Anonymous ID: 7a7dd7 Dec. 22, 2018, 5:03 p.m. No.4430469   🗄️.is 🔗kun   >>0486 >>0561 >>0584 >>0605

>>4429966

 

I think it was you anon who mentioned my research on the shill spambot deployment here and. Thank you anon.

 

Below we have our spambot:

>>4429917

>>4429896

>>4429917

>>4429928

>>4429942

>>4429896

>>4429917

>>4429942

>>4429952

>>4429965

>>4429980

>>4430027

>>4430035

>>4430086

>>4430093

>>4430105

>>4430115

>>4430142

>>4430235

>>4430142

>>4429896

 

Now this is not a dumb fully automatic spambot, even though it appears as such. Notice that 1 or 2 of its posts are manually made. Also notice that the automatic text replies are sometimes edited manually. It happens when the automatic template seems too unfitting, or to help the spambot to blend in, this is why the spambot, whenever deployed is always operated and monitored by a human shill.

now to my dig:

 

a shill chatbot analysis - including relevant q posts V2.0

 

V1.0 of the research:

>>4346883 pb

 

look at the attached q posts.

The marked text explains the behavior of the so called spam chatbots.

my experiment is described here:

 

here i trolled the spam chatbot with a reply:

 

>>4345440 pb

 

and what do you know?

it gave me an automatically generated text pasta reply:

>>4345586 pb

and posted another 4 posts with a random delta that is in the range [10-30 minutes]:

>>4345586 pb

>>4345666 pb

>>4345825 pb

>>4345962 pb

 

exactly as q told us more than a year ago!

What they did manage to do during this year is to update their automatic post pattern to be triggered by a reply. Notice that the bot posts a first "common drive post", like q called it, and the subsequent 4 posts will all tap into this one.

 

To summarize, lets get back to the q post.

 

similarly to what is written in the q post, the spambot uses a 5 prong pre packaged injection, only this time it has a precursor post serving as bait. After an anon takes the bait and replies, the bot searches for "negative" keywords ("bot", "r2d2", "spam", "shill", etc). If it found these words, then the 5 prong pre packaged delivery is injected, meaning 5 automatic posts are inserted, with the first one auto generating the other 4 posts at random designated times with deltas in a range of 10 to 30 minutes. Note that all 4 posts are linked to each other, forming a chain of posts with a common driver (root).

Then, as q said, "shills log and send new info back to ASF for instruction." with ASF probably referring to the APACHE SOFTWARE FOUNDATION.

see attached snip taken from:

 

https://www.apache.org/foundation/

 

Also as you may or may not remember, Q used "APACHE" as a signature, and told us to dig it. An anon found out before that it is connected to the Securedrop whistleblower honeypot fiasco, but it could have multiple meaning with one of the being the ASF, or in fact the ASF can be connected to securedrop as well (see attached q snip).

 

Manual script inserted by a human operator:

 

Last bread I played a little trolling game with the spambot. I exposed 3 of his lies on purpose, to see if in fact there is a human operator that can insert a script that gets inserted, thus modifying the next automatically generated post. "Trolling is fun".

 

Here is the experiment:

 

  • trolled it once:

>>4351198 pb

 

and received a manually inserted script.

>>4351259 pb

 

  • trolled it a second time:

>>4351407 pb

 

and received a manually inserted script to an automatic template.

>>4351463 pb

 

attached are the snips of the second trolling and reply that included the manual insertion.

 

my conclusion: there is a human operator that does exactly that, he can manually interupt the automatic generation of posts and either pick a different one or insert a specific line.