New Research Shows Guccifer 2.0 Files Were Copied Locally - DNC Not "Hacked By Russians"

Tyler Durden's picture

Via Disobedient Media

New meta-analysis has emerged from a document published today by an independent researcher known as The Forensicator, which suggests that files eventually published by the Guccifer 2.0 persona were likely initially downloaded by a person with physical access to a computer possibly connected to the internal DNC network. The individual most likely used a USB drive to copy the information. The groundbreaking new analysis irrevocably destroys the Russian hacking narrative, and calls the actions of Crowdstrike and the DNC into question.

The document supplied to Disobedient Media via Adam Carter was authored by an individual known as The Forensicator. The full document referenced here has been published on their blog. Their analysis indicates the data was almost certainly not accessed initially by a remote hacker, much less one in Russia. If true, this analysis obliterates the Russian hacking narrative completely.

The Forensicator specifically discusses the data that was eventually published by Guccifer 2.0 under the title "NGP-VAN."  This should not be confused with the separate publication of the DNC emails by Wikileaks. This article focuses solely on evidence stemming from the files published by Guccifer 2.0, which were previously discussed in depth by Adam Carter.

Disobedient Media previously reported that Crowdstrike is the only group that has directly analyzed the DNC servers. Other groups including Threat Connect have used the information provided by Crowdstrike to claim that Russians hacked the DNC. However, their evaluation was based solely on information ultimately provided by Crowdstrike; this places the company in the unique position of being the only direct source of evidence that a hack occurred.

The group’s President Shawn Henry is a retired executive assistant director of the FBI while their co-founder and CTO, Dmitri Alperovitch, is a senior fellow at the Atlantic Council, which as we have reported, is linked to George Soros. Carter has stated on his website that “At present, it looks a LOT like Shawn Henry & Dmitri Alperovitch (CrowdStrike executives), working for either the HRC campaign or DNC leadership were very likely to have been behind the Guccifer 2.0 operation.” Carter’s website was described by Wikileaks as a useful source of primary information specifically regarding Guccifer 2.0.

Carter recently spoke to Disobedient Media, explaining that he had been contacted by The Forensicator, who had published a document which contained a detailed analysis of the data published by Guccifer 2.0 as  "NGP-VAN."

The document states that the files that eventually published as "NGP-VAN" by Guccifer 2.0 were first copied to a system located in the Eastern Time Zone, with this conclusion supported by the observation that "the .7z file times, after adjustment to East Coast time fall into the range of the file times in the .rar files." This constitutes the first of a number of points of analysis which suggests that the information eventually published by the Guccifer 2.0 persona was not obtained by a Russian hacker.

Image via The Forensicator

Image via The Forensicator

The Forensicator stated in their analysis that a USB drive was most likely used to boot Linux OS onto a computer that either contained the alleged DNC files or had direct access to them. They also explained to us that in this situation one would simply plug a USB drive with the LinuxOS into a computer and reboot it; after restarting, the computer would boot from the USB drive and load Linux instead of its normal OS. A large amount of data would then be copied to this same USB drive.

In this case, additional files would have been copied en masse, to be "pruned" heavily at a later time when the 7zip archive now known as NGP-VAN was built. The Forensicator wrote that if 1.98 GB of data had been copied at a rate of 22.6 MB/s and time gaps t were noticed at the top level of the NGP-VAN 7zip file were attributed to additional file copying, then approximately 19.3 GB in total would have been copied. In this scenario, the 7zip archive (NGP-VAN) would represent only about 10% of the total amount of data that was collected.

The very small proportion of files eventually selected for use in the creation of the "NGP-VAN" files were later published by the creators of the Guccifer 2.0  persona. This point is especially significant, as it suggests the possibility that up to 90% of the information initially copied was never published.

The use of a USB drive would suggest that the person first accessing the data could not have been a Russian hacker. In this case, the person who copied the files must have physically interacted with a computer that had access to what Guccifer 2.0 called the DNC files. A less likely explanation for this data pattern where large time gaps were observed between top level files and directories in the 7zip file, can be explained by the use of 'think time' to select and copy 1.9 GB of individual files, copied in small batches with think time interspersed. In either scenario, Linux would have been booted from a USB drive, which fundamentally necessitates physical access to a computer with the alleged DNC files.

The Forensicator believed that using the possible 'think-time' explanation to explain the time-gaps was a less likely explanation for the data pattern available, with a large amount of data most likely copied instantaneously,  later "pruned" in the production of the Guccifer 2.0's publication of the NGP-VAN files.

Both the most likely explanation and the less likely scenario provided by The Forensicator's analysis virtually exclude the possibility of a Russian or remote hacker gaining external access to the files later published as "NGP-VAN."  In both cases,  the physical presence of a person accessing a containing DNC information would be required.

