OSINT Challenge: The Missing Pieces — Complete Walkthrough
How I Unmasked the Creator Behind TgBash Bot
A Step-by-Step Investigation Walkthrough by D4rk_Intel
Introduction
This document is a complete, transparent walkthrough of my investigation process for the OSINT Challenge: The Missing Pieces by . I will document every search query, every tool, every click, and every thought process that led me from a single Telegram bot handle to a comprehensive digital identity profile.
Why I am writing this: To help other OSINT investigators understand not just what I found, but how I found it — including the dead ends, the pivots, and the “aha” moments.
Call to Action: Solve the Challenge Yourself
The Missing Pieces Challenge link – you can solve the challenge and share your report with me:
https://preciousvincentct.medium.com/osint-challenge-the-missing-pieces-aa6250e46678
After completing the challenge, email your investigation report and entity graph to: cybershieldmentor@gmail.com
I review every submission. The most detailed, well-documented reports may be featured in future community spotlights.
Let me begin.
Pre-Investigation Setup
Before touching any tool, I established my environment:
Item — — — — — — — — — My Setup
- Browser > Google Chrome (clean profile, no extensions)
- Search Engines > Google, Yandex, Bing
- Tools Ready > Sherlock, WhatsMyName, Obsidian
- Documentation > Notion for raw findings, screenshots folder
- OPSEC > Standard browsing, no VPN (all public data)
I also reviewed the 5W1H framework:
- Who: Unknown — starting only with
@TgBash - What: Malicious Telegram bot investigation
- Where: Telegram, GitHub, and associated platforms
- When: Current/past activity
- Why: Identify the creator behind the bot
- How: GitHub OSINT → email pivot → website archive → social correlation
Now, let me walk you through each phase.
Phase 1: The Bot Owner Pivot
My Initial Thought Process
I have one piece of intelligence: @TgBash. The scenario suggests the bot was built using a publicly available phishing framework. In my experience, developers often:
- Post their code on GitHub
- Use the same username across platforms
- Leave the bot handle in code comments or documentation
Step 1.1: GitHub Search
I navigated to github.com and used the search bar with the query:
Result: A single repository appeared: iicc1/TgBash (username: iicc1).
Another simple technique I used was utilizing Google’s advanced search operators. I ran the following query: “TgBash” “Telegram bot” site:github.com
This query led me directly to a GitHub repository containing a collection of Telegram bots arranged for different tasks. From there, I manually navigated through the repository’s contents — scanning the listed bots, examining the README, and reviewing the code comments — until I located the specific entry for the target’s Telegram bot (@TgBash).
The GitHub repository I discovered with the person of interest’s Telegram bot listed was:
Step 1.2: Examining the Repository
With the repository located, I drilled down into its contents for further intelligence collection. A quick assessment of the bot’s scripting language revealed it was written entirely in Shell — evident from the .sh file extensions and the syntax structure throughout the codebase.
Based on my manual review of the repository’s commit history, contributor metadata, and code comments, the primary person of interest was identified as iicc1. The repository also listed additional contributors, whose usernames I documented for further pivoting in later phases.
Observation: The commit history showed multiple commits. The first commit was made by iicc1 alias > Ignacio Iglesias.
I clicked on the first commit to see the author details.
Finding: The commit metadata revealed:
- Author: iicc1
- Email: Null (we will get there)
I also checked Insights → Contributors (GitHub’s built-in feature).
Finding: Two other contributors:
Step 1.3: Extracting Contributor Emails
I clicked into each contributor’s profile and checked their public commits.
- Madji had no public email (set to private)
- TiagoDanin Tiago Danin had a commit with the email: TiagoDanin@outlook.com
Step 1.4: GitHub Account Creation Timestamp
To find when iicc1 Ignacio Iglesias created their GitHub account:
Method 1: I went to https://api.github.com/users/[username] (I customized it with the POI’s GitHub username)
The API returned JSON data. I looked for:
- created_at: “2015–06–30T15:45:44Z”
- updated_at: “2026–04–26T10:30:53Z”
Note: Manually, you can scroll to the bottom of the POI’s GitHub profile page — the join date is displayed there, labeled as “Joined.”
Step 1.5: POI Email Extraction & Provider Check
I attempted to locate the POI’s email address via GitHub API lookup using their repository, but the API did not return any positive feedback — only an earlier email address belonging to a contributor. This was somewhat frustrating.
https://api.github.com/repos/[owner]/[repo]/commits
So I pivoted to an alternative tool: braingainsoft.com. This tool automated the entire process for me. It indeed handled the heavy lifting by significantly reducing the manual effort and time it would have taken me to navigate the POI's repositories manually in search of their email address.
