twitter accounts appear early on in both followed/following lists this indicates a higher chance of prior association. Why did you choose to follow the first Twitter accounts in your Followed list? Chances are you had some prior interest/association.
Read 5 tweets
29 May 20
THREAD: #Geolocation of images taken indoors is infinitely more difficult than geolocating those taken outside, but there are still some resources that can help. Time for some real #OSINT nerdery looking at how plug sockets can help with geolocating an indoor image...
There are 14 different types of plug socket in use around the world. They are categorised from A to N:
Some are very common, being used in a wide range of countries. One legacy of Britain's past is that many former colonies still use the same plug socket as mainland UK (Type G, in case you didn't know...)

iec.ch/worldplugs/typ…
Read 7 tweets
28 Feb 20
THREAD: This evening's disturbances at #Paris Gare de Lyon show the importance of acting quickly to gather real-time #OSINT information.

There are lots of resources for doing this, but Snapchat Map is one of the most useful:

map.snapchat.com
2) Snapchat Map displays near-live time videos that are all geotagged and which can be accessed without the Snapchat app via a web browser.

Here's #Paris about 20 mins ago. Hotspots indicate a lot of uploads:
3) The videos are only visible for a short while before being removed from the map. The need to geotag the videos and their short lifespan makes them slightly less susceptible to being faked than on some other platforms.

Click on a hotspot to start viewing videos from that area:
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(