Kategorie: Chaos & Karma

  • Attackers Fight for Control of Sites Targeted in File Manager Vulnerability

    „Attackers Fight for Control of Sites Targeted in File Manager Vulnerability“
    Conspiracy Revelation: 28.9.2020: Wordfence caused a long time a WSOD on my page…not sure if it was a counterdefense mechanism of these notorious russian cleptocratic cyberhack spambot mafiosis, that dominate the Internet for the last 25 years with their viral loads… I will check that soon…I surely would have used wordfence if it didn´t lose compatibility aka WSOD which made it impossible for me to use it at a certain point in time with this webpage.
    These ico exploits are very old and typical russian cyber mafiosi method. At least 20 years old, also for Windows Systems.
    Update: I installed Wordfence now, it works again, the white screen of death was likely caused by these russian cyber mafiosis as a Malware Persistence Factor, so that their exploit could survive longer, that is a good indicator that the page is finally really cleansed from this filth.
    „This entry was posted in Research, Vulnerabilities, WordPress Security on September 10, 2020 by Ram Gall 5 Replies
    Last week, we covered a vulnerability in the File Manager plugin installed on over 700,000 WordPress sites. By Friday, September 4, 2020, we recorded attacks on over 1.7 million sites, and by today, September 10, 2020 the total number of sites attacked has increased to over 2.6 million. We’ve seen evidence of multiple threat actors taking part in these attacks, including minor efforts by the threat actor previously responsible for attacking millions of sites, but two attackers have been the most successful in exploiting vulnerable sites, and at this time, both attackers are password protecting vulnerable copies of the connector.minimal.php file.
    An early bird stealing passwords
    Our site cleaning team has found numerous indicators that the most active of these attacks are the work of a Moroccan threat actor known as “bajatax” which has historically stolen credentials from PrestaShop sites. These indicators include simple files containing only the string “bajatax” as well as modifications to the original vulnerable connector.minimal.php file designed to lock out all other attackers, containing a $content=“by bajatax” line of code. Logs from infected sites indicate these files are being added by some of the most active attacking IPs, and we were able to verify that this threat actor is behind the hardfork.php and hardfile.php IOCs mentioned in our initial post. This attacker was the first to attack this vulnerability at scale.
    Once a site is infected, the “bajatax” attacker adds malicious code that uses the Telegram messenger’s API to exfiltrate the credentials of any user logging into the site. This code is added to the WordPress core user.php file. If WooCommerce is installed, the wc-user-functions.php and class-wc-form-handler.php files will also be modified to exfiltrate user credentials. These credentials could then be resold or used to gain access to other accounts using the same credentials.
    We’ve found IOCs from this threat actor on a substantial number of sites. Despite this attacker’s efforts to lock out other hackers, they haven’t always managed to get their foot in the door first, but we’ve seen them make regular attempts to update the passwords on both the vulnerable connector.minimal.php file and on other files they’ve added to allow additional upload capability, while leaving the credential scraping functionality in place which consistently sends to the same Telegram chat ID of 1110165405.
    Our Threat Intelligence team has been hard at work adding malware signatures to detect Indicators of Compromise by the bajatax threat actor, and these have been available to Wordfence Premium users starting September 8, 2020. These signatures will be released to sites still using the free version of Wordfence after 30 days, starting October 8, 2020.
    A second attacker scattering backdoors
    The most prevalent single indicators of compromise we found are an infector, feoidasf4e0_index.php, with an MD5 hash of 6ea6623e8479a65e711124e77aa47e4c, and a backdoor inserted by this infector. In this case we are providing the MD5 hash since this file is extremely consistent, and as such the MD5 can be a useful indicator of compromise.
    This attacker is using the mkfile method outlined in our initial article rather than the upload method favored by the “bajatax” threat actor. This attacker is also adding password protection to the vulnerable connector.minimal.php file in an effort to lock out other attackers, though our attack data indicates this threat actor is using a consistent password.
    The feoidasf4e0_index.php file inserts two copies of the second backdoor with randomized filenames ending in _index.php whenever it is accessed. One copy is placed in the webroot, and one in a randomized writable folder on the site. Both backdoors have the same MD5 of 3f60851c9f7e37c0d8817101d2212c68. While the backdoor in question has been in use for several years, the fact that multiple copies might be scattered across an infected site would help this attacker maintain persistence in the absence of a thorough scanning solution. We’ve also seen additional copies of this backdoor with different MD5 hashes added by this attacker; these are simply the most common variants.
    Once these backdoors are in place, the attacker is using them to make additional modifications to core WordPress files, in some cases by using obfuscated code to include separate backdoors disguised as .ico files. While the prevalence of the feoidasf4e0_index.php file appears to be declining, the secondary backdoors added by this file are still extremely common, indicating that this attacker has managed to achieve some degree of persistence.
    The feoidasf4e0_index.php file itself appears to be a very slightly modified version of an infector used in previous campaigns that primarily added cryptominers and SEO spam to various sites, so these are viable monetization routes for this threat actor, though they could also simply lease access to a botnet of infected sites under their control.
    Other actors abound
    Our site cleaning team has cleaned a number of sites compromised by this vulnerability, and in many cases, malware from multiple threat actors is present. The aforementioned threat actors have been by far the most successful due to their efforts to lock out other attackers, and are collectively using several thousand IP addresses in their attacks. Nonetheless, we’ve seen attacks against this vulnerability from over 370,000 separate IP addresses.
    There has been almost no overlap between the IPs adding and accessing the feoidasf4e0_index.php file and the IPs adding and accessing the bajatax “hardfork” files. The single exception is the IP 51.83.216.204, which appears to be a third party opportunistically checking for the presence of both of these backdoors and then attempting to add a backdoor of its own, without much success. As more and more users update or remove the File Manager plugin, control of any infected sites will likely be split between these two threat actors.
    Conclusion
    In today’s article, we discussed the most common infections we’re seeing on sites where the File Manager vulnerability has been exploited as well as the predominant actors involved. We’ve also managed to link at least one of the attackers to a known threat actor and determine likely paths to monetization. If you or anyone you know has had a vulnerable version of the File Manager plugin installed, we urge you to scan your site for malware using a security solution such as Wordfence. If your site has been compromised by the “bajatax” threat actor, it is critical that you completely clean your site before contacting all of your users and advising them that their credentials may have been compromised, especially if you are running an e-commerce site.“
    „Some Agency September 10, 2020 at 2:42 pm:
    For that telegram chat room 1110165405 I deleted their webhook using the telegram API once I found out one of our clients sites was hacked. Hoping I helped the cause a little there lol. The index file found on this server was ‚fqsvoig675_index.php‘ and they injected code into ‚user.php‘ to send user creds to their telegram bot.
    https://api.telegram.org/botXXXXXXXX:XXXXXXX/deleteWebhook?chat_id=1110165405“
    „Surender September 10, 2020 at 8:58 pm:
    I am feeling lucky that I have been using Wordfence since beginning. It has always protected me from such attacks.
    Thank you Wordfence team.“
    „bloganchoi September 13, 2020 at 6:09 pm:
    File managers are very important, if you install an unknown plugin that is susceptible to critical vulnerabilities that lead to your website being hacked, be careful when installing any plugin on your site.“
    „Juan Erazo September 10, 2020 at 1:14 pm:
    That’s right. Our site suffers this attack the las week and only yesterday we are online again. We are using wordfence from now!“
    Source: https://www.wordfence.com/blog/2020/09/attackers-fight-for-control-of-sites-targeted-in-file-manager-vulnerability/

