Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

New Research Shows Guccifer 2.0 Files Were Copied Locally, Not Hacked
Disobedient Media ^

Posted on 07/09/2017 2:28:09 PM PDT by TigerClaws

New meta-analysis has emerged from a document published today by an independent researcher known as The Forensicator, which suggests that files eventually published by the Guccifer 2.0 persona were likely initially downloaded by a person with physical access to a computer connected to the internal DNC network. The individual most likely used a USB drive to copy the information. The groundbreaking new analysis irrevocably destroys the Russian hacking narrative, and calls the actions of Crowdstrike and the DNC into question.

The document supplied to Disobedient Media via Adam Carter was authored by an individual known as The Forensicator. The full document referenced here has been published on their blog. Their analysis indicates the data was almost certainly not accessed initially by a remote hacker, much less one in Russia. If true, this analysis obliterates the Russian hacking narrative completely.

The Forensicator specifically discusses the data that was eventually published by Guccifer 2.0 under the title “NGP-VAN.” This should not be confused with the separate publication of the DNC emails by Wikileaks. This article focuses solely on evidence stemming from the files published by Guccifer 2.0, which were previously discussed in depth by Adam Carter.

Disobedient Media previously reported that Crowdstrike is the only group that has directly analyzed the DNC servers. Other groups including Threat Connect have used the information provided by Crowdstrike to claim that Russians hacked the DNC. However, their evaluation was based solely on information ultimately provided by Crowdstrike; this places the company in the unique position of being the only direct source of evidence that a hack occurred.

The group’s President Shawn Henry is a retired executive assistant director of the FBI while their co-founder and CTO, Dmitri Alperovitch, is a senior fellow at the Atlantic Council, which as we have reported, is linked to George Soros. Carter has stated on his website that “At present, it looks a LOT like Shawn Henry & Dmitri Alperovitch (CrowdStrike executives), working for either the HRC campaign or DNC leadership were very likely to have been behind the Guccifer 2.0 operation.” Carter’s website was described by Wikileaks as a useful source of primary information specifically regarding Guccifer 2.0.

Carter recently spoke to Disobedient Media, explaining that he had been contacted by The Forensicator, who had published a document which contained a detailed analysis of the data published by Guccifer 2.0 as “NGP-VAN.”

The document states that the files that eventually published as “NGP-VAN” by Guccifer 2.0 were first copied to a system located in the Eastern Time Zone, with this conclusion supported by the observation that “the .7z file times, after adjustment to East Coast time fall into the range of the file times in the .rar files.” This constitutes the first of a number of points of analysis which suggests that the information eventually published by the Guccifer 2.0 persona was not obtained by a Russian hacker.

The Forensicator stated in their analysis that a USB drive was most likely used to boot Linux OS onto a computer that either contained the alleged DNC files or had direct access to them. They also explained to us that in this situation one would simply plug a USB drive with the LinuxOS into a computer and reboot it; after restarting, the computer would boot from the USB drive and load Linux instead of its normal OS. A large amount of data would then be copied to this same USB drive.

In this case, additional files would have been copied en masse, to be “pruned” heavily at a later time when the 7zip archive now known as NGP-VAN was built. The Forensicator wrote that if 1.98 GB of data had been copied at a rate of 22.6 MB/s and time gaps t were noticed at the top level of the NGP-VAN 7zip file were attributed to additional file copying, then approximately 19.3 GB in total would have been copied. In this scenario, the 7zip archive (NGP-VAN) would represent only about 10% of the total amount of data that was collected.

The very small proportion of files eventually selected for use in the creation of the “NGP-VAN” files were later published by the creators of the Guccifer 2.0 persona. This point is especially significant, as it suggests the possibility that up to 90% of the information initially copied was never published.

