It Started With A Simple Phone Call

Discussion in 'General' started by nikel, Jun 20, 2014.

  1. nikel

    nikel Lab 1852 - Neurals



     
    Last edited by a moderator: Aug 12, 2014
    13 people like this.
  2. nikel

    nikel Lab 1852 - Neurals

    Looks like the forum automatically capitalizes the first letter of each word in the title. Can I get someone to change that, please?
     
  3. Vorticity

    Vorticity Senior Agent

    At about 30 seconds in to the video:
    [​IMG]
    Not sure about the q7af7v87 part, could be:

    q7(a|s)f7v87(D|B|8|....)

    Added:
    scp syntax: $ scp [email protected]:foobar.txt /some/local/directory
    To copy foobar.txt from remote host to local folder.
     
    Last edited by a moderator: Jun 20, 2014
    3 people like this.
  4. nikel

    nikel Lab 1852 - Neurals

    Ha that is hard to spot vortic!

    I see q7af7v87B, but I could be wrong.

    Also, up there is dancing_ghosts.zip. Nice quiet shoutout to DTG.

    Edit: Also q7af7v87B is not her actual password :c
     
    4 people like this.
  5. Ruke Unlimited

    Ruke Unlimited Senior Agent

    [​IMG]

    I cleaned it up as much as possible. It looks more like q(3,9)af7(J?)v(8,D,B)7(J?)(8,D,B)
     
    4 people like this.
  6. Vismal

    Vismal Gold Member

    Maybe it's just the output but the input was different
    Also, perhaps...q7af7v87B is part of a URL...
     
  7. Ruke Unlimited

    Ruke Unlimited Senior Agent

    2 people like this.
  8. Zerosh

    Zerosh Sleeper Agent

    Last edited by a moderator: Jun 21, 2014
    2 people like this.
  9. nikel

    nikel Lab 1852 - Neurals

    Chrome is warning me to not go to the site because of an SSL error, so it may not be intentional. Also, it looks like you can actually buy jewelry on there so I'm gonna say its a real thing!
     
  10. thatangryviking

    thatangryviking Viking Turkey | The Bot Slayer

  11. Mandraw

    Mandraw Senior Agent

    yeah it warns you because if they done the site some time ago , it still may have heartbleed in it, nay ?
     
  12. Bats

    Bats Division 93: Covert Grammatical Ops Battalion

    Vismal and I were poking at this a bit last night... I'm going to call the jewelry site a dead end (although I still see some potential for the host itself, and maybe even the /patients/ URL - see below).

    1) There's no source for "q7af7vstuff". That was my shorthand for the string that appears to start with "q7af7v..." in Ruke's screenshot from the video: http://i.imgur.com/IC09fzP.png .
    2) The redirect actually happens on any address under (and including) https://rosenbergclinic.com/
    3) https://bijouterielsm.com/ looks suspiciously like an HE site because... well... it is an HE site. Just not an ARG one. It appears that they've actually been cheating on us, going behind our backs and wasting time that should've been exclusively devoted to our entertainment on *shudder* serious contracts. For real businesses, even. http://www.humanequation.co/news/hu...the-release-of-the-new-lsm-ecommerce-website/

    It looks like, since rosenbergclinic.com doesn't have a site configured on port 443, the server's falling back on another site it hosts that does have one defined - since both bijouterielsm.com and rosenbergclinic.com look to be hosted on equation1.multialtos.com - 69.51.202.77.

    The sharp-eyed (or better caffeinated than I) may notice that 69.51.202.77 is also where we see rrecchi logged in. No, it doesn't appear to allow telnet or ssh connections, unless they're on some non-standard port - so either he was connected locally, or we're looking at another ARGnix web-based terminal setup.

    (I suppose that means that what rrecchi's really doing there is moving files from the clinic's system... to the clinic's system. I'm not sure how intentional that bit is - it's a rather roundabout way to copy things from an account he clearly has access to - so I'm going to conveniently ignore it for the moment)

    It may still be worth looking at http://rosenbergclinic.com/patients/q7whatever_this_string_is, though. While /var/mnt/patients - where our old buddy Randy appears to be copying Miz Baup's files - doesn't seem like an entirely logical place for http://.../patients/ to sit on a real server, it's perfectly plausible based on what we've seen of ARGnix (which tends to bend *nix conventions rather freely to suit the plot or puzzle)... except that then we'd probably also be seeing http://rosenbergclinic.com/dancing_ghosts.zip, .../room(patient.1976).mp4 (the same as room.mp4, which we've seen?), and maybe .../breach.crack.pwd. So maybe I need to find some coffee and rethink this whole thing from the beginning.


    -Bats
    (or is that brunch.crack.pwd? maybe I need to find some food, too)
     
  13. Bats

    Bats Division 93: Covert Grammatical Ops Battalion

    2 people like this.
  14. Vismal

    Vismal Gold Member

    I was way tired last night and a little tipsy and I really freaked when I heard the exorcism audio (muffled/modulated through my browser somehow) and was certain it wasn't supposed to be there as I thought it came from elsewhere. Also I tried so many combinations of the site, I even ran a Reaper on Rosenberg site (baring HTTPS) to see if there were any secret pixel links I didn't spot on the first go at it...and nothing, or rather, was too tired to care by that point.
    Good thing Bats was there to keep me grounded or I'd have gone on a paranoid-spree...ugh I need more coffee...
     
    3 people like this.
  15. Santiak

    Santiak MIA

    Just for future reference, I thought it was prudent to add the link to the Rosenberg doc we had going, as it might be beneficial to have handy, in case people start going looney over things others have already gone partially looney over before (initially it was only Nikel and I who heard the exorcism track, because it's connected to your computers clock, and plays between 11 p.m. and 6 a.m. - quite keepy going "why's nobody else hearing this!?") - although I'm sure Nikel's guide, which I believe he will move over here, will cover those aspects as well. :)

    Link's in "Rosenberg doc", but colour is the same as normal font, so just to avoid confusion, here's the url: https://docs.google.com/spreadsheets/d/1qwI1-dhICLm7wIM89r_Qp8WSLR5saZiw0VJGPKPs0QE/edit#gid=0
     
  16. Vismal

    Vismal Gold Member

    Yeah I knew the doc and the exorcism related to time, but I *thought* it shouldn't be showing on that page; because sleeplessness lol.
    But yeah, the doc and original Nikel guide should be reviewed for sure for all new agents/old agents wanting to catch up (and for reference before freaking out over nothing...)
     
    2 people like this.
  17. nikel

    nikel Lab 1852 - Neurals

    Ok, tonight I'll try to put together a whole big catch-up guide for new folks but I'll probably need some help! My writing style is very terse and not pretty so it'll have to be a group effort.
     
    8 people like this.
  18. Vicarne

    Vicarne Senior Agent

    Nikel, I would be happy to assist with the catch-up guide. I am getting caught up myself so reading it over while editing would benefit both of us. I'll message you as I run into questions.
     
  19. Bats

    Bats Division 93: Covert Grammatical Ops Battalion

    You know you're off the rails when I start looking like a stabilizing influence.

    -Bats
    (I got a belfry full of 'em!)
     
    6 people like this.
  20. TheChosenOne

    TheChosenOne Active Agent

    This is why I love you guys. You get one video and imediately you start digging and searching for clues. And who knows-- maybe you might actually find something...
     

Share This Page