So.. What about those Japanese IP addresses in the SONY Hack Anyway?
Just a little note in the derpstorm (another post to follow on that after this one) that I wanted to drop on you all. See, I mentioned this in one of my first posts on the Sony Hack but it has gone little noticed. In the malware samples of Destover-C on Virus Total you can see in the strings a huge list of IP addresses that belong to someone in Japan… I reckoned that they were in fact Sony addresses because they track down to a location in Japan where Sony HQ is and I left it at that. I had made my comments on how Japan and Korea just don’t get along and that they have a long history of unhappy relations, and thus a keyboard map, if taken on face value, might have relevance in this way.
Well, later on someone who shall remain un-named contacted me and thanked me for my post and the information in it. The reason? They said that they worked for Sony and had been told NOTHING. My post actually gave them more information than the actual corporation that they worked for within their own security and networking space! Sadly, this seems to be the M. O. of Sony and I took that piece of info as truth because really this person had nothing to lie about here.
and life went on…
Destover-C connections looking for NetBIOS connections
This morning, as I sit with coffee at 5am, awake because I looked at twitter and ERMEGERD DPRK DID IT is all over the place I just thought I would share. See, there is more going on here than Wolf Blitzer can… Well.. Blitz! All of this, all of the fallout that I will write about next just covers over the fact that much more has gone on and we have not heard anything about.
What happened in Japan?
Do we really think that just SPE was hit? I mean they are connected as a company to the parent which is in Japan right?
What about Germany?
What about all the subsidiaries? Won’t they too have to re-create their networks?
What great fuckery there is going on.
Wake the fuck up people.