Register for our upcoming webinar about corporate security! Cyber Meets Physical Security: Threat Assessment for Corporate Security with Prescient on Wednesday, April 03, 2024 at 17:30 CET. Register now! close
19 Jan 2023

Unmasking a Darkweb Persona: scaryred24

Mathieu Gaucheler

Uncovering Information on a Dark Web Gun Seller đź”—︎

Dread can be considered the Reddit of the Dark Web and, just like Reddit, it is subdivided into different sub forums known as subdreads. The subdread named [/d/murderhomelesspeople] is the sub forum where drug dealers (or people pretending to be one) discuss their different experiences. In this case study, we will investigate the persona of Scaryred24, an individual who offered a gun for sale in a thread posted to this subdread.

Chancing Upon Scaryred24 đź”—︎

The image below shows the Dread post found on the onion site Dread. The post, made by the user okbuddydread around October 2021, notes that they want to take revenge against their drug dealer who allegedly owes them money.

The dread post on the onion site Dread made by the user okbuddydread

Amongst the 20 comments added to this post, we found one comment by the user scaryred24, who offers to sell a gun to okbuddydread.

The comment by the user scaryred24 offering to sell a gun

At this stage, it is already possible to gather significant information from these posts. To begin with, the username scaryred24 seems quite unique. And, given that scaryred24 offers to sell a “piece” (firearm) to the poster if they are in or around the Boston area, it can be assumed that they are located somewhere within that area. Lastly, scaryred24 has also provided a phone number on which they can be contacted via WhatsApp or text.

This information already provides a good start to an investigation. The different pieces can be used as starting points to see what kind of information we could gather to unmask the person hiding behind the user scaryred24.

Investigation Methods & Workflows đź”—︎

With the known username on Dread, we used ShadowDragon SocialNet and Pipl to investigate the person behind scaryred24.

First, we retrieved social media profiles sharing the same username using ShadowDragon SocialNet, which also led to a Paypal account associated with a full name. After a series of extensive analysis on the returned GitHub, Twitter, Gab, Myspace, and Reddit accounts, we were able to make hypothesis about the hobbies, location, and political interests of the person behind scaryred24. These information allowed us to discover a new username potentially controlled by scaryred24.

We then went back to the full name associated with the PayPal account. Using ShadowDragon SocialNet, we retrieved a few social media platforms as well as websites where this name was mentioned. This led us to discover arrest reports and news articles about this person’s criminal history.

Finally, we used Pipl Transforms to obtain more personal identifiers related to this name. The Transforms returned the same location where we believed scaryred24 resided in, as well as a phone number that scaryred24 shared in the original Dread post.

Download this Case Study for A Detailed Investigation Walk-Through! đź”—︎

This case study demonstrated the step by step on how we gathered and combed through social media information to discover the persona behind scaryred24.

Download it now to learn how to efficiently and effective combine information from multiple social media platforms and derive specific personal identifier data!