  • Hacker-Krieg um 300.000 gefährdete WordPress-Sites

    „Hacker-Krieg um 300.000 gefährdete WordPress-Sites“
    „Cybercrime“
    “ Bastivon Basti11. September 20200
    Vor einigen Tagen wurde eine schwerwiegende Sicherheitslücke im File Manager-Plugin für WordPress entdeckt. Obwohl die Lücke vom Entwickler innerhalb weniger Stunden behoben und mit Erscheinen von Version 6.9 ein Update zur Verfügung stand, wurde das Update nicht von allen Nutzern eingespielt. Das hat nun dazu geführt, dass einige Hacker um die Kontrolle von etwa 300.000 infizierten WordPress-Seiten kämpfen.
    Warum viele Nutzer des File Manager-Plugins kein Update eingespielt haben, ist unklar. Einige Nutzer haben das Plugin zwar entfernt (ursprünglich waren es 700.000, nun sind noch 600.000 Installationen), bei einem Teil dürfte es sich um vergessene oder nicht mehr gepflegte WordPress-Installationen handeln, aber ein Teil der Nutzerschaft hat eben kein Update durchgeführt.
    Wie Bleeping Computer gestern berichtete, werden derzeit über 2,6 Millionen WordPress-Installationen von unterschiedlichen Hackern angegriffen. So wie es derzeit aussieht, gibt es zwei Hauptakteure, die in dem Rennen um die Kontrolle die Nase vorne haben. Während einer Backdoors einbaut, versucht ein Anderer fremde Exloit-Versuche andere Angreifer zu blockieren, während er selbst erfolgreich Benutzerzugangsdaten klaut. Der Hacker ist unter dem Namen Bajatax bekannt.
    In all, Defiant’s researchers saw attacks trying to exploit this vulnerability originating from more than 370,000 separate IP addresses, with almost no overlap in backdoor access activity.
    Wenn sich die Aktivitäten beim Zugriff auf Backdoors nicht überschneiden, spricht das eher für abgestimmte Aktionen oder gar den gleichen Täter.
    Das ist ein schönes Beispiel dafür, was passieren kann, wenn Sicherheitsupdates nicht zeitnah eingespielt werden. Diese Lücke im File Manager-Plugin, bzw. die nicht eingespielten Updates, wird WordPress-Betreiber und auch Hoster noch länger beschäftigen.
    Weitere ausführliche Informationen zu den Aktivitäten der Hacker hat Wordfence veröffentlicht.“
    Quelle: https://netzbasti.de/2020/09/11/hacker-krieg-um-300-000-gefaehrdete-wordpress-sites/

