Live data from Hacker News

Technical report on DNC hack [pdf]

us-cert.gov

11–20 of 502 posts

Re: Technical report on DNC hack [pdf]

#11
post #2

>In spring 2016, APT28 compromised the same political party, again via targeted spearphishing. I think I might have missed it, but how did they conclude that it was 'APT28' ? > APT28 is known for leveraging domains that closely mimic those of targeted organizations and tricking potential victims into entering legitimate credentials. APT28 actors relied heavily on shortened URLs in their spearphishing email campaigns.…

An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future. They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.

>An intelligence agency won't declassify how they determined who it was.

Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry.

Give me a reason to trust them again?

Re: Technical report on DNC hack [pdf]

#12

This report is a joke. I didn't find any reasoning about attribution. Here is the only valuable part: " rule PAS_TOOL_PHP_WEB_KIT { meta: description = "PAS TOOL PHP WEB KIT FOUND" strings: $php = " 20KB and filesize < 22KB) and #cookie == 2 and #isset == 3 and all of them } "

That and the supporting indicator files[0].

[0] https://www.us-cert.gov/security-publications/GRIZZLY-STEPPE... This would probably be a better link for the OP than the PDF it links.

Re: Technical report on DNC hack [pdf]

#13

Earlier quoted context omitted.

An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future. They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

>Give me a reason to trust them again?

you are supposed to elect people who you trust to make these decisions. we don't have direct democracy.

Re: Technical report on DNC hack [pdf]

#14
Folks, the point of this report is not to justify the punitive actions taken today. It is to provide information that companies can use to protect themselves against similar attacks in the future.

So if you judge it by whether it "makes the case" against Russia, it will be lacking. We don't need 100 comments pointing that out.

Re: Technical report on DNC hack [pdf]

#16

    ~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|grep -f exits -c
  191
    ~ grep IPV4 JAR-16-20296.csv|awk -F ',' '{print $1}'|sed 's/[][]//g'|sort -u|wc -l           
  876
At least 191 of the IOC IPs are (probably random) Tor exit nodes :) The actual number may very well be higher, I just grabbed current exit node list from https://check.torproject.org/exit-addresses

Here's the PHP backdoor the YARA rule is for http://sprunge.us/ReFg I'll probably put up the rest of the samples in a sec.

Edit: Here, I uploaded most of the samples listed in the csv http://www.filedropper.com/samples_5

Edit 2: The obfuscation used in the russian PHP shells looked awfully familiar, I think the shell they're using could very well be this one http://profexer.name/pas/download.php originally shared on a .ru hacker forum.

Re: Technical report on DNC hack [pdf]

#17
post #9

This report is a joke. I didn't find any reasoning about attribution. Here is the only valuable part: " rule PAS_TOOL_PHP_WEB_KIT { meta: description = "PAS TOOL PHP WEB KIT FOUND" strings: $php = " 20KB and filesize < 22KB) and #cookie == 2 and #isset == 3 and all of them } "

I guess you missed https://www.us-cert.gov/sites/default/files/publications/JAR...

What exactly is this? A list of IP addresses and countries? It's unclear which attributes from this list associate the hack with Russia, and presumably it's more than IP address seeing as how trivial proxying is.

Re: Technical report on DNC hack [pdf]

#18

Folks, the point of this report is not to justify the punitive actions taken today. It is to provide information that companies can use to protect themselves against similar attacks in the future. So if you judge it by whether it "makes the case" against Russia, it will be lacking. We don't need 100 comments pointing that out.

[deleted]

Re: Technical report on DNC hack [pdf]

#20

Earlier quoted context omitted.

An intelligence agency won't declassify how they determined who it was. That would compromise their ability to use the same method (informant, vulnerability, etc) in the future. They are standard techniques. It doesn't say they are unique. Just that this hacker relies on these specific standard techniques as opposed to other ones.

>An intelligence agency won't declassify how they determined who it was. Yeah, just like a weapon of mass destruction in Iraq. We can't tell how we got this information, but we know for sure. Then few years later it turns out there is no WMD found. Ooops. Sorry. Give me a reason to trust them again?

> Give me a reason to trust them again?

There is not a good reason to do so. The trust has been broken and we should consider them corrupt if not overtly adversarial to the democratic process.

No officials took responsibility for the excesses revealed by Snowden, or promised any sort of remediation. Such smugness in the abuse of power is a very scary thing.

Post reply on HN