Kategorie: IT Security/IT Forensic

  • Updates notwendig: Sicherheitslücken im UEFI-BIOS erleichtern Rootkitverankerung

    „Updates notwendig: Sicherheitslücken im UEFI-BIOS erleichtern Rootkitverankerung“

    „Zahlreiche Bugs in UEFI-BIOS-Versionen der Firma Insyde H2O betreffen auch große PC-Hersteller. Sie erleichtern gezielte Angriffe auf Desktop-PCs und Notebooks.“

    „02.02.2022
    Security
    Von
    Mark Mantel

    Für viele Notebooks, Desktop-PCs, Workstations, Server und Embedded-Systeme sind BIOS-Updates dringend empfehlenswert, denn im UEFI-BIOS-Code der taiwanischen Firma Insyde wurden 19 Sicherheitslücken mit „hohem“ Risiko entdeckt. Das Firmware-Framework InsydeH2O verwenden unter anderem die Hersteller Fujitsu, Siemens, Dell, HP, HPE, Lenovo, Microsoft, Intel und Bull Atos für ihre UEFI-BIOS-Versionen.

    Die Sicherheitslücken betreffen insbesondere den schon oft mit schweren Schwachstellen aufgefallenen System Management Mode (SMM) und lassen sich dazu ausnutzen, manipulierte Firmware im System zu verankern, beispielsweise in Form von BIOS-Rootkits..Zudem schlagen gängige Sicherheitsmechanismen nicht an, etwa Endpunkt-Sicherheitsverfahren, Secure Boot und virtualisierungsbasierte Sicherheitsisolierung.“

    „Insyde listet alle 19 Sicherheitslücken auf einer eigenen Security-Webseite auf. Sie alle haben CVSS-Scores von 7,5 bis 8,2, sind also mit einem „hohem“ Sicherheitsrisiko eingestuft:

    CVE-2020-5953
    CVE-2021-33625
    CVE-2021-33626
    CVE-2021-33627
    CVE-2021-41837
    CVE-2021-41838
    CVE-2021-41839
    CVE-2021-41840
    CVE-2021-41841
    CVE-2021-42059
    CVE-2021-42060
    CVE-2021-42113
    CVE-2021-42554
    CVE-2021-43323
    CVE-2021-43522
    CVE-2021-43615
    CVE-2022-24030
    CVE-2022-24031
    CVE-2022-24069″

    „BIOS-Updates kommen

    Firmware-Updates von Insyde stehen den betroffenen Herstellern bereits zur Verfügung, sie müssen damit aber noch eigene BIOS-Updates entwickeln und verteilen. Fujitsu etwa hat mit der Bereitstellung schon begonnen.

    Die Sicherheitsfirma Binarly entdeckte die Sicherheitslücken ursprünglich in Fujitsu-PCs, wies sie später aber auch bei anderen Herstellern nach. Binarly leitete daraufhin den Disclosure-Prozess ein – im Blog-Beitrag wird die Zusammenarbeit insbesondere mit Binarly und Fujitsu gelobt. In einer eigenen Auflistung stehen derweil die IDs von 23 Sicherheitslücken, vier davon stammen aus älteren Bekanntmachungen.“

    Quelle: https://www.heise.de/news/Updates-notwendig-Sicherheitsluecken-im-UEFI-BIOS-erleichtern-Rootkitverankerung-6346108.html

  • Rootkit schlüpft durch Lücke in HPEs Fernwartung iLO

    „Rootkit schlüpft durch Lücke in HPEs Fernwartung iLO “

    „Eine Iranische Security-Firma hat ein Rootkit entdeckt, das sich in Hewlett Packards Fernwartungstechnik „Integrated Lights-Out“ (iLO) eingenistet hat.“

    „Update
    02.01.2022 12:02 Uhr
    Security

    Hinter der von Compaq entwickelten und von Hewlett Packard Enterprise (HPE) genutzten Fernwartungstechnik „Integrated Lights-Out“ (iLO) steckt wie bei den meisten derartigen Serverkomponenten ein eigener Computer, der über das Netzwerk erreichbar ist. Er kann den Server fernsteuern und ihn nicht nur ein- und ausschalten, sondern auch fernbedienen, Betriebssysteme installieren und sogar seine Firmware aktualisieren. Der Zugriff auf iLO kann über eine separate Netzwerkkarte erfolgen, aber auch aus einem installierten Betriebssystem heraus. Abschaltbar ist die Funktion nicht, sondern aktiv, sobald ein Server Strom erhält.“