Phase 1 Summary of Answers
Question — — — — — — My Answer
- Bot owner GitHub username: iicc1
- GitHub account creation timestamp: 2015–06–30T15:45:44Z
- Bot owner email address: ignacio.iglesias@hotmail.es
- Two other contributors: Madji, TiagoDanin Tiago Danin
- Contributor email address: TiagoDanin@outlook.com
- External Email provider: Outlook
Phase 2: The Missing Piece
My Thought Process
Now I have ignacio.iglesias@hotmail.es and the GitHub username iicc1. Who is this person? I need to pivot to professional networks and personal websites.
Step 2.1: Email Intelligence Tools
I opened intelbase.is and entered ignacio.iglesias@hotmail.es.
Results:
- No LinkedIn account found (main entity)
- No website found (second main entity)
I then tried holehe (command line):
Output: No registered accounts found on target platforms but gave me a crucial lead > X (Twitter) footprint. Dead end? Not yet.
holehe Output: One crucial lead = POI’s X (Twitter Footprint)Step 2.2: Google Dorking with the Email
I then switched to manual Google searches. Unfortunately, the first query I ran — "ignacio.iglesias@hotmail.es" — returned a significant number of false positives. None of the results were relevant to my investigation or helped me move closer to identifying the person of interest.
Next, I tried narrowing my search using the POI’s GitHub username and alias to see if I could obtain anything of significant value. Unfortunately, I found multiple unrelated profiles. That was when I paused, reflected, and approached my search more precisely.
First query: “iicc1” OR “Ignacio Iglesias” site:linkedin.com
I then utilized the “Forgot Password” technique to verify whether the POI truly had a presence on LinkedIn. It turned out I was right — an account existed.
Second query: -site:linkedin.com “Ignacio Iglesias” “Telecom engineer and dev | Stakely Co-Founder & CTO”
This query gave me a beautiful lead: the POI’s Crunchbase profile with the username > Ignacio Castreño.
This was a solid lead. I gently navigated down the Crunchbase profile and found the POI’s LinkedIn profile link embedded on their page.
Key Takeaway
One piece of evidence that helped solidify the integrity of my finding was the correlation between the primary job title and organization listed on Crunchbase — which matched the same information I had observed on the POI’s GitHub account.
This was a good lead, but not a perfect solidification of evidence. Still, I kept digging deeper to fill in the perfect “missing pieces.”
Step 2.3: Analyzing the LinkedIn Profile
I clicked the link found in step 2.2. The profile belonged to Ignacio Iglesias Castreño
From the profile, I extracted:
Field — — — — — — — Value
- Current position: Chief Technology Officer (2020-present)
- Previous position: Full-Stack Developer (2020–2022)
- Education: Highest Grades Award. Master in Computer Systems Networking & Telecommunications (2020–2021)
- Personal website: ignacio.xyz
Step 2.4: Visiting the Personal Website
I typed ignacio.xyz into my browser.
Result: The website wasn’t opening — dead end!
But that is fine. The domain is not active, but it once was. This is perfect for Wayback Machine analysis.
Phase 2 Summary of Answers
Question — — — — — — My Answer
- LinkedIn URL: linkedin.com/in/ignacio-iglesias-castreño
- Personal website URL: ignacio.xyz
- Most recent work experience: Chief Technology Officer at Stakely.io
- Educational background: Highest Grades Award. Master in Computer Systems Networking & Telecommunications
Phase 3: Wayback Analysis — The First Archive
My Thought Process
The website ignacio.xyz is dead. But the Wayback Machine at archive.org likely has copies. I need to find the earliest snapshot — people often reveal more in their first website version before they learn to be careful.
Step 3.1: Navigating to Wayback Machine
I opened https://archive.org/web/ and entered ignacio.xyz.
The calendar view appeared. The earliest snapshot was from June 27, 2018.
Step 3.2: Viewing the First Snapshot
I clicked on the earliest blue circle. The page loaded — a simple portfolio site.
Step 3.3: Scouring the Snapshot
I manually reviewed every element:
- Header: “ignacio.xyz”
- About section: This premium domain name is available for purchase: BrandNameChoice.com
- Footer: THIS DOMAIN NAME IS AVAILABLE NOW FOR $49 ONLY! CONTACT US FOR IMMEDIATE PURCHASE!
Finding 1: Another email address — sales@brandnamechoice.com
Finding 2: Domain sale price — $49
Phase 3 Summary of Answers
Question — — — — — My Answer
- First archived snapshot timestamp: 2018–06–27 15:06:39 UTC
- Domain sale listing price: $49 USD
- Additional email address: sales@brandnamechoice.com
Phase 4: Wayback Analysis — The Last Archive (Deep Dive)
My Thought Process
The first archive gave me crumbs. But the last archive — the final version of the website before the domain expired — might contain more. People become complacent over time. They add social media links. They forget to remove personal information.
Step 4.1: Locating the Last Snapshot
From the same Wayback calendar, I scrolled to the right. The last snapshot was from January 8, 2025.
Step 4.2: Loading the Final Snapshot
I clicked on the last blue circle. The page was more elaborate — a full portfolio of the POI’s social media footprints and a crucial piece of evidence > Stakely that connect with Phase 2.
