Live data from Hacker News

US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

wordfence.com

1–10 of 120 posts

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#2
The conclusions are of particular note:

"The IP addresses that DHS provided may have been used for an attack by a state actor like Russia. But they don’t appear to provide any association with Russia. They are probably used by a wide range of other malicious actors, especially the 15% of IP addresses that are Tor exit nodes.

The malware sample is old, widely used and appears to be Ukrainian. It has no apparent relationship with Russian intelligence and it would be an indicator of compromise for any website."

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#3

The conclusions are of particular note: "The IP addresses that DHS provided may have been used for an attack by a state actor like Russia. But they don’t appear to provide any association with Russia. They are probably used by a wide range of other malicious actors, especially the 15% of IP addresses that are Tor exit nodes. The malware sample is old, widely used and appears to be Ukrainian. It has no apparent relati…

That's the conclusion anyone working in the security/network area was bound to arrive at.

It's really interesting FBI/DHS would make those claims publicly when the chance of having any hard evidence of that would be minimal. But they still did it. Why?

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#4
The php malware is the least interesting piece of all the alleged activity. Being a version behind isnt significant. Its a simple common hacker tool. My postgresql is a few versions behind. So what ? If RIS had used obvious elite tools with impressive functionality then it would point straight to them. Its much smarter to look amateur.

The JAR should have declassified something juicy. They put out this weak report, revealed nothing and now critics will attack and win. Maybe its the US that are a bunch of amateurs.

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#5
post #3

The conclusions are of particular note: "The IP addresses that DHS provided may have been used for an attack by a state actor like Russia. But they don’t appear to provide any association with Russia. They are probably used by a wide range of other malicious actors, especially the 15% of IP addresses that are Tor exit nodes. The malware sample is old, widely used and appears to be Ukrainian. It has no apparent relati…

That's the conclusion anyone working in the security/network area was bound to arrive at. It's really interesting FBI/DHS would make those claims publicly when the chance of having any hard evidence of that would be minimal. But they still did it. Why?

To me the ongoing 'Russia rigged elections' smells like propaganda from the other side. And maybe russia did release the DNC emails, but Assange said that wasn't the case and I feel he's more likely to be telling the truth than state players. And even if they did release these emails it's hardly rigging an election. Comneys email announcement at the 11th hour about reopening email investigation was probably a deciding variable and that was hardly Russian lead.

Your question of 'why' seems to be the scariest. US lead activities have been encircling Russia and pressing influence right to their borders for some time. For me I feel its too far and they are cornering the bear. Probably there is too much resource in the 'spy' world and they have to do something to justify their position, hence the older generation keep the pressure on Russia from their cold war agenda or they are looking to pick a fight. The latter being very scary.

...but really I'm no expert and just wonder why countries can put more effort to looking after their own populations needs. All this spy/military expenditure seems so wasteful.

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#6
post #3

The conclusions are of particular note: "The IP addresses that DHS provided may have been used for an attack by a state actor like Russia. But they don’t appear to provide any association with Russia. They are probably used by a wide range of other malicious actors, especially the 15% of IP addresses that are Tor exit nodes. The malware sample is old, widely used and appears to be Ukrainian. It has no apparent relati…

That's the conclusion anyone working in the security/network area was bound to arrive at. It's really interesting FBI/DHS would make those claims publicly when the chance of having any hard evidence of that would be minimal. But they still did it. Why?

a) Anyone who thinks this document is the sole source of evidence is deluding themselves. The intelligence agencies are not going to document their capabilities to the world. Which I am sure would include compromised Tor nodes and DPI (including SSL/encrypted traffic) across many of the key sites/switches/cables.

b) It has been claimed that this document is more a guide for other companies and government agencies about the type of techniques that Russia allegedly used. General education about security is still pretty low and the US government et al are going to need to more in this area.

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#7
post #3

Earlier quoted context omitted.

That's the conclusion anyone working in the security/network area was bound to arrive at. It's really interesting FBI/DHS would make those claims publicly when the chance of having any hard evidence of that would be minimal. But they still did it. Why?

To me the ongoing 'Russia rigged elections' smells like propaganda from the other side. And maybe russia did release the DNC emails, but Assange said that wasn't the case and I feel he's more likely to be telling the truth than state players. And even if they did release these emails it's hardly rigging an election. Comneys email announcement at the 11th hour about reopening email investigation was probably a decidin…

Nobody said Russia rigged the election. The issue was the attempts to influence the election which Russia has a long, documented history of doing so. And the US had an obligation to respond which they did with minimal effect. So claiming all of this was about propaganda really makes no sense given the facts on the ground.

And please remember why Russia's relations with almost all of the world deteriorated in the first place. It's because they annexed Crimea (unprecedented for our generation) and allowed soldiers and weapons to flood into Ukraine which then resulted in Flight 117 being shot down.

Nobody is looking for a fight with Russia but capitulating and doing nothing is not an answer either. Diplomatic sanctions have been the correct response and I don't see anyone asking for an escalation of that.

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#8
Anyone who has run a wordpress or vbulletin site has probably seen this at some point in time. Got tonnes of logs from IPs in Ukraine, Russian, China, etc that crawl for holes and if they find one you will find something like this somewhere. VBulletin is the worst - executable code is stored in the database so that's where you'll likely find it.

I find it hard to believe this is what a state sponsored attack would look like - in business, we see this all the time.

I would love to see some action taken on this, there's probably tonnes of time and post business spent on these attacks. I just don't want to see that solution in the form of slanderous claims that paint it as more than it is.

Re: US Govt Data Shows Russia Used Outdated Ukrainian PHP Malware

#10
post #9

Someone around the GOP could merely have hired a hacker from Eastern Europe or Russia specifically to do the hacking. I find it troubling that this avenue was not explored.

I find it troubling that this avenue was not explored.

What indication do you have that it wasn't?

Post reply on HN