    „Die von der Firma Amnpardaz analysierte „Implant.ARM.iLOBleed.a“-Malware in der HPE-iLO-Firmware war so gebaut, dass sie regelmäßig sämtliche Datenträger des Servers löschte. Selbst wenn ein Admin den Server also neu aufgesetzt hat, zerstörte der Eindringling seine Arbeit nach einer Weile erneut. Updates der iLO-Firmware können dem Schädling laut Amnpardaz nichts anhaben: Er trickst die Update-Funktion aus, indem er einen Erfolg zurückmeldet. Obendrein manipuliert er die Versionsnummer, die die Weboberfläche anzeigt. So wiegen sich Admins in falscher Sicherheit.“

    Quelle: https://www.heise.de/news/Rootkit-schluepft-durch-Luecke-in-HPEs-Fernwartung-iLO-6315714.html

  • More than 100,000 Zyxel networking products could be vulnerable to a hardcoded credential vulnerability (CVE-2020-29583) potentially allowing cybercriminal device takeover.

    „More than 100,000 Zyxel networking products could be vulnerable to a hardcoded credential vulnerability (CVE-2020-29583) potentially allowing cybercriminal device takeover.“

    The initial IPs scanning for this are all geo-locating back to Russia,” Ullrich told Threatpost. “But other than that, they are not specifically significant. Some of these IPs have been involved in similar internet wide scans for vulnerabilities before so they are likely part of some criminal’s infrastructure.”

    „Separately, researchers with GreyNoise said on Twitter, on Monday, they observed a slew of “opportunistic exploitation of the newly discovered Zyxel USG SSH Backdoor and crawling of SOHO Routers.”
    The vulnerability stems from Zyxel devices containing an undocumented account (called zyfwp) that has an unchangeable password – which can be found in cleartext in the firmware..“

    „From an attacker perspective, this would give cybercriminals the ability to adjust firewall rules, run malicious code on devices, or launch machine-in-the-middle attacks, Ullrich told Threatpost.“

    Source: https://threatpost.com/cybercriminals-exploits-zyxel-flaw/162789/

  • Sophisticated hackers are targeting these Zyxel firewalls and VPNs

    „Sophisticated hackers are targeting these Zyxel firewalls and VPNs“

    „Written by Liam Tung, Contributor
    on June 25, 2021 | Topic: Security

    Zyxel, a manufacturer of enterprise routers and VPN devices, has issued an alert that attackers are targeting its devices and changing configurations to gain remote access to a network.

    In a new support note, the company said that a „sophisticated threat actor“ was targeting Zyxel security appliances with remote management or SSL VPN enabled.

    (Virtual private networks are essential to staying safe online — especially for remote workers and businesses.)

    The attacks affect organizations using Unified Security Gateway (USG), ZyWALL, the USG FLEX combined firewall and VPN gateway, Advanced Threat Protection (ATP) firewalls, and VPN series devices running its ZLD firmware.

    SEE: Network security policy (TechRepublic Premium)

    „The threat actor attempts to access a device through WAN; if successful, they then bypass authentication and establish SSL VPN tunnels with unknown user accounts, such as“zyxel_sllvpn“, „zyxel_ts“, or „zyxel_vpn_test“, to manipulate the device’s configuration. We took action immediately after identifying the incident,“ Zyxel noted.

    This seems to suggest that the attackers are using hardcoded accounts to access the devices remotely.

    Earlier this year, researchers found a hardcoded admin backdoor account in one of Zyxel’s firmware binaries, which left 100,000 internet-exposed firewalls and VPNs.“

    „Zyxel notes that firewalls may be affected if users experience issues accessing the VPN, or routing, traffic and login issues. Other signs include unknown configuration parameters and password problems.

    Zyxel warns admins to delete all unknown admin and user accounts that have been created by the attackers. It also advises them to delete unknown firewall rules and routing policies.“

    „“Based on our investigation so far, we believe maintaining a proper security policy for remote access is currently the most effective way to reduce the attack surface,“ Zyxel said.