Importantly, The Forensicator concluded that the chance that the files had been accessed and downloaded remotely over the internet were too small to give this idea any serious consideration. He explained that the calculated transfer speeds for the initial copy were much faster than can be supported by an internet connection. This is extremely significant and completely discredits allegations of Russian hacking made by both Guccifer 2.0 and Crowdstrike.

This conclusion is further supported by analysis of the overall transfer rate of 23 MB/s. The Forensicator described this as "possible when copying over a LAN, but too fast to support the hypothetical scenario that the alleged DNC data was initially copied over the Internet (esp. to Romania)." Guccifer 2.0 had claimed to originate in Romania. So in other words, this rate indicates that the data was downloaded locally,  possibly using the local DNC network. The importance of this finding in regards to destroying the Russian hacking narrative cannot be overstated.

If the data is correct, then the files could not have been copied over a remote connection and so therefore cannot have been "hacked by Russia."

The use of a USB drive would also strongly suggest that the person copying the files had physical access to a computer most likely connected to the local DNC network. Indications that the individual used a USB drive to access the information over an internal connection, with time stamps placing the creation of the copies in the East Coast Time Zone, suggest that  the individual responsible for initially copying what was eventually published by the Guccifer 2.0 persona under the title "NGP-VAN"  was located in the Eastern United States, not Russia.

The implications of The Forensicator's analysis in combination with Adam Carter's work, suggest that at the very least, the Russian hacking narrative is patently false. Adam Carter has a strong grasp on the NGP-VAN files and Guccifer 2.0, with his website on the subject called a "good source" by Wikileaks via twitter. Carter told Disobedient Media that in his opinion the analysis provided by The Forensicator was accurate, but added that if changes are made to the work in future, any new conclusions would require further vetting.

On the heels of recent retractions by legacy media outlets like CNN and The New York Times, this could have serious consequences, if months of investigation into the matter by authorities are proven to have been based on gross misinformation based solely on the false word of Crowdstrike.

Assange recently lamented widespread ignorance about the DNC Leak via Twitter, specifically naming Hillary Clinton, the DNC, the Whitehouse and mainstream media as having “reason” to suppress the truth of the matter. As one of the only individuals who would have been aware of the source of the DNC Leaks, Assange’s statement corroborates a scenario where the DNC and parties described in Adam Carter's work likely to have included Crowdstrike, may have participated in “suppressing knowledge" of the true origins and evidence surrounding the leak of the DNC emails by confusing them with the publication of the Guccifer 2.0 persona.

Despite Guccifer 2.0's conflicting reports of having both been a Russian hacker and having contact with Seth Rich, the work of The Forensicator indicates that neither of these scenarios is likely true.

What is suggested is that the files now known as "NGP-VAN" were copied by someone with access to a system connected to the DNC internal network, and that this action had no bearing on the files submitted to Wikileaks and were most likely unassociated with Seth Rich, and definitively not remotely "hacked" from Russia.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Occident Mortal's picture

But not Seth Rich, anyone but him.

Looney's picture

 

The Forensicator

It’s a cool moniker, although not as cool as The Fornicator.  ;-)

Looney

nmewn's picture

His name was Seth Rich.

American Psycho's picture

Well this hurts the narritive.  Back to the drawing board to illegitimize the POTUS

WTFRLY's picture

Russian hacking is just a Joominati lie, please call it what it is

robertsgt40's picture

The problem here is not finding evidence to prosecute Hitlery and the Obama administration.  The problem is finding someone with cajones tp uphpld the constitution and rule of law that will do something besides scratch their ass.

Four chan's picture

 

His name was Seth Rich.

His name was Seth Rich.

 His name was Seth Rich.

 His name was Seth Rich. 

hillary clinton had john podesta have him murdered.

Yes We Can. But Lets Not.'s picture

Not Seth Rich?

What sayeth you, Kim Dotcom?

jeff montanye's picture

i'm not kim but i put a link on zerohedge some weeks back to this same effect: 

https://www.reddit.com/r/The_Donald/comments/6d9xcm/breaking_ive_found_e...

this guy should get some credit.

All Risk No Reward's picture

Hillary is a puppet.

John Podest is a puppet.

The PUPPET MASTER are the Money Power Supremacists... currently incarnated as the Debt-Money Monopolists that rule over the Mega-Corporate Fascist Empire system that rules over the rest of us.

Don't be a tool, blame the ROOT CAUSE!

Give Me Some Truth's picture

Re: "His name was Seth Rich ..."

Well, according to this story, Rich was not at the center of this story. Nor were "the Russians."

