{"id":1205,"date":"2020-12-23T23:24:03","date_gmt":"2020-12-23T23:24:03","guid":{"rendered":"https:\/\/osintme.com\/?p=1205"},"modified":"2020-12-23T23:27:09","modified_gmt":"2020-12-23T23:27:09","slug":"osint-iran-passive-reconnaissance-of-iranian-ip-space-iot-wifi-networks-social-media-and-more","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2020\/12\/23\/osint-iran-passive-reconnaissance-of-iranian-ip-space-iot-wifi-networks-social-media-and-more\/","title":{"rendered":"OSINT Iran: passive reconnaissance of Iranian IP space, IoT, WiFi networks, social media and more"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"1205\" class=\"elementor elementor-1205\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-039c0ba elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"039c0ba\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e37c308\" data-id=\"e37c308\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1cd4fdf elementor-widget elementor-widget-image\" data-id=\"1cd4fdf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"150\" height=\"150\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/11\/iran-symbol-flag-OSINT.jpg?resize=150%2C150&amp;ssl=1\" class=\"attachment-thumbnail size-thumbnail wp-image-1211\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/11\/iran-symbol-flag-OSINT.jpg?w=640&amp;ssl=1 640w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/11\/iran-symbol-flag-OSINT.jpg?resize=300%2C300&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/11\/iran-symbol-flag-OSINT.jpg?resize=150%2C150&amp;ssl=1 150w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-30c5e1e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"30c5e1e\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c56f85f\" data-id=\"c56f85f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bcf7b09 elementor-widget elementor-widget-text-editor\" data-id=\"bcf7b09\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>News about or from Iran that appear in the Western public information domain are usually in connection with some disturbing political developments in the region, or international sanctions. Or both.<\/p><p>Or, like this year and especially in the recent months, hostile actions by foreign intelligence services and military against the Iranian regime.<\/p><p>Examples of these include the <a href=\"https:\/\/www.nytimes.com\/2020\/01\/03\/world\/middleeast\/suleimani-dead.html\">assassination of General Suleimani<\/a>, a series of <a href=\"https:\/\/en.wikipedia.org\/wiki\/2020_Iran_explosions\">unexplained explosions<\/a> at various strategic locations across the country, or more recently the <a href=\"https:\/\/www.bbc.com\/news\/world-middle-east-55118140\">assassination of Iran&#8217;s leading nuclear scientist<\/a>.<\/p><p>The serious nature of these events frequently overshadows other news from the cyber space, such as alleged Iranian activities on the online disinformation front (examples <a href=\"https:\/\/www.justice.gov\/opa\/pr\/united-states-seizes-domain-names-used-iran-s-islamic-revolutionary-guard-corps\">here<\/a> and <a href=\"https:\/\/www.justice.gov\/opa\/pr\/united-states-seizes-27-additional-domain-names-used-iran-s-islamic-revolutionary-guard-corps\">here<\/a>).<\/p><p>Iran and the Middle East in general remain a volatile region, with many international relations experts pointing out the possibility of the next global conflict starting there.<\/p><p>All of the above are the reasons why I thought it would be interesting to conduct some research of the Iranian online landscape.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2c6aa09 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2c6aa09\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ea85e6a\" data-id=\"ea85e6a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-acca5ad elementor-widget elementor-widget-heading\" data-id=\"acca5ad\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">1. Iran's ASN numbers<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ca0fed1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ca0fed1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-884153d\" data-id=\"884153d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-113d20a elementor-widget elementor-widget-text-editor\" data-id=\"113d20a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>ASN stands for Autonomous System Number. Such numbers are global unique identifiers and are assigned to autonomous systems used by ISPs so that they can exchange routing information with other ISPs.<\/p><p>Iran is known for its strict censorship of the Internet, so it should be no surprise that every single one of the top ISPs is controlled by the government.<\/p><p>The top ISP in Iran, judging by the list of IP addresses, is the <strong>Iran Telecommunication Company PJS<\/strong>, currently with close to 3.5 million identified IP addresses, a large majority of which are IPv4.