    It recommends disabling HTTP and HTTPS services from the WAN side. For those who need to manage devices from the WAN side, it recommends restricting access to trusted source internet address and enabling GeoIP filtering. It also emphasizes that admins need to change passwords and set up two-factor authentication.“

    „The attacks on Zyxel devices follows a string of similar attacks on a range of VPN devices, which make a handy entry point to a corporate network for remote attackers to gain persistent access. The US Cybersecurity and Infrastructure Security Agency warned in April that attackers were targeting vulnerabilities in Pulse Secure Connect VPNs.“

    Source: https://www.zdnet.com/article/sophisticated-hackers-are-targeting-these-zyxel-firewalls-and-vpns/

  • Badbios connecting and hiding traffic from WAN using zyxel USG20…

    „Gepostet vonvor 7 Jahren:
    Badbios connecting and hiding traffic from WAN using zyxel USG20 – Other Badbios attacks linux kernel with live cd bash script and random process injections

    Not only are all the machines in my house infected but the firewall i bought from amazon.com was tampered with before i got it in the mail.

    The entire USG20 is under stealth control from the WAN – It also demonstrated the ability to break the rules if you make your own browser. I discovered this when i compiled a basic browser that would pull http data even though the firewall had no rule to allow it + Other browsers like I.E , Firefox and Gchrome obey firewall rule and no data access while custom browser can access internet in secret past USG20. USG also powers off when running multiple VPNs or slows down to 1 or 2k a sec to stop transmissions from individual openvpn connections.

    My personal computers have 2 different bios infections… The laptop badbios infection stops all knoppix based OS and older linux like MEPIS from booting at all

    My older pentium 2 system which has an awardbios from 1995 is also infected with the same virus but it dont stop the kernel… but

    Both computers are injecting 6 bash scripts or terminal windows that i can’t shut down or edit or view into every linux distro on the market i’ve tried so far.. now i honestly can’t say what the 6 bash scripts or terminals are doing but they can’t be killed because if you kill them them a mysterious root user logs in within 1 second and relaunches the bash. The only distro that doesn´t have any strange processes is TAILS… But when i use tails on my laptop the mouse stops working as soon as the tor network makes a connection to the internet and i have to move it to another port to make it work again. Seems to be automated

    In windows 7 and windows 8 the 32bit service host is relaying the underlying badbios connection out every time a brower windows opens but i’ve managed to control the breakins using a combo of AVG firewall combined with zyxel + the Strongvpn with I.E because I.E detects the second „fake“ connection to the webpage after the first one loads up. However the information is not totally SECURE sent over the vpn because badbios attempts to mess up the vpn but it does work to bypass all the „Routed“ hacks that can sometimes slow up or block you from accessing info.

    I also believe that Badbios is adding functionality to the power supply units of all computers allowing them to be the client END of a Network over power lines? I say this because some people i know who are connected to the infection on my computer seem to know what i’m doing all the time on the computer even though i have no wifi or bluetooth at all.

    I had a laptop in 2012 was receiving wake up and turn on packets to the BIOS from an unknown network.. the computer even knew when I was in the room with it..to turn on LOL which leads me to believe Badbios is much more than just a computer bios and it might be communicating with stealth sensors and or cameras relaying your position to whoever owns the unknown network… I say unknown because i drove the laptop 20 miles out in the country away from celltowers and wifi and it still turned on randomly out in timbuk2. I found out later they had also somehow installed their own „theft prevention system“ over the network that allowed them to geolocate the PC and talk to it via some hidden networking that works from your car radio and possibly piggybacks on to SIRIUS or a random .gov satt in space via modern car antenna. Can say i’m smart enough to know but i don’t use any kind of cell phone so none of that. All i know is they knew where that PC went all the time

    Anyway IF you have been infected with BADBIOS or have become a target of these asshats… take a few precautions here and know some stuff.

    Don’t buy any OS from ebay or OSDISC.com Don’t buy any computer hardware from AMAZON.

    Unlike a lot of people who are infected with badbios… i know some of the people who are responsible for infecting my original computers with the original version and it seems to be something to keep you busy by constantly creating a new level of evolving computer problems based on how much you know about computer science.

    I’ve had this shit on my computers in 1 form or another for other 10 years and i know some of the assholes involved with putting it on my machine as well. The same people are responsible for creating massive covert networks to spy on americans by putting small and almost undetectable cctv cams on a lot of telephone poles and in various locations and sometimes even put up fake cell phone towers to intercept and relay calls.

