Our research results are based solely on irrefutable evidence obtained through various forensic tools expertly wielded by professionals. This following report may be completely corraborated by Law Enforcement using our data. They shall have no problems to obtain access to full communication logs and email account of the perpetrator.
Meet Robert M. Behrens from Shawnee, KS — a pedophile and a danger to society. He is living at 10706 w. 72nd st 66203 and accessible by the phones (913) 631-7275, (913) 696-8023, (913) 709-5203, (913) 401-5579. As usual, we took a bunch of reserve snapshots of his facebook account in case he is going to delete it.
We found Mr. Behrens at the child pornography website where a lot of pedophiles were exchanging pictures and videos. We were able to locate the server where the aformentioned website is hosted. By exploiting the security vulnerabiloties we gained a full control over the server. And the analysis of the mountains of data then followed.
Here is what we've found in connection to Robert.
First we found a credit card details that Robert provided when he tried to purchase an access to the special sections of the child pornography website. 0n 05/Nov/2018 10:24:20 AM CDT Robert posted his credit card with a purpose of getting an access to all sections of the website. Here is what he entered:
You see his name, address, phone and CC details. Also you can see the IP address of his machine. Here is what you can get from a simple geolocation check on that IP:
ISP Organization: Spectrum
What really surprised us is how naiive Robert is. As we already mentioned in our previous report about pedophile Bryan Nichols, we modified the purchase form in such a way that it asks for an additional info after the CC was entered. We requested such things as facebook account, SSN, DOB, even things like shoe size. To our surprise. Robert filled out all info. We mean — everything. Take a look:
To prove that information Robert provided is correct, we successfully registered an account on creditkarma.com and pulled a bunch of reports from there -- take a look: all of his credit cards, his previous problems with a law, his unpaid student loans etc.
Robert even correctly entered his facebook info -- you can check it yourself by entering his email and a password he provided. But since Robert already changed a password, the facebook will respond that you are trying to use an old password. It was easv to connect Robert's email with his facebook handler by performing a search on TruthFinder.com
Here is the list of private messages Robert sent to the administration of a forum where he initially requested a child pornography packages and then he explained that he was unable to purchase anything.
This is an excerpt from the log of the webserver. Lets pull apart one of the lines and you will get an idea what it is about:
the last line:
/var/log/httpd/custom_access_log-20181105:3735:rmbehre1 [Sun 11/04/2018 @ 06:11:30.708 PM MSK] /var/sandbox/gui/sand/files/pictures/ 7yo_vicky_jumping_on_her_fathers_cock.jpg 184.108.40.206 "Mozilla/5.0 (Linux; Android 5.0.2; SM-T357T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.80 Safari/537.36" W98MIj8BkyY7DzLDOz@fcgAAAIM
/var/log/httpd/custom_access_log-20181105:3735 - log file of the webserver and a line number at which the information was found
rmbehre1 - this is a name of the user which is issued a request. We already ascertained that this is Robert Behrens.
[Sun 11/04/2018 @ 06:11:30.708 PM MSK] - date of the request. The timezone is MSK +03:00 (which is [Sun 11/04/2018 @ 09:11:30.708 AM CDT] in Central Daylight Time -06:00)
/var/sandbox/gui/sand/files/pictures/ 7yo_vicky_jumping_on_her_fathers_cock.jpg - the file which was requested. There are many more files but these are named very explicitly.
220.127.116.11 - address of the machine from which Robert issued a request. ISP of that IP is "Spectrum".
"Mozilla/5.0 (Linux; Android 5.0.2; SM-T357T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.80 Safari/537.36" - user-agent of the web-browser. In this particular case we can see that Robert is using Chrome on his Samsung Tablet.
W98MIj8BkyY7DzLDOz@fcgAAAIM - id of the forensic log (see below)
Here is a list of IP which Robert was using:
As can be seen, Robert was using only one IP address meaning that it is almost certain that he was using the same device to access child pornography website -- the machine from his own home. :)
Please remember that his ISP can corraborate our results with easiness and give it to the authorities without any doubts about any tampering made by anyone.
Actually Robert was able to open an archive and as can be seen Robert attached a disgusting picture (which is actually a few dozens of thumbnails with child pornography) which he extracted from the zip archive -- see filename "notacopnorsnitch#0001 (0).jpg".
That zip archive was a part of the letter with the instructions for a registration. He received that letter because he sent a join-request:
Robert absolutely certainly knew what he was doing and why. Nobody can make so many sequential actions by mistake. Would you agree?
We went farther than that and installed two very important changes on the server. The first change is that we switched the webserver from HTTPS protocol to the HTTP protocol. This simple change stripped all the anonymity off of Robert by transmitting ALL requests from his computers to web-server in the open without a protection of encryption. Every request Robert ever made to that particular server is now logged in plain text by ISP Spectrum and ready to be claimed by authorities.
The second change is a seamless upgrade of web-server access log capabilities. We added a forensic log module which saves exact fingerprint of a computer and can be served as a concrete and bulletproof evidence. Here is how it looks like:
Just ask Robert where he had been on the following dates (already converted to CDT timezone):
We proved that at these times he had been on the child pornography website.
The above presented facts clearly shows that Robert M Behrens knowingly and willingly became a member of a child pornography websitel He uploaded and downloaded child pornography and tried to purchase some more content while giving all possible information about himself (we bet his pet's name is really "Snickers" :) ).
Please have no illusions about this case by trying to persuade yourself that people like Robert M Behrens mean no harm. that an old man just trying to have some fun and so on. We do not know what is going on behind the screen -- may be Robert M. Behrens just "peacefully" jerking off on a pictures of children and toddlers OR ... What if he went a step farther? Would you take a chance? If not then it is now up to the authorities to investigate the case. The authorities shall have no problem to build up the case -- they just have to obtain logs from ISP and email from the Gmail. We only pointed out above what they should look for and where we do agree that the actual evidence should be obtained from the ISP and gmail, so the guilt of Robert M. Behrens would be proved beyond doubt and without any possibility of meddling from our side.
So we presented enough evidence and arguments that Robert is a rmbehre1 and that Robert is a pedophile.
Now you know the truth. Call the police and explain that Robert M. Behrens violated several federal laws and has to be arrested.