  • Attacks Targeting Recent WordPress File Manager Flaw Ramping Up

    „Attacks Targeting Recent WordPress File Manager Flaw Ramping Up
    By Ionut Arghire on September 11, 2020
    Attacks targeting a recently addressed vulnerability in the WordPress plugin File Manager are ramping up, warns the Wordfence Threat Intelligence team at WordPress security company Defiant.
    With over 700,000 active installs, File Manager is a highly popular WordPress plugin that provides admins with file and folder management capabilities (copy/paste, delete, download/upload, edit, and archive).
    In early September 2020, the plugin’s developer addressed a critical-severity zero-day flaw that was already being actively targeted. Assessed with a CVSS score of 10, the flaw can allow attackers to remotely execute code on a vulnerable installation.
    The issue is related to code taken from the elFinder project, with the File Manager developers renaming the elFinder library’s connector.minimal.php.dist file to .php, to have it execute directly. This, however, opened the plugin to attackers.
    Nearly two weeks after a patch for the vulnerability was released, multiple threat actors are targeting unpatched installations, Wordfence researchers reveal.
    Within days after the zero-day was patched, attackers were targeting over 1.7 million sites, but that number increased to 2.6 million as of September 10.
    “We’ve seen evidence of multiple threat actors taking part in these attacks, including minor efforts by the threat actor previously responsible for attacking millions of sites, but two attackers have been the most successful in exploiting vulnerable sites, and at this time, both attackers are password protecting vulnerable copies of the connector.minimal.php file,” Wordfence notes.
    The most active of the attackers is a Moroccan threat actor referred to as “bajatax,” which modifies the vulnerable connector.minimal.php file to prevent further attacks. This is the first threat actor observed targeting the vulnerability at scale.
    Once it manages to compromise a website, the attacker adds code to exfiltrate user credentials using the Telegram messenger’s API. The code is added to the WordPress core user.php file and, if WooCommerce is installed, two more files are modified to steal user credentials.
    A second adversary targeting the security flaw is attempting to inject a backdoor into the vulnerable websites, and is protecting the connector.minimal.php file with a password, in an attempt to prevent other infections. However, it appears that the threat actor is using a consistent password across infections.
    Two copies of the backdoor are inserted into the infected website, one in the webroot and the other in a randomized writable folder, likely in an attempt to ensure persistence. The attacker leverages the backdoors to modify core WordPress files which would then be abused for monetization purposes, based on the threat actor’s previously observed modus operandi.
    On many of the compromised websites, Wordfence discovered malware from multiple adversaries. Attacks targeting the vulnerability were observed originating from more than 370,000 separate IP addresses, with almost no overlaps between the IPs used by the two most active attackers.
    “As more and more users update or remove the File Manager plugin, control of any infected sites will likely be split between these two threat actors,” Wordfence notes.
    Site administrators are advised to update the File Manager plugin as soon as possible, but also to scan their website for possible compromise and to remove any malicious code they might find.
    Related: WordPress ‚File Manager‘ Plugin Patches Critical Zero-Day Exploited in Attacks
    Related: WordPress Malware Targets WooCommerce Stores
    Related: Hackers Can Inject Code Into WordPress Sites via Flaw in Product Review Plugin“
    Source: https://www.securityweek.com/attacks-targeting-recent-wordpress-file-manager-flaw-ramping

  • Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    „Hackers are exploiting a critical flaw affecting >350,000 WordPress sites“
    „Flaw is in File Manager, a plugin with more than 700,000 users; 52% are affected.
    Dan Goodin – 9/2/2020, 3:40 AM“
    „Hackers are actively exploiting a vulnerability that allows them to execute commands and malicious scripts on Websites running File Manager, a WordPress plugin with more than 700,000 active installations, researchers said on Tuesday. Word of the attacks came a few hours after the security flaw was patched.
    Attackers are using the exploit to upload files that contain webshells that are hidden in an image. From there, they have a convenient interface that allows them to run commands in plugins/wp-file-manager/lib/files/, the directory where the File Manager plugin resides. While that restriction prevents hackers from executing commands on files outside of the directory, hackers may be able to exact more damage by uploading scripts that can carry out actions on other parts of a vulnerable site.
    NinTechNet, a website security firm in Bangkok, Thailand, was among the first to report the in-the-wild attacks. The post said that a hacker was exploiting the vulnerability to upload a script titled hardfork.php and then using it to inject code into the WordPress scripts /wp-admin/admin-ajax.php and /wp-includes/user.php.
    Backdooring vulnerable sites at scale
    In email, NinTechNet CEO Jerome Bruandet wrote:
    It’s a bit too early to know the impact because when we caught the attack, hackers were just trying to backdoor websites. However, one interesting thing we noticed is that attackers were injecting some code to password-protect the access to the vulnerable file (connector.minimal.php) so that other groups of hackers could not exploit the vulnerability on the sites that were already infected.
    All commands can be run in the /lib/files folder (create folders, delete files etc), but the most important issue is that they can upload PHP scripts into that folder too, and then run them and do whatever they want to the blog.
    So far, they are uploading „FilesMan“, another file manager often used by hackers. This one is heavily obfuscated. In the next few hours and days we’ll see exactly what they will do, because if they password-protected the vulnerable file to prevent other hackers to exploit the vulnerability it is likely they are expecting to come back to visit the infected sites.
    Fellow website security firm Wordfence, meanwhile, said in its own post that it had blocked more than 450,000 exploit attempts in the past few days. The post said that the attackers are trying to inject various files. In some cases, those files were empty, most likely in an attempt to probe for vulnerable sites and, if successful, inject a malicious file later. Files being uploaded had names including hardfork.php, hardfind.php, and x.php.
    „A file manager plugin like this would make it possible for an attacker to manipulate or upload any files of their choosing directly from the WordPress dashboard, potentially allowing them to escalate privileges once in the site’s admin area,“ Chloe Chamberland, a researcher with security firm Wordfence, wrote in Tuesday’s post. „For example, an attacker could gain access to the admin area of the site using a compromised password, then access this plugin and upload a webshell to do further enumeration of the server and potentially escalate their attack using another exploit.“
    52% of 700,000 = potential for damage
    The File Manager plugin helps administrators manage files on sites running the WordPress content management system. The plugin contains an additional file manager known as elFinder, an open source library that provides the core functionality in the plugin, along with a user interface for using it. The vulnerability arises from the way the plugin implemented elFinder.
    „The core of the issue began with the File Manager plugin renaming the extension on the elFinder library’s connector.minimal.php.dist file to .php so it could be executed directly, even though the connector file was not used by the File Manager itself,“ Chamberland explained. „Such libraries often include example files that are not intended to be used ‚as is‘ without adding access controls, and this file had no direct access restrictions, meaning the file could be accessed by anyone. This file could be used to initiate an elFinder command and was hooked to the elFinderConnector.class.php file.“
    The developers of File Manager credited researcher Ville Korhonen of security firm Seravo with discovering and first reporting the vulnerability. The researchers, who said they found the vulnerability as part of their regular „WordPress upkeep service,“ published their own writeup here.
    Sal Aguilar, a contractor who sets up and secures WordPress sites, took to Twitter to warn of attacks he’s seeing.
    „Oh crap!!!“ he wrote. „The WP File Manager vulnerability is SERIOUS. Its spreading fast and I’m seeing hundreds of sites getting infected. Malware is being uploaded to /wp-content/plugins/wp-file-manager/lib/files.“
    The security flaw is in File Manager versions ranging from 6.0 to 6.8. Statistics from WordPress show that currently about 52 percent of installations are vulnerable. With more than half of File Manager’s installed base of 700,000 sites vulnerable, the potential for damage is high. Sites running any of these versions should updated to 6.9 as soon as possible.“
    Source: https://arstechnica.com/information-technology/2020/09/hackers-are-exploiting-a-critical-flaw-affecting-350000-wordpress-sites/