    These cell phone towers can be really small and hell anything that has been covered by the news must be REALLY old news and i was thinking that what was stopping SAMSUNG or SONY from building a hidden cellphone into the design of my laptop s0 If you program the bios and tell the hidden phone to „call“ the same .gov # in secret on powerup somewhere you can easily maintain secret ethernet over cellphone dialup for keylogging.“

    „r/badBIOS
    BadBIOS and other firmware rootkits, nation-state spyware, interdiction and implants, forensics… side channel attacks, power line hacking, hacking smart homes, constructing faraday rooms, forensic bags, Libreboot, ultrasound and electromagnetic radiation (EMR) technical surveillance counter measures (TSCM) and shielding.
    Online
    Am 31. Okt. 2013 erstellt
    Eingeschränkt“

    Source: https://www.reddit.com/r/badBIOS/comments/3a00l3/badbios_connecting_and_hiding_traffic_from_wan/

  • heise online News 01/2021: Zyxel hat Backdoor in Firewalls einprogrammiert

    „heise online News 01/2021 Zyxel hat Backdoor in Firewalls einprogrammiert

    Zyxel hat Backdoor in Firewalls einprogrammiert

    Zyxel Networks hat in Firewalls und Access-Point-Controller Hintertüren eingebaut und das Passwort verraten. Für die Firewalls gibt es ein Update.
    Update
    04.01.2021
    Security
    Von
    Daniel AJ Sokolov

    Wer ein Zyxel-Gerät der Reihen USG, ATP, VPN, ZyWALL oder USG FLEX hat, sollte schleunigst die Firmwareversion überprüfen. Zyxel hat nämlich in ZLD V4.60 ein Zugangskonto mit fix eingestelltem Usernamen zwyfp und fixem Passwort einprogrammiert, über das die Software der Geräte verändert werden kann. Zu allem Überdruss waren diese Zugangsdaten sogar im Klartext in einer Binary-Datei ersichtlich.

    Das Konto ist in der Kontenverwaltung nicht zu sehen, das Passwort lässt sich nicht ändern. Die Zugangsdaten erlauben Zugriff sowohl über SSH als auch das Web-Interface. Entdeckt wurde das als CVE-2020-29583 registrierte offene Scheunentor von Niels Teusink von der niederländischen IT-Sicherheitsfirma EYE Ende November 2020. Zyxel Networks hat die Sicherheitslücke nach eigenen Angaben für automatische Firmware-Updates via FTP geschaffen. Unter SD-OS laufende Geräte der VPN-Serie seien nicht betroffen.

    Weil fix einprogrammierte Zugangsdaten eine richtig schlechte Idee sind, hat Zyxel die Firmwareversion ZLD V4.60 zurückgezogen und durch ZLD V4.60 Patch 1 ersetzt. Betroffen ist allerdings auch Firmwareversion V6.10 der WLAN-Access-Point-Controller NXC2500 und NXC5500. Weil Zyxel erst im April einen Patch bereitstellen möchte, ist guter Rat teuer.

    Eine Stichprobe EYEs hat ergeben, dass rund zehn Prozent der Zyxel USG/ATP/VPN mit niederländischer IP-Adresse die verwundete Firmware nutzen. Hochgerechnet könnten weltweit mehr als 10.000 Geräte betroffen sein – ein gefundenes Fressen für Botnetzbetreiber und andere Übeltäter.
    ..

    heise-online-Leser Daniel Nussko teilte uns mit, dass er im August 2020 auf einen Hintertür-Account (CVE-2020-13364, CVE-2020-13365) in neun Netzwerkspeicher-Modellen (NAS) Zyxels gestoßen ist. Hat ein Angreifer Zugriff auf den „unprivileged ‚admin‘ user account“ kann er über SSH oder Telnet ein Passwort für den Root-Account „NsaRescueAngel“ generieren. Weitere Infos kann man in einer Warnmeldung von Zyxel nachlesen.