The use of a USB drive would suggest that the person first accessing the data could not have been a Russian hacker. In this case, the person who copied the files must have physically interacted with a computer that had access to what Guccifer 2.0 called the DNC files. A less likely explanation for this data pattern where large time gaps were observed between top level files and directories in the 7zip file, can be explained by the use of ‘think time’ to select and copy 1.9 GB of individual files, copied in small batches with think time interspersed. In either scenario, Linux would have been booted from a USB drive, which fundamentally necessitates physical access to a computer with the alleged DNC files.

The Forensicator believed that using the possible ‘think-time’ explanation to explain the time-gaps was a less likely explanation for the data pattern available, with a large amount of data most likely copied instantaneously, later “pruned” in the production of the Guccifer 2.0’s publication of the NGP-VAN files.

Both the most likely explanation and the less likely scenario provided by The Forensicator’s analysis virtually exclude the possibility of a Russian or remote hacker gaining external access to the files later published as “NGP-VAN.” In both cases, the physical presence of a person accessing a containing DNC information would be required.

Importantly, The Forensicator concluded that the chance that the files had been accessed and downloaded remotely over the internet were too small to give this idea any serious consideration. He explained that the calculated transfer speeds for the initial copy were much faster than can be supported by an internet connection. This is extremely significant and completely discredits allegations of Russian hacking made by both Guccifer 2.0 and Crowdstrike.

This conclusion is further supported by analysis of the overall transfer rate of 23 MB/s. The Forensicator described this as “possible when copying over a LAN, but too fast to support the hypothetical scenario that the alleged DNC data was initially copied over the Internet (esp. to Romania).” Guccifer 2.0 had claimed to originate in Romania. So in other words, this rate indicates that the data was downloaded locally, possibly using the local DNC network. The importance of this finding in regards to destroying the Russian hacking narrative cannot be understated.

If the data is correct, then the files could not have been copied over a remote connection and so therefore cannot have been “hacked by Russia.”

The use of a USB drive would also strongly suggest that the person copying the files had physical access to a computer most likely connected to the local DNC network. Indications that the individual used a USB drive to access the information over an internal connection, with time stamps placing the creation of the copies in the East Coast Time Zone, suggest that the individual responsible for initially copying what was eventually published by the Guccifer 2.0 persona under the title “NGP-VAN” was located in the Eastern United States, not Russia.

The implications of The Forensicator‘s analysis in combination with Adam Carter‘s work, suggest that at the very least, the Russian hacking narrative is patently false. Adam Carter has a strong grasp on the NGP-VAN files and Guccifer 2.0, with his website on the subject called a “good source” by Wikileaks via twitter. Carter told Disobedient Media that in his opinion the analysis provided by The Forensicator was accurate, but added that if changes are made to the work in future, any new conclusions would require further vetting.

On the heels of recent retractions by legacy media outlets like CNN and The New York Times, this could have serious consequences, if months of investigation into the matter by authorities are proven to have been based on gross misinformation based solely on the false word of Crowdstrike.

Assange recently lamented widespread ignorance about the DNC Leak via Twitter, specifically naming Hillary Clinton, the DNC, the Whitehouse and mainstream media as having “reason” to suppress the truth of the matter. As one of the only individuals who would have been aware of the source of the DNC Leaks, Assange’s statement corroborates a scenario where the DNC and parties described in Adam Carter’s work likely to have included Crowdstrike, may have participated in “suppressing knowledge” of the true origins and evidence surrounding the leak of the DNC emails by confusing them with the publication of the Guccifer 2.0 persona.

Despite Guccifer 2.0’s conflicting reports of having both been a Russian hacker and having contact with Seth Rich, the work of The Forensicator indicates that neither of these scenarios is likely true. What is suggested is that the files now known as “NGP-VAN” were copied by someone with access to a system connected to the DNC internal network, and that this action had no bearing on the files submitted to Wikileaks and were most likely unassociated with Seth Rich, and definitively not remotely “hacked” from Russia.