  • Conspiracy Revelation hat Bajatax-Exploit zertrümmert…/ Conspiracy Revelation smashed Bajatax exploit…

    Conspiracy Revelation hat Bajatax-Exploit zertrümmert… Bajatax-Exploit hatte conspiracyrevelation befallen, ich habe die Seite gesäubert, von ihrem widerlichen Shellcode..
    Er hatte einige Modifikationen vorgenommen, um mir den Zugriff zum Back-End zu blockieren und hatte die leere Antikeymagic-HP komplett in einen Bajatax Ordner verfrachtet, auf dem Domain-Server. Die Exploits sind russischer Natur… Wenn man versucht hatte über Bing auf conspiracyrevelation.com zu gelangen wurde man auf japanische Webseiten umgelenkt.
    Also eine triplistische Ausländerfraktion von Marokko-Maghreb/russischer und japanischer Mixtur.
    Kundalini Devi ist verzaubert… du hast keine Chance… egal was du gegen mich versuchst.
    //
    Conspiracy Revelation smashed Bajatax exploit… Bajatax exploit had attacked conspiracyrevelation, I cleaned the page of its disgusting shellcode.. He had made some modifications to block my access to the back-end and had put the empty Antikeymagic-HP completely in a Bajatax folder on the domain server. The exploits are Russian in nature … If you tried to get to conspiracyrevelation.com via Bing, you were redirected to Japanese websites. So a tripartite foreigners faction from Morocco-Maghreb/Russian and Japanese mixture.
    Kundalini Devi is enchanted…you have zero chance…no matter what you try against me.
    //
    [28.09.20 00:33]:
    [Weitergeleitet aus ConspiracyRevelation]
    Hier nochmal der absolute Beweis dass conspiracyrevelation.com der Bajatax Attacke unterzogen wurde…
    //
    Here again the absolute proof that conspiracyrevelation.com was subjected to the Bajatax attack…

    „$password = „bajatax_cae5fff19c1…“; // Password“
    //
    spamxtoolz_com:104.24.99.74 Cloud14 Server… „Hacked By Hunter Bajwa“
    //
    [Weitergeleitet aus ConspiracyRevelation]
    logpass=““; //FORMAT: md5(loginIMAILpassword);
    session_start();
    define(‚DEBUG‘, FALSE);
    define(‚SIMULATION‘, FALSE);
    define(‚SERVICEMODE‘, FALSE);
    if(isset($_POST[„password_bajatax“])){
    if(md5(md5(md5($_POST[„password_bajatax“]))) == „15857d3eacb3f9894b0d2551acbbd828“){
    SESSION[„connected“]=$_POST[„password_bajatax“];
    …
    header(‚Content-type: text/html; charset=utf-8;‘);
    #Alexus(240980845) – http//\www.a-l-e-x-u-s/\ru/
    #CREATED AT 15.12.2011
    #UPD 02.04.2012 v 1.
    #UPD 10.04.2012 v 1.2
    …
    #UPD 20.10.2014 v 2.0.3
    define(„VERSION“, „2.0“);
    define(„FULLVERSION“, „2.0.8“);
    define(„RELEASEDATE“, „08-12-2014″);
    $boundary=“–„.AMUtil::randomString(10);
    $timezone=’Europe/Moscow‘;
    /**
    Запрос авторизации
    Authorization request“

  • ALIEN CREATURE 3700 FEET DOWN IN THE DEEP OF THE OCEAN .


    „ALIEN CREATURE 3700 FEET DOWN IN THE DEEP OF THE OCEAN .“
    „516 Aufrufe•20.09.2020
    Atlantica Evolution
    1420 Abonnenten“
    „20.3.2013“

  • Der geheime Krieg gegen das deutsche Volk und seine historischen Wurzeln


    „Der geheime Krieg gegen das deutsche Volk und seine
    historischen Wurzeln“
    „345 Aufrufe•17.09.2020“
    „Frieden Freiheit Wahrheit
    85 Abonnenten
    Der geheime Krieg gegen das deutsche Volk und seine historischen Wurzeln
    @dieZuversicht
    @unzensiert“


    „Codex Sinaiticus… der Krieg gegen die deutschen hat
    seine Wurzeln jedoch im Konflikt zwischen dem jesuitischen Vatikan und dem protestantischen Deutschland, der Chronologiekritiker Wilhelm Kammeier war überzeugt davon, dass die originalen Dokumente der germanischen Geschichte
    vernichtet und ersetzt wurden durch gefälschte Dokumente der gallisch-romanischen Geschichte.“
    „Während sich also die Herrscher der Neuzeit keinerlei Mühe machten überhaupt irgendetwas niederzuschreiben,
    existiert für die Kirche angeblich eine lückenlose Dokumentation der Geschichte bis zum fünften Jahrhundert nach
    Christus, daran wird erkennbar, dass die Kirche höchstwahrscheinlich rückwirkend sämtliche Dokumente bis zur Neuzeit gefälscht hat.“