I've always thought the Rich angle should definitely be seriously investigated, but I was skeptical he was the one and only source of WikiLeaks' reporting. Assange, if he thought it proper, could have made a definitive statement about Rich's role (after all, if Rich WAS killed over his role in downloading the emails, this is info of great importance to a homicide investigation. Is not withholding info of importance to a homicide investigation a possible crime? It's at least a moral crime.  

Also, if we are to believe that such "spycraft" would result in the order being given to assasinate someone, it always seemed odd to me that the "hit men" didn't put two bullets into the back of the target's head. Isn't this the way it happens if one really wants to "silence" someone? You certainly don't let the person live (and potentially talk) for some unknown duration of time.

Any "certainty" that Rich was the central figure in this email release could actually prevent consideration of alternative theories.  

 

 

Bendromeda Strain's picture

Assange will not name a source. What part of that statement is unclear to you? Going forward, folks now have the option to put a deadmans switch on their identity. Failing that, Wikileaks will keep your secret unto death. Your bullets speculation reminds me of idiot conservatives and their scenario objections to 911 Truth, as if they could plan a massive conspiracy better. If the assassin wanted to make it look like a hit, he would have... ergo, he didn't.

HRClinton's picture

But, but... 17 Intelligence Agencies! 

Winston Churchill's picture

Braverman and Seth Rich.Rich may have been set up as a patsy by Braverman as somehow he's still

alive.He must have an exceptional dead mans switch..

PlayMoney's picture

They wouldn't let Homeland Security, FBI and now Mueller look at their computers. Doesn't take an Einstein to figure out there never was anything to their allegations. A bunch of crying wolf liars from the start.

Hail Spode's picture

Worse. I think Guccifer 2.0 was a DNC front to pin it on Russia. Guy did not even show up until after they knew they had been hacked. Never released anything that hurt the dems. First thing released was their oppo research FILE ON TRUMP.

Now why did they go to all that trouble to make it look like a "hack" rather than a leak? Maybe to mis-direct from their having the first leaker Seth Rich murdered?

j0nx's picture

CNN and MSNBC have been reporting on this article all morning. Oh wait, no they aren't...

Nostradumbass's picture

OyVey.

How can (((we))) spin this to our advantage?

JackMeOff's picture

Ironic that this is released on the one year anniversary of the death of Seth Rich.

small axe's picture

ironic or intended? Release on the one-year anniversary provides a good "lead-in" for the media to bring up Rich's murder, assuming MSM ever deigns to mention either story.

Cordeezy's picture

Only CNN and MSMS still thinks the Russians did the hacking.

 

www.escapeamazon.com

 

Give Me Some Truth's picture

Re: "Only CNN thinks the Russians did the hacking"

... Plus, 97 members of the U.S. Senate who just voted to punish Russia for said non-hacking.

lester1's picture

Jeff Sessions get off your mother fucking ass and assign a special prosecutor for the DNC servers and murder of DNC email leaker Seth Rich ! 

 

And if it exposes pedogate, oh fucking well !! Are you part of Pedogate Jeff ??

 

Do your job Jeff Sessions !!! ..Perhaps we need a new AG ??

PlayMoney's picture

What? I always thought they were sexist?

Bavarian's picture

Gunned down 5 days later

my new username's picture

A logical extension of this is that Seth Rich was assassinated to create a Red Herring trail.

rbianco3's picture

Is the story about Seth Rich being trained by Israeli military prior to working for the DNC fact?

It it is, than he's likely back in his home country. 

tyberious's picture

His name was Seth Rich.

LA_Goldbug's picture

Yes BUT .... but Russia knows all this and did it in such a way as to make it look like it happened as though done in the US. This will be shortly discussed on FOX and CNN who have the best of the best to offer us this new TRUTH.

lester1's picture

How embarrassing that 17 intelligence agencies got this one wrong.

 

Lol

JackMeOff's picture

Which is worse - the crickets of the DNC refusing 13 times to release the server to the FBI or the crickets of a Russian lawyer who was banned from the US getting a parole from the Obama administration to visit Trump Jr. in the summer of 2016?

Troy Ounce's picture

 

Fuck. How angry can you get? 

Mercuryquicksilver's picture

Seth Rich downloaded thumbdrive, was murdered for it. Crowdsoure filtered thumbdrive and released as Guccifer2.

First 5 emails meta links to user login of actual computer.

