Sitemap

OSINT Challenge: The Missing Pieces — Complete Walkthrough

11 min readMay 22, 2026

--

Press enter or click to view image in full size

How I Unmasked the Creator Behind TgBash Bot

A Step-by-Step Investigation Walkthrough by D4rk_Intel

Introduction

This document is a complete, transparent walkthrough of my investigation process for the OSINT Challenge: The Missing Pieces by

. I will document every search query, every tool, every click, and every thought process that led me from a single Telegram bot handle to a comprehensive digital identity profile.

Why I am writing this: To help other OSINT investigators understand not just what I found, but how I found it — including the dead ends, the pivots, and the “aha” moments.

Call to Action: Solve the Challenge Yourself

The Missing Pieces Challenge link – you can solve the challenge and share your report with me:

https://preciousvincentct.medium.com/osint-challenge-the-missing-pieces-aa6250e46678

After completing the challenge, email your investigation report and entity graph to: cybershieldmentor@gmail.com

I review every submission. The most detailed, well-documented reports may be featured in future community spotlights.

Let me begin.

Pre-Investigation Setup

Before touching any tool, I established my environment:

Item — — — — — — — — — My Setup

  • Browser > Google Chrome (clean profile, no extensions)
  • Search Engines > Google, Yandex, Bing
  • Tools Ready > Sherlock, WhatsMyName, Obsidian
  • Documentation > Notion for raw findings, screenshots folder
  • OPSEC > Standard browsing, no VPN (all public data)

I also reviewed the 5W1H framework:

  • Who: Unknown — starting only with @TgBash
  • What: Malicious Telegram bot investigation
  • Where: Telegram, GitHub, and associated platforms
  • When: Current/past activity
  • Why: Identify the creator behind the bot
  • How: GitHub OSINT → email pivot → website archive → social correlation

Now, let me walk you through each phase.

Phase 1: The Bot Owner Pivot

My Initial Thought Process

I have one piece of intelligence: @TgBash. The scenario suggests the bot was built using a publicly available phishing framework. In my experience, developers often:

  • Post their code on GitHub
  • Use the same username across platforms
  • Leave the bot handle in code comments or documentation

Step 1.1: GitHub Search

I navigated to github.com and used the search bar with the query:

Press enter or click to view image in full size

Result: A single repository appeared: iicc1/TgBash (username: iicc1).

Another simple technique I used was utilizing Google’s advanced search operators. I ran the following query: “TgBash” “Telegram bot” site:github.com

Press enter or click to view image in full size

This query led me directly to a GitHub repository containing a collection of Telegram bots arranged for different tasks. From there, I manually navigated through the repository’s contents — scanning the listed bots, examining the README, and reviewing the code comments — until I located the specific entry for the target’s Telegram bot (@TgBash).

The GitHub repository I discovered with the person of interest’s Telegram bot listed was:

Press enter or click to view image in full size

Step 1.2: Examining the Repository

With the repository located, I drilled down into its contents for further intelligence collection. A quick assessment of the bot’s scripting language revealed it was written entirely in Shell — evident from the .sh file extensions and the syntax structure throughout the codebase.

Based on my manual review of the repository’s commit history, contributor metadata, and code comments, the primary person of interest was identified as iicc1. The repository also listed additional contributors, whose usernames I documented for further pivoting in later phases.

Press enter or click to view image in full size
Press enter or click to view image in full size

Observation: The commit history showed multiple commits. The first commit was made by iicc1 alias > Ignacio Iglesias.

I clicked on the first commit to see the author details.

Finding: The commit metadata revealed:

  • Author: iicc1
  • Email: Null (we will get there)

I also checked Insights → Contributors (GitHub’s built-in feature).

Finding: Two other contributors:

Step 1.3: Extracting Contributor Emails

I clicked into each contributor’s profile and checked their public commits.

Step 1.4: GitHub Account Creation Timestamp

To find when iicc1 Ignacio Iglesias created their GitHub account:

Method 1: I went to https://api.github.com/users/[username] (I customized it with the POI’s GitHub username)

The API returned JSON data. I looked for:

  • created_at: “2015–06–30T15:45:44Z”
  • updated_at: “2026–04–26T10:30:53Z”
Press enter or click to view image in full size

Note: Manually, you can scroll to the bottom of the POI’s GitHub profile page — the join date is displayed there, labeled as “Joined.”

Step 1.5: POI Email Extraction & Provider Check

I attempted to locate the POI’s email address via GitHub API lookup using their repository, but the API did not return any positive feedback — only an earlier email address belonging to a contributor. This was somewhat frustrating.

Press enter or click to view image in full size
Extract commit emails from repositories:
https://api.github.com/repos/[owner]/[repo]/commits

So I pivoted to an alternative tool: braingainsoft.com. This tool automated the entire process for me. It indeed handled the heavy lifting by significantly reducing the manual effort and time it would have taken me to navigate the POI's repositories manually in search of their email address.

Press enter or click to view image in full size
Find GitHub users by programming languages, locations, keywords, and more.

Phase 1 Summary of Answers

Question — — — — — — My Answer

  1. Bot owner GitHub username: iicc1
  2. GitHub account creation timestamp: 2015–06–30T15:45:44Z
  3. Bot owner email address: ignacio.iglesias@hotmail.es
  4. Two other contributors: Madji, TiagoDanin Tiago Danin
  5. Contributor email address: TiagoDanin@outlook.com
  6. External Email provider: Outlook

Phase 2: The Missing Piece

My Thought Process

Now I have ignacio.iglesias@hotmail.es and the GitHub username iicc1. Who is this person? I need to pivot to professional networks and personal websites.

Step 2.1: Email Intelligence Tools

I opened intelbase.is and entered ignacio.iglesias@hotmail.es.

Results:

  • No LinkedIn account found (main entity)
  • No website found (second main entity)

I then tried holehe (command line):

Output: No registered accounts found on target platforms but gave me a crucial lead > X (Twitter) footprint. Dead end? Not yet.

Press enter or click to view image in full size
Press enter or click to view image in full size
holehe Output: One crucial lead = POI’s X (Twitter Footprint)

Step 2.2: Google Dorking with the Email

I then switched to manual Google searches. Unfortunately, the first query I ran — "ignacio.iglesias@hotmail.es" — returned a significant number of false positives. None of the results were relevant to my investigation or helped me move closer to identifying the person of interest.

Press enter or click to view image in full size

Next, I tried narrowing my search using the POI’s GitHub username and alias to see if I could obtain anything of significant value. Unfortunately, I found multiple unrelated profiles. That was when I paused, reflected, and approached my search more precisely.

First query: “iicc1” OR “Ignacio Iglesias” site:linkedin.com

Press enter or click to view image in full size
This returned multiple unrelated profiles — another dead end.

I then utilized the “Forgot Password” technique to verify whether the POI truly had a presence on LinkedIn. It turned out I was right — an account existed.

Press enter or click to view image in full size

Second query: -site:linkedin.com “Ignacio Iglesias” “Telecom engineer and dev | Stakely Co-Founder & CTO”

This query gave me a beautiful lead: the POI’s Crunchbase profile with the username > Ignacio Castreño.

This was a solid lead. I gently navigated down the Crunchbase profile and found the POI’s LinkedIn profile link embedded on their page.

Key Takeaway

One piece of evidence that helped solidify the integrity of my finding was the correlation between the primary job title and organization listed on Crunchbase — which matched the same information I had observed on the POI’s GitHub account.

This was a good lead, but not a perfect solidification of evidence. Still, I kept digging deeper to fill in the perfect “missing pieces.”

Press enter or click to view image in full size
Press enter or click to view image in full size

Step 2.3: Analyzing the LinkedIn Profile

I clicked the link found in step 2.2. The profile belonged to Ignacio Iglesias Castreño

From the profile, I extracted:

Field — — — — — — — Value

  • Current position: Chief Technology Officer (2020-present)
  • Previous position: Full-Stack Developer (2020–2022)
  • Education: Highest Grades Award. Master in Computer Systems Networking & Telecommunications (2020–2021)
  • Personal website: ignacio.xyz
Press enter or click to view image in full size
Note: The personal website was listed in the “Contact Info” section of LinkedIn.

Step 2.4: Visiting the Personal Website

I typed ignacio.xyz into my browser.

Result: The website wasn’t opening — dead end!

But that is fine. The domain is not active, but it once was. This is perfect for Wayback Machine analysis.

Phase 2 Summary of Answers

Question — — — — — — My Answer

  1. LinkedIn URL: linkedin.com/in/ignacio-iglesias-castreño
  2. Personal website URL: ignacio.xyz
  3. Most recent work experience: Chief Technology Officer at Stakely.io
  4. Educational background: Highest Grades Award. Master in Computer Systems Networking & Telecommunications

Phase 3: Wayback Analysis — The First Archive

My Thought Process

The website ignacio.xyz is dead. But the Wayback Machine at archive.org likely has copies. I need to find the earliest snapshot — people often reveal more in their first website version before they learn to be careful.

Press enter or click to view image in full size

Step 3.1: Navigating to Wayback Machine

I opened https://archive.org/web/ and entered ignacio.xyz.

The calendar view appeared. The earliest snapshot was from June 27, 2018.

Press enter or click to view image in full size

Step 3.2: Viewing the First Snapshot

I clicked on the earliest blue circle. The page loaded — a simple portfolio site.

Press enter or click to view image in full size

Step 3.3: Scouring the Snapshot

I manually reviewed every element:

  • Header: “ignacio.xyz”
  • About section: This premium domain name is available for purchase: BrandNameChoice.com
  • Footer: THIS DOMAIN NAME IS AVAILABLE NOW FOR $49 ONLY! CONTACT US FOR IMMEDIATE PURCHASE!
Press enter or click to view image in full size

Finding 1: Another email address — sales@brandnamechoice.com
Finding 2: Domain sale price — $49

Press enter or click to view image in full size
I also checked the page source (Ctrl+U) for hidden comments or metadata. Nothing else.

