Eyes on China: Weibo OSINT

Updated: Nov 2, 2023

Image Credit: Lehel Kovaks

Disclaimer: This article does not endorse hacking, any active operations, or anything unlawful; it only discusses open source intelligence, information publicly available and unconventional approaches to acquiring information online. Majority of western investigators, (such as journalists, PI, Law Enforcement, and anyone who part of their line of work relies on open source intelligence - OSINT) is inevitably facing challenges in working around, and navigating the Chinese ecosystem smoothly, that is specifically major obstacles in understanding context of text, discussions, chatter, "domestic" social & communication platforms, influential factors on the entire process of OSINT delivery such as language, business practices, ethics, cultural, censorship and really anything and everything that influences your job as the "analyst" to collect, identify, and analyze data from Chinese sources of information today.

Our academy offers those individuals, organizations and professionals in the field of OSINT, HUMINT, SOCMINT, IMINT and other practices, an advanced Chinese OSINT Investigator course

Today, we are the only educational institution and academy offering such advanced course.

You can continue reading trough this blog or watch the video version of this blogpost

Text version:

Let's imagine during your investigation online you found an image online, that image is hosted on the Weibo ( servers. You see in the URL of that img that it has format like this (or similar) example:

Take the first 8 characters after the / of the first unique identifier in the URL, (see highlighted red).

Open any kind of hexadecimal converter, because the first 8 characters are actually in fact the hexadecimal value of the UID > which leads to the user profile in the Weibo platform with which you can find who posted a particular image.

Conver these 8 chars to decimal (numbers) same way you see in this screeshot, then copy the converted value from row "10" -> this right here is the converted value that represents the user profile identification.

Now open a new tab in the browser, type in "" where "value" is the converted value. so now ideally you identified a user profile on the platform which has posted that particular image.

Some next steps:

  1. Crawl images to cross match and verify that the image URL is the same one from the profile images.

  2. You can apply this method to any image hosted via any subdomain on Weibo, to any user, and almost any case scenario using this specific method.

This is just a drop in the ocean example with some of the creative out of the box manual methods that exist out there for conducting OSINT on and within China.

We put a lot of emphasis on "out of the box" approaches and things that are less "conventional" for information gathering, such as combining penetration testing methods and hacker mindset to the typical day to day processes of an OSINT analyst, allowing you to get better, maximized results, all while having a different perspective and lens.

This post is just one example out of many that exist out there and out of those that we teach in our advanced course.