    „Dass fast durch alle Jahrhunderte des Mittelalters
    Könige und Kaiser keine Register haben führen lassen, dann stehen wir vor dem ausserordentlichen Faktum, dass ganze
    Generationen einer bestimmten Klasse Menschen durch überaus hohen unter anhaltenden Schaden nicht um einen deut
    klüger geworden sein, so müsste man sich, wie gesagt, damit
    abfinden, die mittelalterlichen weltlichen Fürsten seien durch die Bank kindische Tore, um nicht zu sagen Halb-Idioten gewesen. Zitat Ende. Dies ist allerdings äußerst unwahrscheinlich, denn Kammeier konnte ebenfalls belegen, dass so gut wie alle kirchlichen Dokumente Anzeichen für
    Fälschungen aufweisen. (Die Fälschung der deutschen Geschichte – Verlag für ganzheitliche Forschung)“
    „Architektur ist neben Literatur das stärkste Band zwischen Gegenwart und Vergangenheit.“

    „Die deutsche Geschichte der letzten 400 Jahre, seit dem dreißigjährigen Krieg lässt sich verstehen als die
    schrittweise Zerstörung der Germania Magna…lateinisch für großes Germanien. Das alte Germanien beinhaltete vermutlich
    geografische Gebiete der Schweiz und Niederlande, sowie des heutigen Dänemarks, Österreichs, Ungarns, Frankreich und Teile Osteuropas.“
    „Es gab nie einen Apfel und im altdeutschen bedeutet der Wortstamm Abel einfach böse, der Sinn hinter dieser Geschichte ist, dass die Menschheit aus dem paradiesischen Zustand hinausgeworfen wurde, als das Böse in die Welt kam und bei Kain und Abel handelt es sich nicht um Namen zweier Menschen: Kein Abel bedeutet einfach kein Übel, Kain für kein und Abel für Übel, der text sollte wahrscheinlich beschreiben, weshalb das Böse in die Welt kam und die Menschen begannen sich gegenseitig Schaden zuzufügen.“
    „Das Wort katholisch enthält verschlüsselt ebenfalls die wahre Bedeutung, es kommt vom altdeutschen Wort Kautulum,
    die Irrlehre, dazu das adjektiv toll für dumm, verwirrt, albern und töricht, sowie die Formen Tholik und Katholik, was
    wörtlich die Verdummten, die Irregeleiteten, die Törichten bedeutet, dementsprechend lässt sich ableiten, welchen Ruf die Katholiken vor ihrer Machtergreifung genossen.“
    „Die Reformationslüge, die Reformation geschah nicht so, wie man es uns glauben machen will, in Wirklichkeit geschah es genau umgekehrt, das heißt die Katholiken waren die
    Reformatoren, die andere Gruppe waren die Protestanten,
    die gegen die katholischen Änderungen der heiligen Schriften protestierten, die Bedeutung liegt im Namen. Die Bibel gab es vor der Zeit der sogenannten Reformation noch nicht, sie ist ein Produkt des frühen 17 Jahrhunderts und wurde kurz nach dem Höhepunkt der Reformationskriege zusammengestellt, was wahrscheinlich die Zeit des dreißigjährigen Krieges war.
    “Die Belagerung von Bauzen – 1620.”
    Die Reformationskriege waren meine Ansicht nach der letzte große blutige Konflikt zwischen den Mächten des Lichtes und der Finsternis und die Finsternis hat gewonnen.
    Nachdem sie das freie deutsche Volk eliminiert hatten, stellten die Katholiken die Bibel als die wichtigsten
    Schriftstücke aus den zuvor frei zirkulierenden Büchern zusammen, aber sie veränderten wesentliche Elemente,
    der Grund dafür, dass in der Bibel immer noch Wahrheit zu finden ist, liegt darin, dass die Fälscher nicht viel Zeit hatten, da sie schnell eine Propagandaversion der Schriften erstellen mussten, um die Massen zu indoktrinieren und was noch wichtiger ist, sie, also die päpstlichen Katholiken, mussten auch wahre Elemente einfügen, um die Menschen davon zu überzeugen, dass sie die einzig richtige Religion vertreten, der Protest gegen den Vatikan vereinte
    ganz Europa und war dezentraler Natur, es gab nie die sogenannten Protestanten, im Sinne einer Art Religion, außer dass verschiedene Gruppen von Gnostikern und Häretikern in ihrem Willen vereint waren gegen die Institution Kirche in Rom zu kämpfen.” geschah es genau umgekehrt, das heißt die Katholiken waren die
    Reformatoren, die andere Gruppe waren die Protestanten,
    die gegen die katholischen Änderungen der heiligen Schriften protestierten, die Bedeutung liegt im Namen. Die Bibel gab es vor der Zeit der sogenannten Reformation noch nicht, sie ist ein Produkt des frühen 17 Jahrhunderts und wurde kurz nach dem Höhepunkt der Reformationskriege zusammengestellt, was wahrscheinlich die Zeit des dreißigjährigen Krieges war.
    „Die Belagerung von Bauzen – 1620.“
    Die Reformationskriege waren meine Ansicht nach der letzte große blutige Konflikt zwischen den Mächten des Lichtes und der Finsternis und die Finsternis hat gewonnen.
    Nachdem sie das freie deutsche Volk eliminiert hatten, stellten die Katholiken die Bibel als die wichtigsten
    Schriftstücke aus den zuvor frei zirkulierenden Büchern zusammen, aber sie veränderten wesentliche Elemente,
    der Grund dafür, dass in der Bibel immer noch Wahrheit zu finden ist, liegt darin, dass die Fälscher nicht viel Zeit hatten, da sie schnell eine Propagandaversion der Schriften erstellen mussten, um die Massen zu indoktrinieren und was noch wichtiger ist, sie, also die päpstlichen Katholiken, mussten auch wahre Elemente einfügen, um die Menschen davon zu überzeugen, dass sie die einzig richtige Religion vertreten, der Protest gegen den Vatikan vereinte
    ganz Europa und war dezentraler Natur, es gab nie die sogenannten Protestanten, im Sinne einer Art Religion, außer dass verschiedene Gruppen von Gnostikern und Häretikern in ihrem Willen vereint waren gegen die Institution Kirche in Rom zu kämpfen.“

