It looks like you're using an Ad Blocker.
Please white-list or disable AboveTopSecret.com in your ad-blocking tool.
Thank you.
Some features of ATS will be disabled while you continue to use an ad-blocker.
For those of us that understand transfer speeds, can you point out how the Russian hackers transferred the contents of a thumb drive to the Kremlin?
Just wondering, because math is important in the real world...
In this report, we analyze the time zone offset that was likely in force when Guccifer 2’s first five (5) Word documents were written. We also look at the time of day pattern of the “last modified” times for the 25/so documents that Guccifer 2 modified and then uploaded to his blog site.
Finally, we look at one particular Word document that Guccifer 2 uploaded, which had “track changes” enabled. From the tracking metadata we deduce the time zone offset in effect when Guccifer 2 made that change — we reach a surprising conclusion: The document was likely saved by Guccifer 2 on the West Coast, US.
Using a technique recently disclosed by another researcher (David Blake), we were able to establish GMT time zone offsets for Guccifer 2’s first five (5) Word documents. Four of those documents (1.doc, 2.doc, 3.doc, and 5.doc) were created with GMT+3 time zone settings in effect. (During the summer of 2016, GMT+3 would have applied to Central Europe, the Middle East, and Western Russia.) One document, 4.doc, was created with GMT+4 time zone settings in force.
We deduce that 4.doc‘s GMT+4 time setting indicates that Russian time zone settings were in force when that document was saved. This conclusion derives from the possible use of an outdated cracked Windows XP OS which did not receive updates to its time zone tables. Hypothetically, this unpatched OS was not updated to reflect the fact that Moscow/Russia dropped Daylight Saving Time for Western Russia in 2014. This conclusion also depends upon the user not adjusting their time zone offset manually for over three months after the time zone should have been corrected.
Given that the user did not manually disable the DST time adjustment, we suggest that 4.doc may have been created on a VM that was purpose-built to “telegraph” the use of Russian time zone settings.
We construct a histogram of the time of day that Guccifer 2 last modified the 25/so documents that he changed mainly for the purposes of manipulating their metadata (such as “last saved by” user, company name, etc). This histogram supports the conclusion that Guccifer 2 operated out of a region with a GMT+3 time zone offset in force.
We analyze the timestamp on an internal “track changes” entry created by Guccifer 2 when he modified a document that was published in his second batch of documents that were uploaded to his WordPress site. We correlate this timestamp to the document’s “modified” (“last saved”) time recorded in the document’s metadata. Based on this analysis, we reach the surprising conclusion that this document was created on a system which had Pacific Daylight Saving Time (PDT) settings in force, when the change was made.
The PDT finding draws into question the premise that Guccifer 2 was operating out of Russia, or any other region that would have had GMT+3 time zone offsets in force. Essentially, the Pacific Time Zone finding invalidates the GMT+3 time zone findings previously described.
It has since been proved through meta-data that the files Guccifer 2.0 uploaded “NGP-VAN” were copied locally not hacked, Disobedient Media reported.
“Look, about the server in Chappaqua, in New York state,” he said. “That server was scanned well before me. It was scanned 2012, from IP numbers in Serbia, Belgrade, it was scanned again in 2013 from IPs in Ukraine and Russia.
The point is, somebody had mirrored, had copied, mirrored the whole server of Hillary Clinton, the question is how many countries. One, two or three? At one point, it was the whole server. I just think, I'm sure some people, I can say some people, I'm sure some people have the server contents.”
FBI Director James Comey denies that Guccifer ever hacked Clinton’s server despite outdated software and that the server was open to RDP and VNC connections which wouldn’t have even required any actual hacking, according to the Register.
“He did not. He admitted that was a lie,” Comey said. “We do assess that hostile actors gained access to the private commercial email accounts of people with whom Secretary Clinton was in regular contact from her personal account.”
On June 12 last year, Julian Assange announced that WikiLeaks had and would publish documents pertinent to Hillary Clinton’s presidential campaign.
On June 14, CrowdStrike, a cyber-security firm hired by the DNC, announced, without providing evidence, that it had found malware on DNC servers and had evidence that Russians were responsible for planting it.
On June 15, Guccifer 2.0 first appeared, took responsibility for the “hack” reported on June 14 and claimed to be a WikiLeaks source. It then posted the adulterated documents just described.
On July 5, Guccifer again claimed he had remotely hacked DNC servers, and the operation was instantly described as another intrusion attributable to Russia. Virtually no media questioned this account.
originally posted by: Sillyolme
Trump needs to cancel his meeting with Putin and come home and increase sanction against them. NOW
originally posted by: Sillyolme
a reply to: Middleoftheroad
Wasted? Wow. What do you think should have haopened? Just let it go cuz oh well?
originally posted by: theantediluvian
a reply to: Lumenari
For those of us that understand transfer speeds, can you point out how the Russian hackers transferred the contents of a thumb drive to the Kremlin?
Just wondering, because math is important in the real world...
It's a complete joke that 22mb/s is unattainable over the Internet. I do 20mb/s+ between VPSes in Houston, TX and Windsor, Ontario on a regular basis.
The Forensicator wrote that if 1.98 GB of data had been copied at a rate of 22.6 MB/s