Analyzing Analytics (Featuring: The FBI)
exploits.run
exploits.run
Some searching on code samples shows that the AAM section of analytics code is an exact match for analytics code served up by an older version of the FBI's most wanted website. Likely that it was also used on older versions of other FBI websites as well.
In the end I find it unlikely that this website has anything to do with the FBI, and more likely that the website owner copy-pastad a large section of source code and accidentally ended up with this result.
One bit of commonality I've noticed is that a lot of websites with the FBI tracking code were all built with FrontPage. I'm not sure if this is causal or coincidental, but perhaps it contributes to this that FrontPage allows you to open a webpage that you saved from IE and edit it... which might lead to some websites being complete duplicates of FBI websites, except for visible content, simply because websites like the FBI most wanted were relatively prominent parts of the early internet.
Edit: I spent a little time riding the WayBackMachine to some of the other webpages when they were apparently using FBI analytics code. The results are odd but they're so inconsistent that it's hard to think it was at all intentional. One interesting finding is that both ohthx.com and ppc-guy.com, at the time they supposedly had the FBI analytics ID, were apparently hosting an analytics package called Prosper202 that redirected the WayBackMachine crawler from the login page to fbi.gov. I have a suspicion that this was a partially-joking way to deter crawling of the admin interface of the software. The record that they used the FBI analytics code is presumably just an artifact of the crawler following the redirect. It seems that this exact Prosper202 behavior results in the majority of the old hits.
They are the websites that are being used on the facebook pages that are primarily pushing 'reopen' content, and the GA accounts on those pages links them to a bunch of pro-firearm shell corps as well.
Here's the thread. It got deleted since it was deemed as doxxing (a reddit no-no) even though Whois data is public:
http://removeddit.com/r/maryland/comments/g3niq3/i_simply_ca...
A very interesting way to associate the same site owners!
>Update, April 21, 6:40 a.m. ET: Mother Jones has published a compelling interview with Mr. Murphy, who says he registered thousands of dollars worth of “reopen” and “liberate” domains to keep them out of the hands of people trying to organize protests. KrebsOnSecurity has not be able to validate this report, but it’s a fascinating twist to this tale: How an ‘Old Hippie’ Got Accused of Astroturfing the Right-Wing Campaign to Reopen the Economy
Update, April 22, 1:52 p.m. ET: Mr. Murphy told Jacksonville.com he did not register reopenmn.com or reopenpa.com, contrary to data in the spreadsheet linked above. I looked up each of the records in that spreadsheet manually, but did have some help from another source in compiling and sorting the information. It is possible the registration data for those domains got transposed with reopenmd.com and reopenva.com, which included Mr. Murphy’s information prior to being redacted by the domain registrar.
[1] https://en.wikipedia.org/wiki/Sunil_Tripathi#Misidentificati...
If you check your console log, you'll see:
> Tracking Prevention blocked an XHR request to https://www.reddit.com/api/v1/access_token.
This is called Analytics hi-jacking and it was once (still is) a common spam technique: Create site buy-my-stuff.net, load a bunch of hijacked analytics scripts there, and then the owners of those accounts will see “but-my-stuff.net” in their analytics reports.
Edit: As commenter lmgk reminded me, you don’t even need to make a site, just use the API to make pageview calls.
Also, usually these IDs are copied when someone clones a website they want to steal the design of but they don’t bother updating the style or JS.
eg: maybe a website about siberian huskies actually has a hidden login or hosts another service when contacted on port 80/443 in just the right way?
Now, that would make more sense for the CIA than the FBI, but I think it illustrates another avenue of interpretation
[1]: https://www.goodreads.com/book/show/46223297-permanent-recor...
In this example its quite possible FBI put their traps to get better understanding what third parties are involved; who is visiting the site, and probably some admin management page behind it. Sort of like get the contacts of a criminal and go from there.
I just made a tenuous mental connection between this concept and a Reddit phenomenon called "Lake City quiet pills". I heard about it on the podcast "Stuff They Don't Want You To Know" and it held my interest for a few hours' worth of investigation.
The short version is that a Redditor died. He was a stereotypical grumpy old dude, and someone hopped on Reddit and posted that he'd passed. Someone got interested and tied that poster to some websites, one of which had a bunch of stuff hidden in the public source. It definitely seems like a clandestine group of some kind communicating, but to who it was and to what end isn't clear. The Reddit conspiracist belief seems to be that it was a group of assassins-for-hire.
Podcast: https://www.iheart.com/podcast/182-stuff-they-dont-want-you-... Subreddit: https://www.reddit.com/r/LakeCityQuietPills/
It's not just the Google Analytics ID or GTM Id, you can also use the Adsense pub-id or just about anything else that you might think sites have in common. When you start to also look at backlinks and IP neighborhoods, things can get interesting, as well.
[0] https://www.nytimes.com/2016/05/06/nyregion/students-at-fake...
https://web.archive.org/web/20160327093120/http://unnj.edu/
[1] https://www.freep.com/story/news/local/michigan/2019/11/27/i...
https://web.archive.org/web/20180414235355/http://university...
Maybe it's the same with these sites?
Why would they need to do that?
Presumably the FBI doesn't all share just one massive "fbi@gmail.com" email address.
Even if a bunch of FBI employees decided foolishly to use google analytics on their honeypot sites, one would expect them to all separately sign up using different google accounts - either using their real email addresses, or hopefully throwaway ones.
A relative of mine works at FBI and several years back he told me a story about how an investigation into an organized crime syndicate was blown up because an agent on the case was dumb enough to check out the target's LinkedIn profile while he was logged into his own real account. So the target got a notification that Joe Blow from the FBI had just viewed his profile. Over a year of work down the drain with a single GET request, crazy.