TOPICS: Crime/Corruption; Government; News/Current Events; Politics/Elections
KEYWORDS: adamcarter; alperovitch; awanbrothers; brightbluedata; carter; clinton; crowdstrike; dccc; dnc; dncemails; dnchacked; dncleaks; fake; forensicator; fraud; guccifer; guccifer2; guccifer20; haters; hillary; hillaryclinton; ngpvan; obama; podesta; russianhacking; sethrich; shawnhenry; theforensicator; toronto; traitor; warrenflood; wassermanschultz; wikileaks
Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-106 next last
To: Fedora

Well isn’t that special...


81 posted on 07/10/2017 12:23:09 AM PDT by piasa
[ Post Reply | Private Reply | To 78 | View Replies]

To: nicollo
"Also, any evidence out there that Rich knew Linux?"

"In 2014 [Rich] began working for the Democratic National Committee (DNC) as the Voter Expansion Data Director. One of his tasks at the DNC was the development of a computer application to help voters locate polling stations"-Wiki

Let's at least say based on that wiki, he was acquainted with Linux. It's worth noting that anyone even merely acquainted with Linux would also know that the primary way to get around a Windows platform password [and perhaps even copy data therefrom] is a Linux-based USB stick...

82 posted on 07/10/2017 12:34:36 AM PDT by StAnDeliver (Prosecute the win. Run up the score.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: henkster
"Just because Seth Rich downloaded the emails to a USB drive doesn’t mean that the Russians didn’t also hack into the DNC server. And just because the Russians hacked into the DNC server doesn’t mean Seth Rich didn’t also download the emails to a USB device."

Exactly. Rich may not have been the primary source, but could have been left holding the bag. Occam's Razor.

"The point is that it was the content of those emails, revealing the corruption of the DNC, that damaged Clinton’s campaign. Neither Seth Rich nor the Russians wrote those emails."

So true.

83 posted on 07/10/2017 12:40:07 AM PDT by StAnDeliver (Prosecute the win. Run up the score.)
[ Post Reply | Private Reply | To 29 | View Replies]

To: piasa
Carter told Big League Politics he believes that it was likely a misdirection effort by Crowdstrike, a cybersecurity firm that worked for the DNC, and Warren Flood, an IT worker with links to the DNC and the Obama administration. He has referred to the Guccifer 2.0 persona as a “donkey in a bear costume.”
84 posted on 07/10/2017 1:15:22 AM PDT by Fedora
[ Post Reply | Private Reply | To 81 | View Replies]

To: StAnDeliver
Actually, Occam's Razor would favor the simplest hypothesis that fits all the facts: in this case, it would favor an internal leak rather than a Russian hack as the source of Wikileaks' information, unless there is evidence that does not fit this theory. There does seem to be evidence that the Russians were monitoring the DNC's server to keep track of Ukranian lobbyists working for the DNC (see Ukrainian efforts to sabotage Trump backfire: Kiev officials are scrambling to make amends with the president-elect after quietly working to boost Clinton.: "Almost as quickly as Chalupa’s efforts attracted the attention of the Ukrainian Embassy and Democrats, she also found herself the subject of some unwanted attention from overseas. . ."); but I cannot recall seeing any evidence connecting Russia to the Wikileaks leak, apart from CrowdStrike's uncorroborated claim, which should be excluded by Occam's Razor unless they can produce some evidence to support it, which they haven't done publicly so far.
85 posted on 07/10/2017 1:23:47 AM PDT by Fedora
[ Post Reply | Private Reply | To 83 | View Replies]

To: Fedora; henkster
"Actually, Occam's Razor would favor the simplest hypothesis that fits all the facts: in this case, it would favor an internal leak rather than a Russian hack as the source of Wikileaks' information, unless there is evidence that does not fit this theory."

Actually, that's exactly what I said. Rich may not have been the primary source within the DNC, but was the one left holding the bag. This is contextually driven by Henkster's observation that, paraphrasing, all things are possible. Thus my cite to Occam's Razor.