Step 4.3: Extracting Social Media Links
I clicked every social media icon and recorded the URLs and usernames:
Platform — — — Username / Handle — — — Full URL
- Telegram: @iicc1 > http://t.me/iicc1
- X (Twitter): @iicc_eth > https://twitter.com/iicc_eth
- OpenSea: @iicc > https://opensea.io/iicc
- Discord: User ID > 311985361658183691
- Len: @iic96 https://www.lensfrens.xyz/iicc96
Step 4.4: Extracting Profile Name and Username
From the website header and “About” section:
- Full name: Ignacio
- Main username across platforms: @iicc
Step 4.5: Verifying Each Profile
I opened each link in a new tab to confirm they were active (or at least existed).
Every account I discovered existed and displayed consistent characteristics — such as bio, profile imagery, and behavioral patterns — that directly correlated with my initial GitHub account lead. The lone exception was Len, though I am confident that account can be accessed and verified by manually visiting the platform itself.
Phase 4 Summary of Answers
Question — — — — My Answer
- Full name: Ignacio
- Main username: iicc
- Telegram username & display name: iicc1 / Ignacio — iicc
- OpenSea username: iicc
- X username & display name: iicc_eth / Ignacio iicc
- Discord User ID: 311985361658183691
- Len username: iicc96
Direct links:
- Telegram: http://t.me/iicc1
- OpenSea: https://opensea.io/iicc
- X (Twitter): https://twitter.com/iicc_eth
- Discord: https://discordapp.com/users/311985361658183691
- Len: https://www.lensfrens.xyz/iicc96
- GitLab: https://gitlab.com/iicc1
Phase 5: Correlation & Entity Graphing
My Thought Process
I have raw data across five phases. Now I need to visualize the connections. An entity graph will show relationships that text alone cannot.
Step 5.1: Choosing a Tool
I used Obsidian (free, local, markdown-based) because I can create nodes with [[double brackets]] and see the graph automatically.
Graph…
Tools Used — Complete List
Tool — — — — — Purpose
- GitHub: Repository discovery, commit analysis, contributor identification
- GitHub API: Account creation timestamp extraction
- IntelBase: Email intelligence lookup
- Holehe: Platform registration check (limited success)
- Google: Search engine dorking for LinkedIn
- LinkedIn: Professional profile analysis
- Wayback Machine (archive.org): Historical website snapshot recovery
- Obsidian: Entity graph visualization
Timeline of Investigation
All phases of the investigation, including GitHub OSINT, email pivoting, Wayback Machine analysis, social media correlation, and entity graphing, were conducted and documented within a 24-hour period. Although, in a professional setting. it would look like:
Phase — — Date/Time (approximate) — — Key Milestone
- Pre-investigation > Day 1, 09:00 > Environment setup
- Phase 1 > Day 1, 09:30 > GitHub repository located
- Phase 1 > Day 1, 10:15 > Owner email and contributors extracted
- Phase 2 > Day 1, 10:45 > LinkedIn profile found via Google dork
- …………
- Report writing > Day 1, 15:30–18:00 > Documentation and walkthrough
Critical Reminder — Evidence Log
Don’t forget to include an Evidence Log in any real investigation. It ensures traceability, reproducibility, and professional credibility. This often include:
Evidence ID > Description > Source / URL > Screenshot Filename
Example:
What I Learned
- Start with what you have. One Telegram bot handle was enough to begin.
- GitHub is an intelligence goldmine. Commit history, contributor lists, and API endpoints reveal more than the README.
- Dead websites are not dead. The Wayback Machine is an investigator’s best friend.
- People reuse usernames. iicc → iicc1 → iicc1_eth — the pattern was consistent.
- Never stop at one source. I cross-referenced every finding across multiple platforms before accepting it as fact.
- Document everything. Screenshots with timestamps saved me from confusion later.
Conclusion
This walkthrough demonstrates that a single Telegram bot handle — @TgBash — can be expanded into a complete digital identity profile using publicly available OSINT techniques and free tools.
The investigation chain:
@TgBash
→ GitHub repository (iicc1)
→ Email (ignacio.iglesias@hotmail.es)
→ LinkedIn (Ignacio Iglesias Castreño)
→ Personal website (ignacio.xyz)
→ Wayback Machine (first archive: 2018, last archive: 2025)
→ Social media accounts (Telegram, X, OpenSea, Discord, Len, GitLab)
→ Real identity confirmed.All findings were obtained without:
- Breaking any laws
- Violating any platform’s terms of service (to my knowledge)
- Contacting or harassing the target
This is ethical OSINT in practice.
Final Note
This walkthrough is my honest account of how I solved the challenge. Every search, every click, and every thought process is documented here. If you are reading this as a fellow investigator, I hope it helps you develop your own methodology. Thanks to for building this.