    „Vorher dagegen wurde Deutschland als ein Ort des Friedens und der Aufklärung angesehen, der hochangesehene Cambridge
    Historiker …kommentierte ausführlich die hohe Wertschätzung Großbritanniens für Deutschland. Zitat: In England herrschte
    einst die Ansicht vor, dass die deutsche Geschichte vor allem die Geschichte der Freiheit sei, denn es war eine Geschichte,
    die den deutschen Bund, Parlamentarismus, autonome Städte, Protestantismus und ein Freiheitsgesetz umfassten, das von den deutschen Kolonien in den slawischen Osten getragen wurde.“

    „Heute sind es deutsche, die mit ihrem Wissen in Silicon Valley führend dabei sind die technokratische Weltordnung zu
    etablieren.“
    „Die Verbindung zu Atlantis sollte aus der Erinnerung ausgelöscht werden, obwohl der zweite Weltkrieg der letzte Sargnagel für die faktische Überlegenheit
    Deutschlands in Wissenschaft und Technologie war, ist der Krieg noch nicht vorbei, es geht nicht so sehr darum gegen ein bestimmtes Land zu kämpfen, sondern gegen eine bestimmte Gruppe von Menschen. Der Nationalsozialismus sollte
    Deutschland von Anfang an von innen heraus zerstören.“

  • Vortrag: Die NWO

    https://youtu.be/b_mMWKTHOsc
    „Vortrag: Die NWO
    249.168 Aufrufe
    •28.03.2020“
    „Hans-Joachim Müller
    93.700 Abonnenten“
    Der Vatikan ist Satan. (Hajo Müller)
    Im Vatikan werden dann alle Informationen zusammengetragen,
    unter Regie der größten Geheimorganisation der Welt, die Jesuiten. Jesuiten sind ein Orden, der den Vatikan
    steuert, es ist gleichzeitig Informationsquelle des Vatikans, Wachschutz des Vatikans und Dirigent des
    Vatikans, sie schützen damit die Firma vor Angriffen von außen und sorgen dafür, dass die Firma ihrer Aufgabe nachkommen kann, die Aufgabe des Vatikans ist die Anhäufung von Besitz. (Hajo Müller)“
    „Sogar Russland unterliegt noch dem römischen Recht. (Hajo Müller)“
    „Ich informiere Sie erstmal, über die Gruppen, die jetzt in der Welt um die Macht kämpfen und dazu stellen wir erstmal die Macht vor, die 650 Jahre lang die Welt regiert hat..also vor 1920 waren die Menschen schonmal so weit, dass sie das
    alles begriffen hatten, dieses Spiel…Ende des neunzehnten
    Jahrhunderts, da kam eine Betriebsvorschrift, nenne ich es immer in die Welt und das hieß die zionistischen Protokolle und da sind schon die einzelnen Schritte, in die wir uns bewegen, benannt. Es ist von einer Geheimregierung, die tatsächlich existiert. (Hajo Müller)“

  • Forbidden Kingdoms of Inner Earth – ROBERT SEPEHR


    „Forbidden Kingdoms of Inner Earth – ROBERT SEPEHR
    191.124 Aufrufe•Premiere am 03.03.2020“
    Conspiracy Revelation: 19.9.2020: Patala….

    „According to certain Buddhist and Hindu traditions, secret tunnels connect Tibet with a subterranean paradise, and they call this legendary underworld Agartha or Shambhala. Mythologies throughout the world, from South America to the Arctic, describe numerous entrances to these fabled inner kingdoms. Many occult organizations, esoteric authors, and secret societies concur with these myths and legends of subterranean inhabitants, who are the remnants of antediluvian civilizations, which dwell in massive hollow caverns inside the earth. https://atlanteangardens.blogspot.com…
    Atlantis and Antediluvian Anthropology…
    Meaning „to weave“ in Sanskrit, the term Tantra implies a set of spiritual practices that direct the universal energies into the practitioner, thereby leading to liberation from the physical level of existence. This and other occult spiritual techniques were said to have been practiced by the members of the Thule and Vril societies in Germany, led by the medium Maria Orsic who, in pre-WWII Germany, conducted research into psychic phenomenon, and advanced propulsion technology, including saucer-shaped aircraft known in ancient Sanskrit texts as vimanas.
    Hybrids and Rh Negative Blood…
    They believed that many ancient civilizations owed their origins to refugees from Atlantis, and a people that dwelt inside of the earth, advancing the idea of a subterranean civilization ruled by an ancient parent-race who had mastered free energy they called Vril, but is also known as Chi, Ki, Prana, Orgone, and Aether. This Aryan breakaway civilization was said to have survived the antediluvian cataclysms which ended the ice age and continued to thrive below the surface of the Earth such as Antarctica.“


  • Jordan Maxwell – Our Hidden Creators


    „Jordan Maxwell – Our Hidden Creators“
    „225.258 Aufrufe•09.05.2019“
    „The Internationale: 21.600 Abonnenten: Recorded in Nov 15, 2009.“
    „In the beginning the >>>Gods<<< (Plural) (Elohim) created Heaven and Earth.“
    „Mistakes in Translation.“
    „There was no man and all the birds of the heavens were fled and all the cities thereof were broken down, so he’s talking
    about animals, birds and beautiful cities and they were all broken down, but there was no man and so you big you have to ask the question what are you talking about that there was cities and animals an birds, but there was no man… mankind wasn’t here so..I totally believe that that’s true that millions of years ago this earth was a landing place was a meeting place for what the Hebrews called the Elohim, the gods who came here and had cities and those are I mean that I’ve gotten many different multiple translations from different translations that say basically the same thing.“
    „In the Old Testament we’re seeing that there are cities where the Elohim the gods resided now when you hear that there that that the Hebrew religion is the only or the very first monotheistic religion mono of course meaning one the worship of one God in point of fact that’s not true the Hebrew religion is henotheology, henotheistic not monotheistic he No look it up in any religious dictionary you will see that the worship of one God is not monotheistic the word is henotheistic which means picking one God out of out
    of a group out of many so in Hebrew theology when you hear that the Jews were the first monotheistic religion, no, not monotheistic. The Hebrews always have many many gods, but they picked one in particular and to worship and that was Yahweh, one in particular, so you could say that they were the worshippers of one God but they picked that one god from many others.“
    „so it shows that the Hebrew God is judging among the many gods, he’s just one of them and then the footnote talks
    about the Hebrew word Elohim, within the gods within our congregation of the mighty which is the gods the Assembly of
    many gods, so the Hebrews merely picked one of the many gods that were available.“
    „And then they said the next one says in God the Lord God said Behold man has become as one of us, so now once he’s been remade which is obviously, saying that the gods have
    tampered with our DNA they somehow another procreative with us and crossbred with us which is what Zacharia Sitchin and and all these other writers that I have worked with are saying the same thing that the gods have done something with us and changed our DNA and made us look more like they do, so now all they can roam about in around us and we will never know who they are, because they look like us, no, we look
    like them and it’s my opinion I think we’ve been run on the earth by these entities who look like us, even in the Quran talks about how we created you O mankind and throughout the Oh Quran talks about the gods, we, who have created you and on the bottom paragraph it goes on to say that it shows how God made Adam in his own image he formed his body from dust just like the potter is able to make pictures from clay so god is is talked about as being the great Potter who molded us.“
    „Well, even in the Egyptian religion mankind was pictured
    as being designed by a great Potter on the potter’s wheel, implying that the gods created us, we are an experiment, a
    test-tube experiment from a higher dimension and so when we talk to Christians and Jews will tell you about God go back and look at the original word God: Elohim, it’s true, correctly translated the gods.“