86 posted on 07/10/2017 1:58:27 AM PDT by StAnDeliver (Prosecute the win. Run up the score.)
[ Post Reply | Private Reply | To 85 | View Replies]

To: Whenifhow

Bookmark


87 posted on 07/10/2017 4:30:55 AM PDT by DrDude (Get rid of everything Obama or Clinton!)
[ Post Reply | Private Reply | To 19 | View Replies]

To: laxcoach
Seth Rich may have copied that data. But this reads like fiction, and probably is fiction.

If it looks like bullshit and smells like bullshit, it's bullshit.

Anyone who's take Computer Science 101 or Computer Security 101 laughs their ass off reading this thing. Totally unbelievable.

"The Forensicator?" Oh please!

88 posted on 07/10/2017 4:35:41 AM PDT by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 15 | View Replies]

To: StAnDeliver

But that’s postulating two sources when one will do, which is not an application of Occam’s Razor.


89 posted on 07/10/2017 9:12:51 AM PDT by Fedora
[ Post Reply | Private Reply | To 86 | View Replies]

To: All
What the new info suggests:

<><> the “NGP-VAN” files were copied by someone with access to a system connected to the DNC internal network,

<><> this had no bearing on the files submitted to WikiLeaks or to Seth Rich, and,

<><> definitively not remotely “hacked” from or by Russia.

90 posted on 07/10/2017 10:08:12 AM PDT by Liz
[ Post Reply | Private Reply | To 20 | View Replies]

To: rodguy911; seastay
Reported elsewhere: the Guccifer 2 files have meta tags that can be shown were originally English, but were deliberately changed into Russian to make it look as if the files went through a Russian computer.

The most plausible theory is these Guccifer 2 leaks not necessarily were damaging but were leaked on purpose by the DNC with fake Russian meta tags so as to use as evidence before a wire tap judge to tap Trump.

Whomever tried the translation from English to Russian screwed-up several times....... and this is how they were outed.

==========================================

Trace all of it back to the Obama paranoia---if Hillary lost, all of them would have big Big problems.

REFERENCE---Then-Pres Obama and his minions started developing the “Russian hacked the election” narrative to give them cover for their blatantly illegal spying on the Trump campaign....... Obama spying on Trump started a year earlier. This is the stuff of third-rate banana republics. Susan Rice, and all concerned, including BO, should be in prison right this minute. (hat tip Junk Silver)

============================================

FROM ONE OF THE MANY EXPOSES---Seeking to retain his position as CIA director under Hillary, Obama-era Brennan at the CIA used phony foreign intel as a pretext for a multi-agency investigation into Trump.....that led the FBI to probe a computer server connected to Trump Tower and gave cover to Susan Rice's sifting operations....

Not only Brennan.... "Susan The Sifter" had a dog in this hunt......Hillary tapped her for Secy of State. One could conclude Comey also had his reasons .....to stay on as FBI director.

Mighty powerful incentives for anti-Trump shenanigans.

.......apparently there are records proving that Obama's CIA director, John Brennan, oversaw repeated spying on the phone calls of President Donald Trump and millions of other private American citizens. An audiotape just released by Federal Judge G. Murray Snow is part of a civil case........

91 posted on 07/10/2017 10:16:25 AM PDT by Liz
[ Post Reply | Private Reply | To 39 | View Replies]

To: GOPJ; Jane Long; MinuteGal; jsanders2001; V K Lee; HarleyLady27; stephenjohnbanker; ...
The most plausible theory is the Guccifer 2 leaks themselves were not necessarily damaging.....but were leaked on purpose by the DNC......using fake Russian meta tags so as to become evidence before a wire tap judge to get a shady FISA to tap Trump.

POINTS TO PONDER: The more you examine this outrage, the more you sense that then-DNC head Debbie Wasserman Schultz (D/W/S) is the culprit.......but she did not act alone.

Then-Pres Obama and his minions started developing the “Russian hacked the election” narrative to give them cover for their blatantly illegal spying on the Trump campaign....... Obama spying on Trump started a year earlier.