<\/p><p>Ping and connectivity tests that I carried out with sample IP addresses for this ISP suggest the connection speed is very poor,: on average it&#8217;s under 10Mb\/s.<\/p><p>The second largest ISP, which by the way is reflective of the rapidly expanding mobile Internet market, is the <strong>Mobile Communication Company of Iran PLC<\/strong>. They control over 2 million IP addresses.<\/p><p>Surprisingly, mobile Internet is currently the most reliable and statistically the fastest in all of Iran, with average speeds of 20Mb\/s.<\/p><p>The third largest ISP is the <strong>Information Technology Company<\/strong>, with close to 2 million IP addresses.<\/p><p>The fourth largest is the <strong>Iran Cell Service and Communication Company<\/strong>, also the second largest provider of mobile Internet services in the country. They control just over 1 million of IP addresses.<\/p><p>Naturally enough, the number of websites hosted by mobile Internet providers is significantly smaller than with their traditional broadband ISP counterparts.<\/p><p>The fifth largest ISP is the <strong>Aria Shatel Company Ltd<\/strong>, probably the most modern and Western-like Internet provider, with just above 1 million active IP addresses.<\/p><p>Overall, there are approximately 12.5 million of IP addresses, officially identified as belonging to Iran.<\/p><p>This figure is without doubt bigger as it does not include non-Iranian IPs, even if those are in long term use by Iranian entities.<\/p><p>Detailed statistics on Iranian ASN numbers can be found <a href=\"https:\/\/ipinfo.io\/countries\/ir\">here<\/a>.<\/p><p>Major IP address blocks for Iran are seen <a href=\"https:\/\/www.nirsoft.net\/countryip\/ir.html\">here<\/a>.<\/p><p>IP address ranges and total counts identified <a href=\"https:\/\/lite.ip2location.com\/iran-(islamic-republic-of)-ip-address-ranges\">here<\/a> and <a href=\"https:\/\/mainfacts.com\/ip-address-space-addresses\/IR-IRN-Iran\">here<\/a>.<\/p><p>IPv6 stats for Iran <a href=\"https:\/\/ipv6-test.com\/stats\/country\/IR\">here<\/a>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fd022c3 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"fd022c3\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-84d9c27\" data-id=\"84d9c27\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c5ae857 elementor-widget elementor-widget-heading\" data-id=\"c5ae857\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">2. Iran's government websites<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5c58dde elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5c58dde\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5864c6f\" data-id=\"5864c6f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-aad47d5 elementor-widget elementor-widget-text-editor\" data-id=\"aad47d5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The most common domain used by the government is <strong>.gov.ir<\/strong>, but several websites just use the .ir top level alone (for example, the <a href=\"http:\/\/www.president.ir\/en\">www.president.ir<\/a> domain).<\/p><p><em>If unsure about these nuances, check out my post discussing domain level naming structure <a href=\"https:\/\/osintme.com\/index.php\/2020\/05\/22\/new-spam-phishing-campaign-on-whatsapp-investigating-fake-dominos-pizza-websites\/\">here<\/a>.<\/em><\/p><p>The top level .ir domain is administered by the Institute for Research in Fundamental Sciences, located at the Shahid Bahonar (Niavaran) Square, Tehran 1954851167.<\/p><p>The Iranian government has <a href=\"http:\/\/www.president.ir\/en\/president\/cabinet\">19 ministers<\/a>, all in charge of a separate ministry; each of those has its own domain:<\/p><ol><li>Education &#8211; <a href=\"https:\/\/www.medu.ir\/\">https:\/\/www.medu.ir\/<\/a> &#8211; <span class=\"ipaddr\">217.218.26.200<\/span><\/li><li>Communications and Information Technology &#8211; <a href=\"https:\/\/www.ict.gov.ir\/\">https:\/\/www.ict.gov.ir\/<\/a> &#8211; <span class=\"ipaddr\">78.38.249.221<br \/><\/span><\/li><li>Intelligence &#8211; <a href=\"http:\/\/www.vaja.ir\">http:\/\/www.vaja.ir<\/a> &#8211; <span class=\"ipaddr\">2.187.252.17<br \/><\/span><\/li><li>Economic Affairs and Finance &#8211; <a href=\"https:\/\/mefa.ir\/\">https:\/\/mefa.ir\/<\/a> &#8211; <span class=\"ipaddr\">46.209.206.201<br \/><\/span><\/li><li>Foreign Affairs &#8211; <a href=\"https:\/\/www.mfa.gov.ir\/\">https:\/\/www.mfa.gov.ir\/<\/a> &#8211; 185.143.233.5<\/li><li>Health and Medical Education &#8211; <a href=\"https:\/\/behdasht.gov.ir\/\">https:\/\/behdasht.gov.ir\/<\/a> &#8211; 185.123.209.86<\/li><li>Cooperatives, Labour and Social Welfare &#8211; <a href=\"https:\/\/www.mcls.gov.ir\/\">https:\/\/www.mcls.gov.ir\/<\/a> &#8211; 185.192.112.3<\/li><li>Agriculture Jihad &#8211; <a href=\"https:\/\/www.maj.ir\/\">https:\/\/www.maj.ir\/<\/a> &#8211; 79.175.135.30<\/li><li>Justice &#8211; <a