    „So there must have been some kind of a monstrous displacement of of land and water hundreds of thousands of
    years ago millions of years ago who knows, but the point is is that these temples are underwater are there and
    were built by ancient civilizations, we are not the pinnacle of success on the earth and we are not the smartest, we are
    degrading, we are degenerating, we’re not de-evolving, we are devolving, so because the people who built the pyramids and the tombs and all of these artifacts is in Egypt and around the world were far smarter than that will ever be so we are merely seeing the relics of a higher civilization that were
    here and now are under the ocean.“
    „The Elohim or The Anunnaki that is being talked about now they were the gods who came here from another place in the universe who looked like us and created us and now we look like them and therefore they can now operate in public all around us and you will never know who they really are and so when I see these people who are in charge and power and they’re always in power and they hold absolute sovereign power over the earth I’m beginning to wonder who are these people because obviously they’re not human they don’t care about killing people murdering they don’t care about nothing
    but their agenda so I’m saying it’s my belief that we are being manipulated and exploited and ruled by extraterrestrials.“
    „so he’s feeding these three men then you find out later on that these three men was actually they were not three ordinary men they come to find out that that’s Abraham standing the three men, one of them is the Creator God the one called Yahweh, Jehovah, the Creator God would twoo accompanying angels, the Bible goes on to say that there were three men who looked like men but there was actually the Almighty Creator with two
    accompanying angels and afterwards nothing Genesis 18, but in Genesis 19
    those two, if you remember, the story in Genesis 18 that says that two of the men got up and left, but one of them stayed to stay a little
    bit longer with Abraham while the other two left and they said the one that styed was the Almighty God, the Creator, the one who has actually created humans.“
    „but I am totally convinced for myself that there is such
    a thing as reptile alien gods or reptile aliens, not because David Icke says so, because I’m the one that told David Icke
    about it when I brought him here back in 1992. Let me finish I brought David Icke to America back in 1992 and I
    sat with him and talked with him about the aliens and the reptile aliens and I showed him all my documents on it and he
    got interested in and today his famous we’re talking about a subject that I told him about a long time ago, but I believe that there are reptile aliens here, there’s no doubt in my mind about that… like all the other different kinds of aliens are coming here and they’re messing with us it’s
    just like a party you know and and when there’s a big party and they have party crashers, gangs come in from other from
    other places that come into the party and they’re coming in and say hey these are y’all bunch of young teenagers will
    grown men like the like a motorcycle gang and they come in and take over everything and take over the whole party and
    destroy everything.“
    „There’s no doubt in my mind from all the years that I have been able to talk to people in government and science and astronauts and medical people, in my mind mind,
    there’s no doubt in my mind that we have been created we are and we are a test-tube creation, somebody has created
    us and whoever that somebody is, looks like us, so they have taken those all those Neanderthals and the ancient hominid
    creatures which the world is filled with them, we know ..because we’re finding them everywhere, but they don’t
    look like us, so we are a special creation which is why the bible says in genesis the gods said come let us make man in our image, after our likeness, because for being so great is not that great, a bunch of hairy people out there eating each other and living like animals, so let’s take one of the females and procreate with her and see what comes out of a connection between the gods and and the indigenous creatures
    here, so I don’t think evolution is the question its intervention is the question not that we evolved but somebody intervened in our natural evolution and came here and crossbred with the indigenous creatures and
    created us that’s why one half of human is animalistic other half is angelic, because there is that part like the Apostle Paul said there’s a war in our flesh between the man that we are and the man we want to be, that makes sense because if we were like Neanderthal or cro-magnon man or these ancient hominid creatures, they live by instinct alone, just eat, sex, fight, whatever, but now we are a different creation, we have a part of the sons of God in us, so we can now design beautiful music, build televisions and go to the moon and think about the stars and have theology, philosophies,
    .. and the great arts and sciences when all that come from, my god, they were crawling around caves not long ago and we’re walking on the moon with computers, so I’m saying that that´s a part of us is that part that the DNA that they put into the humans a long time ago and were kind of bringing us
    along that’s why we call even humans today are called cultures.. that’s a particular culture, a culture is
    something on a test tube. I mean that you yeah so we are a culture they have designed us and whoever designed us we look like them and so in the Bible you could say oh what they they look like us no no you look like them they don’t look
    like you why because they look like what you look like where they came from they look like what you look like now so they have intervened in your evolution and so therefore there’s
    that inside of us is that desire to know wisdom.“
    „They are here, they live, they’re here and I am totally convinced that that is the case, we are being ruled by extraterrestrial intelligence, whoever these people
    are who are running the earth our highly advanced in science and they’re bringing us along little by little they are mutating the species, they are mutating us, we were used to be back in the 20s just regular people poor people working, now we’re getting sophisticated with computers and Hollywood and we’re moving now into the concept of procreating with
    the brain and the computer, going to the moon, it’s a whole different kind of creature is being developed right now, by whom, somebody out there is messing with us and so I’m saying what you need to do is take back your own humanity and
    no longer buy into any religious system, no cultural systems, none of this…where the words come from what are these ideas and concepts come from.. I’m not buying into anybody’s religion, they are governments, they are systems of Education, none of it. I don’t buy any of it for a long time I’ve been questioning where do we get our knowledge about
    anything, somebody’s manipulating us this is why we have something called politically correct you’ve got to understand you’ve got to go to school and learn what you’re supposed to, so you can get a job and work and fit in with the society. I
    don’t want to fit in with Society, there’s nothing about society I want to fit in.“
    „the word authority comes from author, so when they say well the authorities there is no authority, my god of my authority, so I don’t give a damn about Authority. I don’t care about government, I have no respect for religion. I got no respect for none of this whole stinking dirty system that
    somebody has created above us and manipulating us. I for one want my humanity back, I want to make my own decisions and I don’t care what Hollywood is putting out. I don’t care what’s required in service, in the services of this country. I don’t care about any of this.I want to do my own thinking. I’ll ask the questions and I’ll do my own research and that is very
    serious, because now you are thought of as a revolutionary and by god that’s what I am and that’s what I’ve always been and I want to lead a revolution, an intellectual-spiritual renaissance on this earth that causes people to say to
    the leaders of this world: no more, we’re not buying it, from here on out we’re going to deal with ourselves we’re leaving you well church we don’t need the church we’ll need the synagogue we don’t need your government and we sure as hell don’t need the US government what we need is to get back ourselves in tune with that divine universal God force that’s out there, because I’m telling you that’s where the power is.“
    „No, I don’t think so, I think no, I don’t think so at all. I
    don’t think the Queen has much power at all. I think she’s just like anything else, she’s a figurehead, just like Obama,
    he doesn’t have any power..she’s a figurehead, just like Obama, he doesn’t have any power..Europe has dominated
    the world and so England has manipulated and exploited the races the peoples of the world, the white man has been using
    exploitation Commerce to manipulate and exploit the whole human race, so I cannot believe that some young black guy that walks in and he’s gonna take over the old white man’s establishment on the earth, ain’t gonna happen, no, they brought him in for some reason to make him look like a schmuck ..but he is not in control.. the men who are
    behind him.. study their Moscow, pure Moscow communism.“
    „John Kennedy everybody loved him handsome debonair President United States wealthy and they shot this guy in public and nobody went to jail nobody’s ever going to jail why cuz the powers to be that run this country will kill you.
    You think for one minute you’re gonna get out of line and be important in this country they don’t they’ll like you so as a matter of fact the California State has a has a I don’t
    know if you know this or not but the Mafia have their own license plates in California, do you know that? Yeah, the Mafia has given their own life in plates by the California state government. I know, because I’ve sat with the mob and talked with them and they have their own license plates.“
    „people are hearing you but they’re not listening so as long as people are hearing you then you’re all right but
    when people start to listen to you now that’s different, now we’re talking politics and so we will have to take another look at you then I have had federal agents talking to me about what I do I’ve had FBI people talking to me about what I do and I’ve been threatened by federal government so I know what they can do and I respect them because they will
    kill you in this country you can be killed if you know something you’re not supposed know, if you’re talking I’m in about subject you’re not supposed to talk about they will kill you now first of all they would prefer just putting you
    in jail finding some misplaced comma on your income tax and send you away for 30 Years, but if that is not gonna work and
    they’ll just kill you you’ll be killed coming out of a restaurant one night and as some lone gunman and there and all the and everybody will be there sobbing at your funeral and but the real story is they whacked you because you shut your mouth off you’re talking too much you know too much and you’re talking too much so I’m saying that America is in
    very serious trouble because the people have not been told what’s going on they haven’t been told how this world works. I will give you I’ll give you some freebies it took me 48 years to learn this well let me tell you some of the secrets that I’ve learned one is that nothing in this world works the way you think it does nothing nothing that you understand about this world works the way you think it does it doesn’t
    banks don’t know money there are laws federal laws on the books today that’s saved very specifically banks cannot loan money.“