Debbie Wasserman Schultz is super-ambitious. D/W/S actually has a spreadsheet of "people who owe her"....people she did favors fo

D/W/S was especially keen on getting into the good graces of the half-caste Royal Idiot b/c it suited her crass self-serving ambitions.

Strangely enough, on the surface it seemed like the half/caste kept shrugging her off.....as she pursued him w/ a vengeance.

Distilling the info, one concludes, D/W/S was a willing "doer of tasks," but the Royal Idiot had to give the appearance that they were not connected.

==========================================

And so concludes another chapter from Obama's Third World banana republic.

92 posted on 07/10/2017 10:32:17 AM PDT by Liz
[ Post Reply | Private Reply | To 91 | View Replies]

To: Liz

and still no mention if the Awans have a connection to this.


93 posted on 07/10/2017 10:40:59 AM PDT by stylin19a
[ Post Reply | Private Reply | To 92 | View Replies]

To: stylin19a

The Paki spies had their own bailiwick....tasked by Muslim Pakistan for specific info.

But I’m positively sure Obama approved of all of it....and Little Debbie provided the hands-on facilitation.


94 posted on 07/10/2017 11:03:55 AM PDT by Liz
[ Post Reply | Private Reply | To 93 | View Replies]

To: Liz
I contend the GOPe (lord McCain/Romney/Bush) were the originators of all these lies against Trump and by extension his campaign. The ‘neocon’ contingent are just as dirty as the in your face lying liberals.
95 posted on 07/10/2017 11:34:31 AM PDT by Just mythoughts
[ Post Reply | Private Reply | To 92 | View Replies]

To: Just mythoughts

Can’t dispute the neocon/dirt argument.


96 posted on 07/10/2017 11:43:14 AM PDT by Liz
[ Post Reply | Private Reply | To 95 | View Replies]

To: old-ager; TigerClaws; Whenifhow; SunkenCiv; NormsRevenge; Grampa Dave; SierraWasp; TigersEye; ...

Following the Youtube you linked a followon entry popped up with a nice summary of daths following the Clintons and other notes

Just gonna drop this in here ...Set Rich is mentioned.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

https://youtu.be/f0mXDZI5KL4

WATCH BEFORE REMOVED!!! WE FOUND IT! THIS Hillary Clinton & Bill Clinton
Last Days Watchmen News

*************************************************

Last Days Watchmen News — WATCH BEFORE REMOVED!!! WE FOUND IT! THIS Hillary Clinton & Bill Clinton

Published on Dec 1, 2016

https://youtu.be/BmqHISAuups

*************************************************

Regarding the youtube url just above’’

when looking for the Youtube go the following

*******

“WE FOUND IT! THIS Hillary C...” The YouTube account associated with this video has been terminated due to multiple third-party notifications of copyright infringement.

***********
Sorry about that.


97 posted on 07/10/2017 12:17:54 PM PDT by Ernest_at_the_Beach
[ Post Reply | Private Reply | To 7 | View Replies]

To: TigerClaws

FBI needs to get real and STOP acting like elites are treated differently under the law.

It’s disgusting.

For those who want a lighter moment:

https://www.youtube.com/watch?v=Ut0TaegQ-kw


98 posted on 07/10/2017 12:22:35 PM PDT by GOPJ ( MSM Snowflakes: if you don't like President Trump's tweets don't read 'em.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Fedora
"Rich may not have been the primary source, but could have been left holding the bag. Occam's Razor."

"Left holding the bag" = dead

Rich is more likely - than any other explanation - dead because he was left holding the bag.

99 posted on 07/10/2017 12:56:00 PM PDT by StAnDeliver (Prosecute the win. Run up the score.)
[ Post Reply | Private Reply | To 89 | View Replies]

To: GrandJediMasterYoda

They call/bitch to the ACLU when the voter records are checked.


100 posted on 07/10/2017 1:20:52 PM PDT by Lumper20
[ Post Reply | Private Reply | To 3 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-106 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson