📜 ⬆️ ⬇️

Hackers Shadow Brokers have published a new piece of data grouping Equation Group

Shadow Brokers hackers gained worldwide fame after publishing the secret data of the elite cyber-grouping Equation Group, which used sophisticated and well-designed cyber weapons in cyber attacks. A previously published eqgrp-free-file archive by hackers contained several 0day exploits for Cisco and Fortinet network devices. This time, hackers posted in open access an archive with information about the cyber attack metadata used by the group. In particular, the IP addresses and domains of the sources of cyber attacks, as well as their dates are indicated there.

This is being an equation group pitchimpair (redirector) keys, many missions . Is not owning eqgrp_auction_file. Connect to these pitchimpairs.

An encrypted archive called trickortreat.tar.xz.gpg contains a set of directories with information about domains and IP addresses that were used by the Equation Group in cyber attacks on their victims. Below the screenshot shows some of the directories in the archive. It can be seen that there are servers from around the world.


')
Microsoft's Security-Matcher Swann published a visual representation of information about the Equation Group servers in an Excel document.



As can be seen from the presented data, the archive contains information about cyber attacks, which were carried out from 2000 to 2010. It also shows that the majority of the alleged victims of the Equation Group worked on Solaris, with some using Linux and FreeBSD. Servers of cyber attacks were in many countries, including, Japan, Korea, Belgium, India, Hungary, Russia, Mexico, Spain, Poland, Germany, China, etc. Thus, it is obvious that the group used different servers in each case cyber attacks infrastructure, as well as to complicate the detection of the real origin of the cyber attack.

» US intelligence agencies arrested a possible informant hacker Shadow Brokers
» Equation Group exploit box added a new instance
» Snowden documents confirm the accuracy of Shadow Brokers data
Cisco and Fortinet Release Safety Notices after Data Leakage by Equation Group
» Published data of the elite cyber-grouping Equation Group were not a joke
» Known cyber-grouping Equation Group could be subjected to large-scale hacking

Source: https://habr.com/ru/post/314002/


All Articles