6 ms·
Wikileaks Global Intelligence File Dump Contained Malicious Software
- kstenerud 11y agoOkay... so the computer they grabbed the data from was infected with various old malware. So why the link bait title?
- csvan 11y agoAliens.
- higherpurpose 11y agoBecause Wikileaks is out to get you.
- joshwieder 11y agoI do not understand what about the title is linkbait. If you are circulating any sort of file you should announce the presence of malware or remove it.
- joshwieder 11y agoparticularly when the people viewing those files will be journalists and activists who very much need to protect themselves from surveillance
- mikeash 11y agoThe way it's worded heavily implies that this was done on purpose to hurt anyone who tries to view this stuff, and that you will get infected if you try to download it.
- deleted 11y ago[deleted]
- ethanbond 11y agoI'm not sure how you could word it differently. It implies nothing, and the article itself explicitly denies any finger-pointing. > I ought to be clear from the outset: I have no information linking Wikileaks, Asssange, Hammond, Monsegur, the FBI or anyone else directly with these malicious files. That very well may change quickly as research progresses, but at no point should this post be considered finger pointing. The purpose of this post is not to assign responsibility but to ensure that the journalists and activists downloading these files or who have already downloaded these files understand the consequences and take proper precautions. If I can encourage security researchers to take a look at these files it would be a bonus. Also answers your question of "why the [arguably] click-bait title?" To get attention, which it deserves.
- mikeash 11y agoI think the headline would be much better like, "Wikileaks Global Intelligence File Dump Contains a Great Deal of Malicious Software." The problem is "loaded" which has two rather different meanings in this context. "X is loaded with Y" can just mean that X contains a lot of Y, but it can also mean that someone loaded a lot of Y into X. If you go for the second meaning, which is an entirely natural reading of the original headline, then the headline is saying "Someone (such as the NSA or their friends) put a lot of malware into this stuff." As to the "why" question (which for the record was not mine) I don't think it's justifiable to use a misleading headline just because the information is important. Although I imagine the misleading nature of this headline was entirely unintentional.
- balls187 11y agoIt depends on how you parse loaded. I parsed it as "Loaded" as in the way I like my Baked Potatoes "Loaded" with Sour Cream and Bacon. I can see how you parsed it the other way. Reading the authors other posts--would it be worth giving him the benefit of the doubt that the author wasn't trying link bait?
- mikeash 11y agoYou leave me wondering if you read my comment, since "it depends on how you parse loaded" is most of what I said, and I explicitly gave the author the benefit of the doubt by saying it was probably unintentional.
- eli 11y agoTrue, though if you're downloading some else's entire mailspool you should expect to find viruses and spam and malware.
- Mithaldu 11y ago"Loaded with" vs. "contains a little".
- duskwuff 11y agoMore accurately, it appears that the dump included files from a mail server which, like most mail servers these days, received some messages with virus-laden attachments. It doesn't appear to be anything obviously malicious on the part of the creators of the dump, or Stratfor, or even Wikileaks. http://www.joshwieder.net/2015/07/hector-monsegur-formerly-sabu-of.html http://www.joshwieder.net/2015/07/hector-monsegur-formerly-s...
- themeek 11y agoSo it looks like there's not much of a worry someone has from looking through those files themselves. Personally I have looked through these files and have not run into any malware issues pointed out by the article. I found it very informative and interesting to look through the intelligence files. One of my favorite finds are the docs on CANVAS and some of the US destabilization operations in Venezuela and color revolutions.
- joshwieder 11y agoIt is the latest torrent file. The file is still there, and still is the malware.
- gorgak 11y agothis seems like a non-issue to me as well. you would expect malicious stuff to be there surely.
- joshwieder 11y agoThere is one specific torrent at issue here. It is the latest torrent, gifiles-2014.tar.bz2.torrent. I identified 20 malicious files in my post: gifiles-2014\gifiles\attach\6\6566_The Split Betw.doc gifiles-2014\gifiles\attach\19\19701_MASY - Q MASY HUMINT.doc gifiles-2014\gifiles\attach\19\19719_List of Addresses - Advance Copies.doc gifiles-2014\gifiles\attach\152\152977_Happy vacation.pdf gifiles-2014\gifiles\attach\18\18714_Research_and_R.xls gifiles-2014\gifiles\attach\117\117687_Lithium.doc gifiles-2014\gifiles\attach\117\117870_Hybrid write-up2.doc gifiles-2014\gifiles\attach\117\117793_Hybrid write-up.doc gifiles-2014\gifiles\attach\47\47247_US Congress re.doc gifiles-2014\gifiles\attach\47\47329_US Congress re.doc gifiles-2014\gifiles\attach\52\52004_IRAN_STRAIT_PART.pdf gifiles-2014\gifiles\attach\151\151784_Command.com gifiles-2014\gifiles\attach\151\151098_text.zip->(Zip) gifiles-2014\gifiles\attach\151\151098_text.zip->text.exe gifiles-2014\gifiles\attach\119\119443_Russia Data Requests.doc gifiles-2014\gifiles\attach\142\142345_photos.zip->(Zip) gifiles-2014\gifiles\attach\142\142345_photos.zip->photos.jpg.exe gifiles-2014\gifiles\attach\146\146924_message.zip->(Zip) gifiles-2014\gifiles\attach\146\146924_message.zip->message.exe gifiles-2014\gifiles\attach\17\17102_Draft scenarios for Libya_0416.pdf If it is your position that these files do not contain malicious files in the torrent I stated, please back up your conclusion with the level of research that I provided in my post(s) on the topic. For all files provide the hashes, for .DOC files provide the output of an application showing no macros or embedded OLE's exist, explain the presence of executables of .COM files in the torrent, provide a hex-dump of the PDFs. As for the next comment's claim that the presence of malware in this sort of file distribution is irrelevant, such a position is nothing short of madness. These files are viewed by journalists and activists. Malicious software like this, regardless of its source, can compromise the identities of those journalists and activists. The only way I could understand such a contention would be if you were to also claim that journalists and activists should be "outed" for working on such documents. To that claim, I strenuously disagree. I think that those working on these documents should be able to remain private and protected. This is not a torrent containing a pirated movie. This is a torrent containing leaked documents from a defense contractor, provided on a website that (rightly I believe) claims to be a news organization. Would you think that Fox News embedding malware in their website's flash player would be no big deal? For those of us working toward a safe and secure internet, malware should be removed and/or users notified wherever it exists. Mine is not an extremist position.