Phase 3 Summary of Answers

Question — — — — — My Answer

  1. First archived snapshot timestamp: 2018–06–27 15:06:39 UTC
  2. Domain sale listing price: $49 USD
  3. Additional email address: sales@brandnamechoice.com

Phase 4: Wayback Analysis — The Last Archive (Deep Dive)

My Thought Process

The first archive gave me crumbs. But the last archive — the final version of the website before the domain expired — might contain more. People become complacent over time. They add social media links. They forget to remove personal information.

Step 4.1: Locating the Last Snapshot

From the same Wayback calendar, I scrolled to the right. The last snapshot was from January 8, 2025.

Press enter or click to view image in full size

Step 4.2: Loading the Final Snapshot

I clicked on the last blue circle. The page was more elaborate — a full portfolio of the POI’s social media footprints and a crucial piece of evidence > Stakely that connect with Phase 2.

Press enter or click to view image in full size

Step 4.3: Extracting Social Media Links

I clicked every social media icon and recorded the URLs and usernames:

Platform — — — Username / Handle — — — Full URL

Step 4.4: Extracting Profile Name and Username

From the website header and “About” section:

  • Full name: Ignacio
  • Main username across platforms: @iicc

Step 4.5: Verifying Each Profile

I opened each link in a new tab to confirm they were active (or at least existed).

Every account I discovered existed and displayed consistent characteristics — such as bio, profile imagery, and behavioral patterns — that directly correlated with my initial GitHub account lead. The lone exception was Len, though I am confident that account can be accessed and verified by manually visiting the platform itself.

Phase 4 Summary of Answers

Question — — — — My Answer

  1. Full name: Ignacio
  2. Main username: iicc
  3. Telegram username & display name: iicc1 / Ignacio — iicc
  4. OpenSea username: iicc
  5. X username & display name: iicc_eth / Ignacio iicc
  6. Discord User ID: 311985361658183691
  7. Len username: iicc96

Direct links:

Phase 5: Correlation & Entity Graphing

My Thought Process

I have raw data across five phases. Now I need to visualize the connections. An entity graph will show relationships that text alone cannot.

Step 5.1: Choosing a Tool

I used Obsidian (free, local, markdown-based) because I can create nodes with [[double brackets]] and see the graph automatically.

Graph…

Tools Used — Complete List

Tool — — — — — Purpose

  1. GitHub: Repository discovery, commit analysis, contributor identification
  2. GitHub API: Account creation timestamp extraction
  3. IntelBase: Email intelligence lookup
  4. Holehe: Platform registration check (limited success)
  5. Google: Search engine dorking for LinkedIn
  6. LinkedIn: Professional profile analysis
  7. Wayback Machine (archive.org): Historical website snapshot recovery
  8. Obsidian: Entity graph visualization

Timeline of Investigation

All phases of the investigation, including GitHub OSINT, email pivoting, Wayback Machine analysis, social media correlation, and entity graphing, were conducted and documented within a 24-hour period. Although, in a professional setting. it would look like:

Phase — — Date/Time (approximate) — — Key Milestone

  • Pre-investigation > Day 1, 09:00 > Environment setup
  • Phase 1 > Day 1, 09:30 > GitHub repository located
  • Phase 1 > Day 1, 10:15 > Owner email and contributors extracted
  • Phase 2 > Day 1, 10:45 > LinkedIn profile found via Google dork
  • …………
  • Report writing > Day 1, 15:30–18:00 > Documentation and walkthrough

Critical Reminder — Evidence Log

Don’t forget to include an Evidence Log in any real investigation. It ensures traceability, reproducibility, and professional credibility. This often include:

Evidence ID > Description > Source / URL > Screenshot Filename

Example:

Press enter or click to view image in full size

What I Learned

  1. Start with what you have. One Telegram bot handle was enough to begin.
  2. GitHub is an intelligence goldmine. Commit history, contributor lists, and API endpoints reveal more than the README.
  3. Dead websites are not dead. The Wayback Machine is an investigator’s best friend.
  4. People reuse usernames. iicc → iicc1 → iicc1_eth — the pattern was consistent.
  5. Never stop at one source. I cross-referenced every finding across multiple platforms before accepting it as fact.
  6. Document everything. Screenshots with timestamps saved me from confusion later.

Conclusion

This walkthrough demonstrates that a single Telegram bot handle — @TgBash — can be expanded into a complete digital identity profile using publicly available OSINT techniques and free tools.

The investigation chain:

@TgBash 
→ GitHub repository (iicc1)
→ Email (ignacio.iglesias@hotmail.es)
→ LinkedIn (Ignacio Iglesias Castreño)
→ Personal website (ignacio.xyz)
→ Wayback Machine (first archive: 2018, last archive: 2025)
→ Social media accounts (Telegram, X, OpenSea, Discord, Len, GitLab)
→ Real identity confirmed.

All findings were obtained without:

  • Breaking any laws
  • Violating any platform’s terms of service (to my knowledge)
  • Contacting or harassing the target

This is ethical OSINT in practice.

Final Note

This walkthrough is my honest account of how I solved the challenge. Every search, every click, and every thought process is documented here. If you are reading this as a fellow investigator, I hope it helps you develop your own methodology. Thanks to

for building this.

--

--