DuneCreature's picture

Boarding party sighted!

~~~^~~~~^~~~~^~~~~^~~~~AAA~~~~^~~~~^~~~~^~~~~^~~~~^~~~

***)) One Eyed Pirate Mueller Has Assembled His Boarding Party ((***

Ok, Trumpsters get ready for a boarding attempt over the starboard rail.

One Eyed Mueller and his raiders are rowing toward the ship right now and One Eye is issuing last minute instructions and assigning objectives to his assault team ace marauders and team leaders.

These raiders are out for blood, booty and extreme embarrassment so rally around your captain if you dare or care.

The rest of us are going to make some popcorn, melt some Keigold and maybe roll out a fresh barrel of grog and pound in a tap.

This raiding party looks a lot like the Clinton Satan Foundation legal staff. ....... I told Donald he would regret not throwing the evil lying witch in jail. ... Now she's funding the assault on his ship like a big sore loser. ....... Meanwhile, John The Molesta is out burying booty and treasure just in case things get ugly and the Satan Foundation raiders have to retreat to somewhere lick each other's wounds.

The impeachment team is the who's who of anyone and everyone with a personal reason to make Trump 'Wank The Plank' (tm) and resign.

Send the squeamish and faint-of-heart below. ..... This story of DC intrigue is about to grow some hair on it.

Live Hard, Oh Look!.. There's Slippery And Cagey Putting On Their Full Body 'Blanket Immunity' Suits Of Armor,...It Gets Really Hot And Stuffy Wearing All That Metal Into Battle. .... I Hope They Both Get Thrown Overboard In Their Heavy Chain Mail Clown Shirts And Shin Guards, Myself, Die Free

~ DC v7.3

mary mary's picture

Mueller's job will be to drag his "investigation" out for 4 years while presenting ZERO evidence of ANYTHING to The American Citizens. 

Rachel and Maxine Headroom's jobs will be to spend 90 minutes every day saying, "Well, if today's mind-blowing extremely tough questions don't convince everyone that Donald Trump is an evil alien about to pop out of every Republican's chest and lay eggs your children's beds, I don't know what will".

TwelveOhOne's picture

+1 for Maxine Headroom.  I loved that stuttering show.

DuneCreature's picture

The IC, DoJ and FBI are the crooks.

I know I'm stating the obvious,........but there may be late arrivals to the party.

Trump is The Swamp too. ...... But sometimes swamp monsters eat each other over booty, bluster and ego.

All of DC is lawyering up like I have NEVER SEEN BEFORE.

Live Hard, Yes, This Sonic Boom And Impeachment Volcanic Eruption Circus Should Wake Up A Few People Napping Out In The Corn Fields And Town Square Parks, Die Free

~ DC v7.3

Smedley's Butler's picture

I don't know, DC.

I think George is wrong on this one. His 'working theory' lacks reasoning and facts and he has backtracked on many of the claims. My feeling is that he is beeing sensational as he has claimed to have use this approach before. Btw, he does't have a big enough following for that to work.

I just cannot see the impeachment coming this week. How do you make a case of collusion and/or obstruction with this flimsy evidence and then toss in the old Mossad tape... Will he be on trial for being a bad guy? The pieces don't fit.

 

 

espirit's picture

Perhaps the Polistitutes will convene and make stink bombs to be used against Trump before taking a month long lunch break.

Then the Presstitute dogs will have a bone to chew on until they think their masters will throw them some RED MEAT.

Gohigher's picture

dc,

Did you mean Kerrygold ? For the popcorn ?

Best butter in the WORLD !

 

I pray that this last double-triple-quadruple facile attempt to foment mutiny is the last one by the sick fucks, god we need to be rid of these traitors.

That breadplant MUST remain on the Bounty, Mr. Christian !!

(allright, I twisted the real plot to fit my intent)

And just what are these ball bearings doing in my pocket ?

What Mutiny is this ??  Arrgghhhhh !

mary mary's picture

I am absolutely sure that Guccifer Dvah was actually Natasha, a Russian mail order bride on a North Vietnamese patrol boat, buzzing the USA Far East Fleet while sinking the Maine and dropping barrel bombs laced with chemical weapons on Kuwaiti hospital children for the KKK.  Exactly like DNC, James Clapper VIII, CNN, MSNBC, and Lindsey Graham say.

As "evidence", I note that 17 Spy-and-Lie Agencies say so.   What?  Only 4 Spy-and-Lie Agencies are still saying so?  Well, when it gets down to 0 Spy-and-Lie Agencies, I will become absolutely sure that Natasha is... a disgruntled former lover of James Clapper VIII.  As soon as a Spy-and-Lie Agency pays me to say so.

chindit13's picture

...and the same 'research' proves dinosaurs and humans DID live together 6000 years ago

lester1's picture

There's no way in hell dinosaur bones could last even 6000 years without dissolving into dust.

land_of_the_few's picture

Those poor dinosaurs and their shoddy, sweatshop-made bones, not like our special lavishly-tooled, boutique human bones.

Shemp 4 Victory's picture

Continue monitoring. Your disease we'll try to turn in your dignity.

JailBanksters's picture

Don't tell us what we already know,

tell us what the Fake Jews don't want us to hear.