    Patches stellt Zyxel allerdings nur für vier der neun Modelle zur Verfügung. Für vier weitere Modelle hat Zyxel den Support laut Nussko eingestellt, womit diese Geräte verwundbar bleiben. Für Hilfe zum neunten Modell sollen Betroffene den Support kontaktieren, sagt Zyxel.
    (ds)“

    Quelle: https://www.heise.de/news/Zyxel-hat-Backdoor-fix-in-Firewalls-einprogrammiert-5002067.html

  • Retrospective View / Retrospektive Sicht Chemtrails 2013-2021

    Retrospective View / Retrospektive Sicht Chemtrails 2013-2021

  • MY ROUTER SECURITY LOG | PING OF DEATH

    „34.117.12.32“
    „Posted by ClaytonLBr04/09/2021“
    „MY ROUTER SECURITY LOG | PING OF DEATH“

    „This all seems like an unnecessary amount of persistent invasion of my privacy. I don´t have that many computers or whatever is trying to connect to my computer. Two days ago my computer network was randomly rendered unusable. While trying to reset my modem and router my router would not reconnect. This all happened around 2:00 AM – 4:00AM. As I tried resetting my computer my television would come on and off from a working state to freezing. This is strange because the internet is not connected to the modem in any way. I lose the phone line and internet when I reset the modem and router box but not the television. Eventually I decided to master reset my router because someone or something had likely taken over the box. The internet here in Utah is not decent… while I was trying to figure out why my router had an orange light instead of a blue one, and while my main modem/router was returning to working order; my own personal router would not reset or turn on… After the master reset of my router I set up new parameters and now I see all these different IP Addresses in my security log trying to ping my computer. I only connect to one modem/router therefore these other IPs are 100% not mine. I live in an area where I am convinced the people around me are constantly monitoring me illegally and invading my privacy. Here’s some more proof to further the very real theory.

    I recently discovered a whole lot more IP addresses that I have never before seen on my router.
    Here is what the list looks like:

    04/08/21 04:08:55 AM Ping Of Death from 34.117.12.32 to droped
    04/08/21 04:08:55 AM Ping Of Death from 34.117.12.32 to droped
    04/08/21 04:08:56 AM Ping Of Death from 35.212.182.232 to droped
    04/08/21 04:08:56 AM Ping Of Death from 34.98.64.218 to droped
    04/08/21 04:08:58 AM Ping Of Death from 34.117.12.32 to droped
    04/08/21 04:09:00 AM Ping Of Death from 35.212.182.232 to droped
    04/08/21 04:09:00 AM Ping Of Death from 35.212.182.232 to droped
    04/08/21 04:09:22 AM Ping Of Death from 204.237.133.116 to droped
    04/08/21 04:09:23 AM Ping Of Death from 204.237.133.116 to droped
    04/08/21 04:09:24 AM Ping Of Death from 204.237.133.116 to droped“

    Source: https://loopsoundsampleworkshop.wordpress.com/2021/04/09/my-router-security-log-ping-of-death/

    ConspiracyRevelation: 10.7.2021: Look…the same thing here…
    The Global Monopoly Corporate Digital Cartel, Verizon and the NWO Censor Twitheads…

    https://scamalytics.com/ip/104.17.238.85
    https://scamalytics.com/ip/34.117.12.32
    https://scamalytics.com/ip/35.165.95.183
    https://scamalytics.com/ip/44.236.165.238
    https://scamalytics.com/ip/104.244.42.136
    https://scamalytics.com/ip/93.184.220.70
    https://scamalytics.com/ip/23.160.0.108

    Amazon Technologies, Google LLC, Cloudflare Inc, whereas Cloudflare is assessed as the highest fraud risk, Amazon and Google are rated as medium fraud threat.

    TCP LAN52065 44.236.165.238:443 HERGESTELLT 1636
    TCP LAN52074 54.194.46.103:443 HERGESTELLT 1636
    TCP LAN52075 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52078 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52079 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52080 44.236.165.238:443 HERGESTELLT 1636
    TCP LAN52081 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52083 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52084 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52085 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52113 34.117.12.32:443 HERGESTELLT 1636
    TCP LAN52177 93.184.220.70:443 HERGESTELLT 1636
    TCP LAN57129 104.244.42.136:443 HERGESTELLT 5668

    Update: 10.7.2021: Zombiehost-Addresse (High Fraud Risk Microsoft): https://scamalytics.com/ip/51.103.5.186
    Bypassed Simplewall, neueste Version, auf diversen Laptops…Simplewall hatte ein direktes svchost Antidot, gegen die Bundmafia/CIA/NSA/DoD/Microsoft-Built-In-Facebook-Trojaner-Exploits.