href=\"https:\/\/www.justice.ir\/\">https:\/\/www.justice.ir\/<\/a> &#8211; 62.193.12.10<\/li><li>Defense Armed Forces Logistics &#8211; http:\/\/www.mod.ir\/ (website not resolving, archived version available <a href=\"https:\/\/web.archive.org\/web\/2018*\/http:\/\/www.mod.ir\/\">here<\/a>)<\/li><li>Roads and Urban Development &#8211; <a href=\"https:\/\/www.mrud.ir\/\">https:\/\/www.mrud.ir\/<\/a> &#8211; 5.202.186.133<\/li><li>Industry, Mine and Trade &#8211; <a href=\"http:\/\/www.mimt.gov.ir\/\">http:\/\/www.mimt.gov.ir\/<\/a> &#8211; 217.11.21.21<\/li><li>Culture and Islamic Guidance &#8211; <a href=\"https:\/\/www.farhang.gov.ir\/\">https:\/\/www.farhang.gov.ir\/<\/a> &#8211; 78.157.60.190<\/li><li>Interior &#8211; <a href=\"http:\/\/www.moi.ir\/\">http:\/\/www.moi.ir\/<\/a> &#8211; 185.143.233.5<\/li><li>Science, Research and Technology &#8211; <a href=\"https:\/\/www.msrt.ir\/fa\">https:\/\/www.msrt.ir\/<\/a> &#8211; 94.184.236.55<\/li><li>Cultural Heritage, Tourism and Handicrafts &#8211; <a href=\"https:\/\/www.mcth.ir\/\">https:\/\/www.mcth.ir\/<\/a> &#8211; <span class=\"ipaddr\">91.99.102.190<br \/><\/span><\/li><li>Oil &#8211; <a href=\"https:\/\/www.mop.ir\/\">https:\/\/www.mop.ir\/<\/a> &#8211; <span class=\"ipaddr\">217.174.16.48<br \/><\/span><\/li><li>Energy &#8211; <a href=\"https:\/\/moe.gov.ir\/\">https:\/\/moe.gov.ir\/<\/a> &#8211; <span class=\"ipaddr\">78.157.43.50<br \/><\/span><\/li><li>Youth Affairs and Sports &#8211; http:\/\/www.msy.gov.ir\/ (website not resolving, archived version available <a href=\"https:\/\/web.archive.org\/web\/2019*\/http:\/\/msy.gov.ir\/\">here<\/a>)<\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-56dc471 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"56dc471\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-339f42a\" data-id=\"339f42a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3ea648b elementor-widget elementor-widget-text-editor\" data-id=\"3ea648b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>There are thousands more government websites and it would not be practical to even try and enumerate more of them, but some of them can be detected by probing the IP addresseses I mentioned above (or other IPs residing on the same ranges).<\/p><p>Alternatively you can search for websites on the &#8220;.gov.ir&#8221; domain using some of the well known DNS tools or even Google queries, like <a href=\"https:\/\/www.google.com\/search?ei=nOPDX4njL5iZ1fAPgOCL4Ag&amp;q=%22.gov.ir%22+%2B+website&amp;oq=%22.gov.ir%22+%2B+website&amp;gs_lcp=CgZwc3ktYWIQAzIGCAAQCBAeUPMuWPMuYKUwaANwAHgAgAFPiAFPkgEBMZgBAKABAaoBB2d3cy13aXrAAQE&amp;sclient=psy-ab&amp;ved=0ahUKEwiJody-rKjtAhWYTBUIHQDwAowQ4dUDCA0&amp;uact=5\">this one<\/a> (don&#8217;t forget to insert your own keywords of interest there!).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-070ce5b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"070ce5b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-f0a8958\" data-id=\"f0a8958\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4c38357 elementor-widget elementor-widget-heading\" data-id=\"4c38357\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">3. Iran's IoT landscape<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-44cde1f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"44cde1f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-150cf63\" data-id=\"150cf63\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b2e893c elementor-widget elementor-widget-text-editor\" data-id=\"b2e893c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>One of the best tools for passive reconnaissance of the public facing \/ open infrastructure is <a href=\"https:\/\/www.shodan.io\/home\">Shodan<\/a>.<\/p><p>This time around I was very eager to compare Shodan&#8217;s results to those presented by <a href=\"https:\/\/www.zoomeye.org\/\">Zoomeye<\/a>, but unfortunately this service has been consistently blocking my access to it whenever I tried to connect through a VPN (and connecting from your true residential IP address is not a safe option).<\/p><p><em>If you are not familiar with Shodan, there are still a couple of seats left on my <a href=\"https:\/\/osintme.com\/index.php\/2020\/10\/01\/shodan-osint-iot-devices-my-first-ever-online-course\/\">Shodan, OSINT &amp; IoT Devices online course<\/a> &#8211; it&#8217;s a fully hands on, bullshit-free, practical intro to the Shodan platform.<\/em><\/p><p>The high level overview of all devices indexed by Shodan can be gleaned by using the <a href=\"https:\/\/www.shodan.io\/search?query=country%3Air\">country:ir<\/a> filter &#8211; this offers nearly 2 million results which need to be narrowed down further.<\/p><p>You can probe specific known IP addresses, or you can expand the search filter parameters to search for devices in a particular city, like <a href=\"https:\/\/www.shodan.io\/search?query=country%3Air+city%3Atehran\">country:ir city:tehran<\/a> or another Iranian city of interest (see the database of Iranian cities available <a href=\"https:\/\/simplemaps.com\/data\/ir-cities\">here<\/a>).<\/p><p>One of the most exciting features of Shodan is exploring open webcams and this can be done using the <a href=\"https:\/\/www.shodan.io\/search?query=country%3Air+has_screenshot%3Atrue+port%3A%2280%22\">country:ir has_screenshot:true port:&#8221;80&#8243;<\/a> filter. It is important to focus on the specific port, as this will eliminate all results displaying static RDP login screens and similar results that yield limited information.<\/p><p>Some examples of the types of open webcams that you can find are seen below:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4173187 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4173187\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-976e717\" data-id=\"976e717\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6f11037 elementor-widget elementor-widget-image\" data-id=\"6f11037\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"640\" height=\"400\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-OSINT-screen.jpg?fit=640%2C400&amp;ssl=1\" class=\"attachment-large size-large wp-image-1265\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-OSINT-screen.jpg?w=640&amp;ssl=1 640w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-OSINT-screen.jpg?resize=300%2C188&amp;ssl=1 300w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e64251c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e64251c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6aa7946\" data-id=\"6aa7946\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e42056d elementor-widget elementor-widget-image\" data-id=\"e42056d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"579\" height=\"518\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-screenshot.png?fit=579%2C518&amp;ssl=1\" class=\"attachment-large size-large wp-image-1248\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-screenshot.png?w=579&amp;ssl=1 579w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-screenshot.png?resize=300%2C268&amp;ssl=1 300w\" sizes=\"(max-width: 579px) 100vw, 579px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-19a90e2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"19a90e2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-82e7dc2\" data-id=\"82e7dc2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5250a19 elementor-widget elementor-widget-image\" data-id=\"5250a19\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"397\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-screen-OSINT2.jpg?fit=640%2C397&amp;ssl=1\" class=\"attachment-large size-large wp-image-1264\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-screen-OSINT2.jpg?w=640&amp;ssl=1 640w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-screen-OSINT2.jpg?resize=300%2C186&amp;ssl=1 300w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e2f9d36 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e2f9d36\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-db7c07d\" data-id=\"db7c07d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-b2f30f1 elementor-widget elementor-widget-image\" data-id=\"b2f30f1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"635\" height=\"337\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-screenshot2.png?fit=635%2C337&amp;ssl=1\" class=\"attachment-large size-large wp-image-1249\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-screenshot2.png?w=635&amp;ssl=1 635w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-screenshot2.png?resize=300%2C159&amp;ssl=1 300w\" sizes=\"(max-width: 635px) 100vw, 635px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-597f44b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"597f44b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c7bb8f0\" data-id=\"c7bb8f0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-57546b9 elementor-widget elementor-widget-text-editor\" data-id=\"57546b9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Footage from webcams (some of which you can actually log into without authentication) can be useful if you target a specific IP address that has an IoT device linked to it.<\/p><p>Also, even static screenshots can offer some background elements information &#8211; from objects on a desk, some of which might contain notes of interest, to signs, banners or names on a wall. All of this can be leveraged by zooming in close and applying visual identification.<\/p><p>I also had some successful results when scanning foreign language text from screenshots or static pages using free OCR apps, like <a href=\"https:\/\/osintme.com\/index.php\/2020\/10\/25\/clipdrop-an-unexpected-new-osint-tool\/\">ClipDrop<\/a> that I discussed several weeks ago.<\/p><p>When it comes to probing previously identified IP addresses, you can find some pretty unexpected results.<\/p><p>For example, I extensively searched (and used up my daily Shodan search limit in the process!) for some IP addresses suspected to belong to a government IP address range.<\/p><p>Of the the IPs had an open webcam assigned to it, which seems to capture a backyard of what looks like a secure compound, with some national flags in it:<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3c79e1c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3c79e1c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5465c61\" data-id=\"5465c61\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-17bd6ef elementor-widget elementor-widget-image\" data-id=\"17bd6ef\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"897\" height=\"390\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-IP-address.png?fit=897%2C390&amp;ssl=1\" class=\"attachment-large size-large wp-image-1256\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-IP-address.png?w=897&amp;ssl=1 897w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-IP-address.png?resize=300%2C130&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/shodan-example-IP-address.png?resize=768%2C334&amp;ssl=1 768w\" sizes=\"(max-width: 897px) 100vw, 897px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9ef2d1c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9ef2d1c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e0eaca8\" data-id=\"e0eaca8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6bb62c2 elementor-widget elementor-widget-text-editor\" data-id=\"6bb62c2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>You can attempt an educated guess as to what this location is, but further information can be obtained by pivoting off the IP address (I used <a href=\"https:\/\/ipinfo.io\/\">IPInfo.io<\/a>):<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-30e6e9e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"30e6e9e\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-20cadb0\" data-id=\"20cadb0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5ee8309 elementor-widget elementor-widget-image\" data-id=\"5ee8309\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"524\" height=\"418\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/iran-IP-address-screenshot.png?fit=524%2C418&amp;ssl=1\" class=\"attachment-large size-large wp-image-1257\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/iran-IP-address-screenshot.png?w=524&amp;ssl=1 524w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/iran-IP-address-screenshot.png?resize=300%2C239&amp;ssl=1 300w\" sizes=\"(max-width: 524px) 100vw, 524px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b5a3c4c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b5a3c4c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-25c327d\" data-id=\"25c327d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-03053b2 elementor-widget elementor-widget-text-editor\" data-id=\"03053b2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The GPS coordinates <a href=\"https:\/\/www.google.com\/maps\/place\/%D9%BE%D8%A7%D8%B1%DA%A9+%D9%88%D8%AD%D8%AF%D8%AA%E2%80%AD\/@32.8655677,59.2207119,17.5z\/data=!4m13!1m7!3m6!1s0x0:0x0!2zMzLCsDUxJzU4LjciTiA1OcKwMTMnMTYuMCJF!3b1!8m2!3d32.8663!4d59.2211!3m4!1s0x3f1a5d88c960ca17:0x61443531687c06ad!8m2!3d32.8664606!4d59.2212338\">32.8663, 59.2211<\/a> bring us to a location marked on Google Maps as a park (Google Street View is not available in Iran), which does not add up, but looking for visual clues via Google&#8217;s trove of user uploaded photos we can sometimes get lucky and piece more information together.<\/p><p>It is also a good idea to search for distinctive land marks, buildings and terrain features that can be then cross-referenced using Google Maps satellite view.<\/p><p>More details on an IP address (and on the &#8220;neighbouring&#8221; IPs belonging to the same IP block) can be found on sites like <a href=\"https:\/\/anti-hacker-alliance.com\/index.php?ip=2.181.239.250&amp;searching=yes\">this<\/a>, while there are multiple other directions for exploring this angle further &#8211; such as employing other OSINT techniques to find an associated name, phone number, email, etc.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c1745b7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c1745b7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-84299e2\" data-id=\"84299e2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c83e651 elementor-widget elementor-widget-heading\" data-id=\"c83e651\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">4. Iran's WiFi networks and device MAC addresses<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-77b5842 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"77b5842\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b845ad7\" data-id=\"b845ad7\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-edd0aa4 elementor-widget elementor-widget-text-editor\" data-id=\"edd0aa4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>WiFi reconnaissance is used primarily in penetration testing and ethical hacking, but in this case it can also be used to search for MAC (media access control) addresses of particular devices, if we have attributed such devices to a specific user.<\/p><p>For example, if an individual used a smartphone to carry out certain actions online (log into a platform, etc.) and left a MAC address identifier behind them, we can check if that MAC was at some stage in the past used for setting up a WiFi hotspot.<\/p><p>This is possible using <a href=\"https:\/\/wigle.net\/search\">Wigle<\/a>, an access point mapping service, also commonly referred to as a war driving app.<\/p><p>War driving is an old WiFi vulnerability identification method, relying on moving around in a specific area while actively scanning for networks using a smartphone or a laptop configured to operate in &#8220;promiscuous mode&#8221;, as if it intended to find and connect to every nearby network.<\/p><p>War driving with Wigle is easy: all one needs is an Android phone with the Wigle app running on it. WiFi networks detected by a war driver will get recorded in the Wigle database, so that a record of historical data is present.<\/p><p>War driving was particularly useful during the early days of WiFi networks and it was mainly used to detect open, unprotected networks where anybody could connect up without any authentication.<\/p><p>Currently Wigle has information on over 700 million WiFi networks all over the world.<\/p><p>Broad searching on Wigle is very much possible, but as always, best results are obtained by narrowing down the search criteria. There are many parameters to define here, but to start off I like to define the country of interest and the date when a WiFi was last observed (YYYY-MM-DD format):<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-29da57f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"29da57f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-a4cd640\" data-id=\"a4cd640\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4800cd8 elementor-widget elementor-widget-image\" data-id=\"4800cd8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"465\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT1.png?fit=1024%2C465&amp;ssl=1\" class=\"attachment-large size-large wp-image-1290\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT1.png?w=1276&amp;ssl=1 1276w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT1.png?resize=300%2C136&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT1.png?resize=1024%2C465&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT1.png?resize=768%2C348&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-0ab6e3e elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"0ab6e3e\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-371d92b\" data-id=\"371d92b\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5362e0d elementor-widget elementor-widget-text-editor\" data-id=\"5362e0d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The results displayed contain information such as the SSID name, date ranges, level of encryption on the network, GPS coordinates and a handy map to visualize the location.<\/p><p>SSID names alone can yield a lot of clues, even though people nowadays tend not to name their WiFi networks using their surnames, like they used to do in the past.<\/p><p>You can also search by a specific address to see what networks are or were associated with it by Wigle in the past.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-332620a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"332620a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-28d20c9\" data-id=\"28d20c9\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d0a74f9 elementor-widget elementor-widget-image\" data-id=\"d0a74f9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"642\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT-2.png?fit=1024%2C642&amp;ssl=1\" class=\"attachment-large size-large wp-image-1291\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT-2.png?w=1232&amp;ssl=1 1232w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT-2.png?resize=300%2C188&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT-2.png?resize=1024%2C642&amp;ssl=1 1024w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2020\/12\/Wigle-OSINT-2.png?resize=768%2C482&amp;ssl=1 768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-06a4f38 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"06a4f38\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7df823d\" data-id=\"7df823d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-be61ef8 elementor-widget elementor-widget-heading\" data-id=\"be61ef8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">5. Iran's main state cyber actors<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ca2c2ef elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ca2c2ef\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-02a1eec\" data-id=\"02a1eec\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a9e462c elementor-widget elementor-widget-text-editor\" data-id=\"a9e462c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Iran remains a significant player among other countries with the anti-Western agenda. The Iranian cyber capabilities might not be on par with China or Russia, nevertheless Iran has been working towards improving their cyber offense through outsourcing their work to hacker groups both within and outside of the country.<\/p><p>I recall a conversation I once had during a cybersecurity conference with a senior military officer responsible for cyber defense. He likened Iran&#8217;s level of cyber warfare organisation to a messy server room, with cabling hanging in disarray from every rack and with equipment scattered chaotically in every corner. And yet, this is a fully functioning server room that gets the job done.<\/p><p>The military branch of the government with cyber offense capabilities is the<strong> Islamic Revolutionary Guard Corps (IRGC)<\/strong>. The IRGC has many other responsibilities and cyber is only one of them. They oversee campaigns directed against both governmental and corporate targets globally. They are aided by several paramilitary, semi-professional militias like The Basij, who also formed their own cyber offense wing called the <strong>Basij Cyber Units (BCU)<\/strong>.<\/p><p>Interestingly and somewhat unusually for an official military governmental organisation, the IRGC has been designated as a terrorist organisation by several countries, including the US.\u00a0<\/p><p>The regime&#8217;s civilian intel wing of the government with cyber capabilities is the\u00a0<strong>Ministry of Intelligence and Security (MOIS)<\/strong>. They conduct a wide variety of operations, from signals interception, Internet censorship, digital counter-intelligence and disinformation warfare.\u00a0<\/p><p>In the wake of the infamous Stuxnet malware attack against Iranian nuclear research facilities, the regime created organisations like the <strong>National Passive Defense Organization (NPDO)<\/strong> and the <strong>Cyber Defense Command<\/strong> (styled on the US equivalent). Their objectives include protecting the country&#8217;s cyber infrastructure from attacks and conducting threat modelling, perhaps similar to the CSIRT bodies operating in Western countries.<\/p><p>Finally, Iranian cyber capabilities include companies and NGOs, such as the <strong>Mabna Institute<\/strong> (private tech and IT company located in Tehran, suspected of hacking activities on behalf of the regime) and <strong>The Nejat Society<\/strong> (NGO involved in online PR and propaganda efforts for the Iranian authorities).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9d1727b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9d1727b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b8e8019\" data-id=\"b8e8019\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-714d48a elementor-widget elementor-widget-heading\" data-id=\"714d48a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">6. Iran and social media<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-726ecf7 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"726ecf7\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c4be158\" data-id=\"c4be158\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-aa991a3 elementor-widget elementor-widget-text-editor\" data-id=\"aa991a3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Iranian&#8217;s are very active on the global social media platforms like Twitter, Facebook, Instagram or TikTok.<\/p><p>However, there are also several local social media sites whose popularity is unique to Iran.<\/p><p>To see the current trends, I would recommend starting with the <a href=\"https:\/\/www.alexa.com\/topsites\/countries\/IR\">Alexa Top Sites ranking<\/a>, which shows the websites frequented the most in Iran.<\/p><p>Many of those sites are news platforms and those aren&#8217;t really useful for an OSINT investigator.<\/p><p>But here are some popular Iranian social media sites (yes, the Farsi language is a huge barrier):<\/p><ul><li><strong><a href=\"https:\/\/www.aparat.com\/\">Aparat<\/a><\/strong> &#8211; an Iranian version of Youtube, works in a very similar way with video sharing and comments.<\/li><li><strong><a href=\"https:\/\/www.balatarin.com\/\">Balatarin<\/a><\/strong> &#8211; link sharing website, dominated by political themes. Good for online handles searching.<\/li><li><strong><a href=\"https:\/\/www.cloob.com\/\">Cloob<\/a><\/strong> &#8211; a rather dated social media site that combines discussion forums and chat rooms.<\/li><li><a href=\"https:\/\/www.digikala.com\/\"><strong>Digikala<\/strong><\/a> &#8211; online marketplace that looks and feels like eBay or Amazon.