- joshwieder 11y agoHector Monsegur has commented on the files & their relevance: http://www.joshwieder.net/2015/07/hector-monsegur-formerly-sabu-of.html http://www.joshwieder.net/2015/07/hector-monsegur-formerly-s...
- themeek 11y agoIt's an interesting problem: * If Wikileaks edits the content it can be criticized for tampering. * If Wikileaks leaves malware in it can be criticized for circulating malware. It may also give an excuse to search engines and other partners of the government to block the site on account of it hosting files that are infected. A pretty nasty no-win situation. Also think about what this means for the sources of the documents. It means that the surveillance and intelligence information from these firms was likely compromised. Yikes.
- EthanHeilman 11y agowikileaks could flag infected content and force people to click a "I know what I'm doing" button to download or view.
- mikeash 11y agoWhat's wrong with providing one dump without malware, and a second dump of just the infected files, which when put together gives you the whole thing? That way you have full disclosure, the people who want the infected files can easily get it, and the people who don't want it can easily avoid it.
- themeek 11y agoI really like this solution. Critics might be able to say that Wikileaks BOTH hosts malware AND tampers with evidence - but if Wikileaks has a voice to respond it has a pretty good reply. Filters and services sometimes block entire domains because one page hosts malware. So it might be that the excuse could still be used to block Wikileaks if they did host both - but again agreed that hosting both is pretty good. It does increase the work staff at Wikileaks must do and the amount of data they have to host/manage. But yeah overall if this becomes a problem for them doing both seems like a pretty good solution. Nice!
- bmir-alum-007 11y agoIt seems like a scraper which could manage submitting to and checking virustotal would be a good idea. Also, perhaps wikileaks / virustotal could come to sort of agreement to scan things and flag them while still making assets available to researchers whom still need raw docs, but with large virus warnings which intercept downloads to a warning landing page confirmation if there's no referrer (direct, deep linking). Finally, the other issue is that not all malware (past, current or future) is known. We ran Windows Servers (NT, 2003) boxes directly on the internet (before I forced them to offer departmental firewalls) and these boxes had already attracted all sorts of multi-vendor unseen malware, rootkits and backdoors long before I got there. After deploying WOLF to a number of boxes, Mark Russinovich was like "yea, you should probably take [the IT sec depts advice]" by just get firewalls and then format all these boxes back to clean image, fully-patched and strong, production-usable, security policy state. Most IT folks don't conduct forensics research... they see strange behavior, try to find a scanner/remover (maybe 80% success), or partially remove it and continue despite unprovable to fully remove all traces... Or they wipe the boxes, start over and guess/pray that the same 'sploit doesn't exist twice. There's just too many unknown variants of existing sploits and too many new sploits to have much faith in antivirus (it's reactive, last line-of-defense security). Antivirus is an opposite Bloom filter... it'll tell you if you're pwned or may not pwned. It's a good to have, just not a complete holistic security posture.
- bmir-alum-007 11y agoEdit: One box had really crazy, clever malware (backdoor IRC bot which was firmly detectable by NIDS (snort) and by remote nmap) which defeated local nmap, portmon and rootkitrevealer... and it was a 24x7 production oracle box (no HA or archive log mode master-slave repl) running the dining order, meals and inventory databases, so live cd / usb-hdd-specialized hdd dongle (better forensics) weren't possible. 0. If I had budget authority, I would've ordered something which could grab memory and disk images on a live system and sign-up multiple .edu researchers & symantec security group and equivalent shops under NDA to analyze them. 1. And I would've yanked all those janky (R)ILO (aka RMSA, aka DRAC) cards with their always outdated Linux / Java / PHP "wifi router"-like whatever embedded systems. 2. Finally, I would've spent some cash on honeynet setups and cc: to item 0. Edit^2: Props to Josh Wieder for taking sounding the sec awareness alarm. I would only do active sec research on untrusted materials within a decent hypervisor's VM on a virtual desktop (VDI) which has "nonpersistence" on all storage, so it's clean on every power cycle.
- jugad 11y agoThe author should really add this in the beginning of the article... "Any set of emails this large containing attachments is bound to contain malware, viruses, trojans and other malicious software - just like anybody's inbox which receives more than 5 mails a day. This is a reminder to everyone downloading this data to handle it with caution. Do no execute code, and view things only inside constrained network isolated virtual machines". The way its worded right now seems to point fingers at wikileaks.
- joshwieder 11y agoDid you read the article past the first paragraph? I explicitly state I am not pointing fingers at anyone in the article in paragraph 6: "I have no information linking Wikileaks, Asssange, Hammond, Monsegur, the FBI or anyone else directly with these malicious files. That very well may change quickly as research progresses, but at no point should this post be considered finger pointing. The purpose of this post is not to assign responsibility but to ensure that the journalists and activists downloading these files or who have already downloaded these files understand the consequences and take proper precautions."