Slashdot Mirror


Computer Scientists Believe a Trump Server Was Communicating With a Russian Bank (slate.com)

In light of the Democratic National Committee hack by the Russians earlier this year, a "tightly knit community of computer scientists" working in a variety of fields came up with the hypothesis, "which they set out to rigorously test: If the Russians were worming their way into the DNC, they might very well be attacking other entities central to the presidential campaign, including Donald Trump's many servers." In late July, one of the scientists who asked to be referred to as Tea Leaves discovered possible malware emanating from Russia, with the destination domain having Trump in its name. What the researcher saw "was a bank in Moscow that kept irregularly pinging a server registered to the Trump Organization on Fifth Avenue": Slate Magazine reports: More data was needed, so he began carefully keeping logs of the Trump server's DNS activity. As he collected the logs, he would circulate them in periodic batches to colleagues in the cybersecurity world. Six of them began scrutinizing them for clues. The researchers quickly dismissed their initial fear that the logs represented a malware attack. The communication wasn't the work of bots. The irregular pattern of server lookups actually resembled the pattern of human conversation -- conversations that began during office hours in New York and continued during office hours in Moscow. It dawned on the researchers that this wasn't an attack, but a sustained relationship between a server registered to the Trump Organization and two servers registered to an entity called Alfa Bank. The server was first registered to Trump's business in 2009 and was set up to run consumer marketing campaigns. It had a history of sending mass emails on behalf of Trump-branded properties and products. Researchers were ultimately convinced that the server indeed belonged to Trump. But now this capacious server handled a strangely small load of traffic, such a small load that it would be hard for a company to justify the expense and trouble it would take to maintain it. That wasn't the only oddity. When the researchers pinged the server, they received error messages. They concluded that the server was set to accept only incoming communication from a very small handful of IP addresses. A small portion of the logs showed communication with a server belonging to Michigan-based Spectrum Health.

3 of 548 comments (clear)

  1. Re:BULL SH!T by dugancent · · Score: 0, Troll

    Says the Anonymous poster. Log in or go away.

    --
    SJWs are the new boogeyman. -Me
  2. What do you call a russian Manchurian candidate? by Maxo-Texas · · Score: 1, Troll

    What if they have dirt on Trump?

    I've been blown away how far the republican party has flipped on the russians so far.

    It would explain why they put so many resources into hacking, modifying* and leaking DNC emails.

    *The first leaks had cyrrilic usernames from editing and russian address hyperlinks. So everything from wikileaks after those is suspect. We shouldn't have told them we could identify the documents as fake so quickly. But we are americans and not crafty like the british during world war 2.

    --
    She was like chocolate when she drank... semi-sweet at first and then increasingly bitter.
  3. Re:BULL SH!T by fahrbot-bot · · Score: 0, Troll

    Trump media and doubles down on the loose talk and continual lies.

    What bothers me even more is that he genuinely doesn't seem to care about the truth - any truth. Or, perhaps he doesn't understand that "truth" is something that actually exists. Does than make him sociopath or psychopath (or both)? [genuinely asking] (Oh, and he seriously doesn't understand how video tape works.)

    --
    It must have been something you assimilated. . . .