\u00a0<\/li><li><strong><a href=\"https:\/\/divar.ir\/\">Divar<\/a><\/strong> &#8211; classified ads site, useful for searching usernames, but can be a hit and miss.<\/li><li><a href=\"https:\/\/facenama.com\/\"><strong>Facenama<\/strong><\/a> &#8211; an Iranian clone of Facebook. Nowhere near close to the real thing in terms of usability.<\/li><li><strong><a href=\"https:\/\/www.sheypoor.com\/\">Sheypoor<\/a><\/strong> &#8211; classified ads site for mobile and desktop.<\/li><li><strong><a href=\"https:\/\/wisgoon.com\/\">Wisgoon<\/a><\/strong> &#8211; a photo sharing platform, clone of Instagram.<\/li><\/ul><p>\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6a967a4 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6a967a4\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d61a57c\" data-id=\"d61a57c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cab430e elementor-widget elementor-widget-heading\" data-id=\"cab430e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">BONUS: Additional online resources on Iran<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-4919843 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"4919843\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-16079c8\" data-id=\"16079c8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5e66c40 elementor-widget elementor-widget-text-editor\" data-id=\"5e66c40\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Here is a mix of some official and unofficial sources of information on Iran and Iran-related topics that have dominated the headlines in the past several years.<\/p><p>Reader beware: some of the content might present political bias or be slightly outdated, so do your own research before taking anything as gospel!<\/p><ul><li><a href=\"https:\/\/www.cia.gov\/library\/publications\/the-world-factbook\/geos\/ir.html\">The CIA World Factbook on Iran<\/a><\/li><li><a href=\"https:\/\/www.cia.gov\/search\/?q=iran&amp;site=CIA&amp;output=xml_no_dtd&amp;client=CIA&amp;myAction=%2Fsearch&amp;proxystylesheet=CIA&amp;submitMethod=get\">CIA reports and publications<\/a><\/li><li><a href=\"https:\/\/www.globalfirepower.com\/country-military-strength-detail.asp?country_id=iran\">Global Firepower: Iran&#8217;s Military Strength (2020)<\/a><\/li><li><a href=\"https:\/\/www.dia.mil\/Portals\/27\/Documents\/News\/Military%20Power%20Publications\/Iran_Military_Power_LR.pdf\">Defense Intelligence Agency: Iran Military Power<\/a><\/li><li><a href=\"https:\/\/www.armscontrol.org\/blogs\/P4-plus-Iran-nuclear-talks-and-deal-alerts\">Arms Control Association &#8211; Iran Alerts<\/a><\/li><li><a href=\"https:\/\/iranprimer.usip.org\/\">The Iran Primer<\/a><\/li><li><a href=\"https:\/\/isis-online.org\/search\/google?cx=001381580300407989689%3Aboguwei5u3k&amp;ie=UTF-8&amp;q=iran&amp;sa.x=0&amp;sa.y=0\">Institute For Science And International Security<\/a><\/li><li><a href=\"https:\/\/www.iranwatch.org\/\">Iran Watch<\/a><\/li><li><a href=\"https:\/\/www.recordedfuture.com\/iran-hacker-hierarchy\/\">Recorded Future &#8211; Iran Hacker Hierarchy<\/a><\/li><li><a href=\"https:\/\/smallwarsjournal.com\/search\/node?keys=iran\">Small Wars Journal &#8211; Iran<\/a><\/li><li><a href=\"https:\/\/www.rand.org\/blog.topic.iran.html\">The Rand Blog &#8211; Iran<\/a><\/li><li><a href=\"https:\/\/www.unitedagainstnucleariran.com\/\">United Against Nuclear Iran<\/a><\/li><li><a href=\"http:\/\/iranintelligence.com\/relatedtoc\">Iran Intelligence<\/a><\/li><li><a href=\"https:\/\/irandataportal.syr.edu\/about-us\">Iran Data Portal<\/a><\/li><li><a href=\"https:\/\/www.parseek.com\/EnglishNews\/?c=iran\">Parseek News<\/a><\/li><li><a href=\"https:\/\/www.treadstone71.com\/index.php\/intel-briefs\/irgcinfluenceops\">Treadstone71 &#8211; Iranian Influence Operations<\/a><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>In this quasi-investigative piece I explore various layers of Iranian digital ecosystems, providing a good deal of resources for starting open source enquiries into Iran.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[93],"tags":[80,120,100,29,116,32,57],"class_list":["post-1205","post","type-post","status-publish","format-standard","hentry","category-my-investigations","tag-domain","tag-iran","tag-isp","tag-links","tag-search","tag-social-media","tag-terrorism"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/1205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=1205"}],"version-history":[{"count":127,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/1205\/revisions"}],"predecessor-version":[{"id":1381,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/1205\/revisions\/1381"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=1205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=1205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=1205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}