Download the resource

DE +49
Albania +355
Algeria +213
Andorra +376
Angola +244
Anguilla +1264
Antigua And Barbuda +1268
Argentina +54
Armenia +374
Aruba +297
Australia +61
Austria +43
Azerbaijan +994
Bahamas +1242
Bahrain +973
Bangladesh +880
Barbados +1246
Belarus +375
Belgium +32
Belize +501
Benin +229
Bermuda +1441
Bhutan +975
Bolivia +591
Bosnia and Herzegovina +387
Botswana +267
Brazil +55
Brunei Darussalam +673
Bulgaria +359
Burkina Faso +226
Burundi +257
Cambodia +855
Cameroon +237
Canada +1
Cape Verde +238
Cayman Islands +1345
Central African Republic +236
Chile +56
China +86
Cote d'Ivoire +225
Colombia +57
Comoros +269
Congo +242
Cook Islands +682
Costa Rica +506
Croatia +385
Cuba +53
Cyprus +90392
Czech Republic +42
Denmark +45
Djibouti +253
Dominica +1809
Dominican Republic +1809
Ecuador +593
Egypt +20
El Salvador +503
Equatorial Guinea +240
Eritrea +291
Estonia +372
Ethiopia +251
Falkland Islands (Malvinas) +500
Faroe Islands +298
Fiji +679
Finland +358
France +33
French Guiana +594
French Polynesia +689
Gabon +241
Gambia +220
Georgia +7880
Germany +49
Ghana +233
Gibraltar +350
Greece +30
Greenland +299
Grenada +1473
Guadeloupe +590
Guam +671
Guatemala +502
Guinea +224
Guinea-Bissau +245
Guyana +592
Haiti +509
Honduras +504
Hong Kong +852
Hungary +36
Iceland +354
India +91
Indonesia +62
Iran, Islamic Republic of +98
Iraq +964
Ireland +353
Israel +972
Italy +39
Jamaica +1876
Japan +81
Jordan +962
Kazakhstan +7
Kenya +254
Kiribati +686
Korea, Democratic People's Republic of +850
Korea, Republic of +82
Kuwait +965
Kyrgyzstan +996
Lao People's Democratic Republic +856
Latvia +371
Lebanon +961
Lesotho +266
Liberia +231
Libyan Arab Jamahiriya +218
Liechtenstein +417
Lithuania +370
Luxembourg +352
Macao +853
Macedonia, the former Yugoslav Republic of +389
Madagascar +261
Malawi +265
Malaysia +60
Maldives +960
Mali +223
Malta +356
Marshall Islands +692
Martinique +596
Mauritania +222
Mauritius +230
Mayotte +269
Mexico +52
Micronesia, Federated States of +691
Moldova, Republic of +373
Monaco +377
Mongolia +976
Montserrat +1664
Morocco +212
Mozambique +258
Myanmar +95
Namibia +264
Nauru +674
Nepal +977
Netherlands +31
New Caledonia +687
New Zealand +64
Nicaragua +505
Niger +227
Nigeria +234
Niue +683
Norfolk Island +672
Northern Mariana Islands +670
Norway +47
Oman +968
Pakistan +92
Palau +680
Panama +507
Papua New Guinea +675
Paraguay +595
Peru +51
Philippines +63
Poland +48
Portugal +351
Puerto Rico +1787
Qatar +974
Reunion +262
Romania +40
Russian Federation +7
Rwanda +250
San Marino +378
Sao Tome and Principe +239
Saudi Arabia +966
Senegal +221
Serbia +381
Seychelles +248
Sierra Leone +232
Singapore +65
Slovakia +421
Slovenia +386
Solomon Islands +677
Somalia +252
South Africa +27
Spain +34
Sri Lanka +94
Saint Helena +290
Saint Kitts and Nevis +1869
Saint Lucia +1758
Sudan +249
Suriname +597
Swaziland +268
Sweden +46
Switzerland +41
Syrian Arab Republic +963
Taiwan +886
Tajikistan +7
Thailand +66
Togo +228
Tonga +676
Trinidad and Tobago +1868
Tunisia +216
Turkey +90
Turkmenistan +993
Turks and Caicos Islands +1649
Tuvalu +688
Uganda +256
United Kingdom +44
Ukraine +380
United Arab Emirates +971
Uruguay +598
United States +1
Uzbekistan +7
Vanuatu +678
Holy See (Vatican City State) +379
Venezuela +58
Viet Nam +84
Virgin Islands, British +84
Virgin Islands, U.S. +84
Wallis and Futuna +681
Yemen +967
Zambia +260
Zimbabwe +263

By clicking on "Access", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.

Don’t forget to follow us on Twitter and LinkedIn and sign up to our email newsletter, so you don’t miss out on updates and news!

Happy investigating!

About the Author đź”—︎

Mathieu Gaucheler

Mathieu Gaucheler Mathieu Gaucheler is a subject matter expert at Maltego. His responsibilities include research-driven content development for blog posts, webinars, and talks. He started working in cybersecurity in Barcelona, focusing on malware analysis and sandbox development. He has previously presented his research at BotConf and RSA APJ.

By clicking on "Subscribe", you agree to the processing of the data you entered and you allow us to contact you for the purpose selected in the form. For further information, see our Data Privacy Policy.