- If you're interested in the technical aspects of #DNCHack, implant and attribution, here's @CrowdStrike's analysis: https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/ …
https://twitter.com/pwnallthethings/status/742758448056684544
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:39:48 - .@CrowdStrike assertion is that first hacking group (FANCY BEAR) in #DNCHack is APT28. If so, that is a strong attribution to Russia.
https://twitter.com/pwnallthethings/status/742759010177323008
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:42:02
.@CrowdStrike says the "COSY BEAR" group in #DNCHack is RU for this reason. But tbh, looks more like a piggyback op pic.twitter.com/SVFubyejAFhttps://twitter.com/pwnallthethings/status/742759698324164608
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:44:46
COSYBEAR is an interesting implant. Python and Powershell; comms via .NET using AES with a fixed sym-key #DncHack pic.twitter.com/CpCXNEQTuxhttps://twitter.com/pwnallthethings/status/742760510098186240
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:48:00
That puts COSYBEAR here on the @daveaitel implant-sophistication scale :) #DncHack pic.twitter.com/DXNIhVplhxhttps://twitter.com/pwnallthethings/status/742760889242296320
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:49:30
Fixed IV/key in COSYBEAR means can traffic-decrypt from pcap. Clearly not written by folks who know crypto #DNCHack pic.twitter.com/BrPLBNjli9https://twitter.com/pwnallthethings/status/742761486611845121
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:51:52https://twitter.com/pwnallthethings/status/742761838841106432
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:53:16
lolwtf? COSYBEAR operators apparently are lame script kiddies. Clearing event logs is like the worst opsec #DncHack pic.twitter.com/KW2AA1iW7ahttps://twitter.com/pwnallthethings/status/742762660211658752
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 16:56:32
Serious Q: What AV does DNC run? How did it possibly miss an implant clearing win-event logs w/ WMI persistance? pic.twitter.com/bls5QPOn8Rhttps://twitter.com/pwnallthethings/status/742764971994578944
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 17:05:43
For some reason @CrowdStrike listing IOCs as SHA256, when industry standard is SHA1. Makes it harder to search for. pic.twitter.com/p2BQY92hXzhttps://twitter.com/pwnallthethings/status/742767843360550912
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 17:17:08- .@CrowdStrike Also for some reason clearly have, but aren't sharing the binaries. Seems optimized to stop people checking their results.
https://twitter.com/pwnallthethings/status/742768553728839680
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 17:19:57
Btw, if you want to piggyback onto COSYBEAR, its startup module downloaded w/ fixed AES/IV dl-ed over HTTP (port80) pic.twitter.com/HejStU8MWihttps://twitter.com/pwnallthethings/status/742770109706608644
— Pwn All The Things (@pwnallthethings)Tue, Jun 14 2016 17:26:08
storify.com