  • STAATSTROJANER: NSO-Trojaner sorgen weltweit für „Staatsterror“…

    „STAATSTROJANER:
    NSO-Trojaner sorgen weltweit für „Staatsterror“
    Journalisten und Politiker sind mit dem NSO-Trojaner ausspioniert worden. Nun gibt es erstmals eine Übersicht und Analyse zum Vorgehen weltweit.“


    „Erstmals gibt es ein große Analyse des Einsatzes der NSO-Trojaner.
    (Bild: Stephen Dunn/Getty Images)“

    „Gemeinsam mit der Menschenrechtsorganisation Amnesty International und dem Citizen Lab der Universität Toronto hat die Initiative Forensic Architecture das Vorgehen und den Ablauf bei Hacks mit dem Trojaner der israelischen NSO Group untersucht. Die Analyse liefert damit erstmals einen detaillierten Blick in die Nutzung der Trojaner, die Staaten zugeschrieben werden, um damit gegen oppositionelle Politiker, Journalisten oder andere vorzugehen.

    Die Ergebnisse der Untersuchung hat das Team als interaktive Webplattform aufgearbeitet und unter dem Titel: „Digitale Gewalt: Wie die NSO Group Staatsterror ermöglicht“ veröffentlicht. Zusätzlich dazu stehen Videointerviews mit Betroffenen und mit den Forschern bereit, für die Filmemacherin Laura Poitras verantwortlich war, die für ihren Dokumentarfilm Citizenfour über Edward Snowden einen Oscar erhalten hat. Hinzu kommt außerdem eine Analyse des Firmennetzwerks der NSO Group.

    Wiederkehrende Muster bei Trojaner-Befall:
    Aus den bisher aus öffentlichen Quellen oder auch aus Gerichtsdokumenten verfügbaren Information zu den Hacks mit Hilfe der NSO-Trojaner seien bereits einige Muster erkennbar. So zielten Trojanerangriffe meist nicht auf Einzelpersonen, sondern immer auf ein Netzwerk von Personen. Die Infektionen geschehen dabei, wenn „diese zivilgesellschaftlichen Netzwerke kontroverse oder kriminelle Staatspolitik aufdecken oder dieser trotzen.“

    Parallel zur Infektionen der Geräte komme es außerdem zu Gewalt in der physischen Welt. Dazu gehören „Einbrüche, Einschüchterungen, Übergriffe, Festnahmen, Klagen und Hetzkampagnen sowie Mord“, was sich an Jamal Khashoggi gezeigt habe, dessen Freunde und Kollegen mit dem Pegasus-Trojaner von NSO angegriffen worden seien. Mit Hilfe der Trojaner könne dabei außerdem die Reichweite einer Staatsmacht deutlich erweitert werden, um Dissidenten auch im Exil zu verfolgen.

    Zu den untersuchten Fällen gehören Trojanerinfektionen in „Mexico, den Vereinigten Arabischen Emiraten, Saudi Arabien, Marokko, Ruanda, Indien, Spanien und Togo“. Ende des Jahres 2019 wurde durch eine Klage bekannt, dass die NSO Group allein zwischen April und Mai 2019 rund 1.400 Whatsapp-Nutzer gehackt haben soll. Das Citizen Lab der Universität Toronto hat dabei über Monate entsprechende Beweise gesammelt.“

    „Trojaner Datensicherheit Onlinedurchsuchung Sicherheitslücke Internet Politik/Recht Security“

    Quelle: https://www.golem.de/news/staatstrojaner-nso-trojaner-sorgen-weltweit-fuer-staatsterror-2107-157918.html

  • McAfee’s „tot“ und der Einsturz des Hochhauses in Miami stehen im Zusammenhang…

    https://t.me/conspiravyrevelation/9101

    „‼️McAfee’s „tot“ und der Einsturz des Hochhauses in Miami stehen im Zusammenhang. McAfee soll in dem Gebäude eine Wohnung gehabt haben, in der sich die Beweise auf 31Terrabyte befunden haben sollen. Der Deepstate ist schwer in Panik und sie tun alles um zu verhindern, daß die Beweise an die Öffentlichkeit kommen.
    👉@technicus_news [28.06.2021]“

    „Mord ist die extreme Form der Zensur. / Assassination is the extreme form of censorship. (George Bernard Shaw) [11868]“

    https://t.me/police_frequency/47571