Accidentally Stopping a Global Cyber Attack
malwaretech.com
malwaretech.com
Lessons learnt by NSA - never over estimate the skill level of your network admins.
Lessons learnt by Microsoft - never under estimate the loyalty of your Chinese Windows XP users, both XP and Win10 have 18% of the Chinese market [1].
Lessons learnt by the Chinese central government - NSA is a partner not a threat, they build tools which can make the coming annual China-US cyber security talk smooth.
[1] http://gs.statcounter.com/os-version-market-share/windows/de...
I like to imagine that one of the developers on that team filed a tech debt item to do exactly this, was never able to get their manager to prioritize it, and is now pulling out their hair saying, "I told you so!"
Malware authors have budgets and schedules too. It's a business, probably more profitable than 90% of the startups in SV
No, it's not, and it's pretty damn rude to make that claim in the presence of legitimate businesspeople.
I'll take an honest crook any day.
The typical moral distinction b/w a business and other entities which make[1] money is a business (presumably) does it within the constraint of their counterparties enjoying the liberty of choice. This becomes a grey area when government enters the picture and removes liberties--which is why there is debate about the legitimate role of government's monopoly on legitimate violence/aggression here.
1 - note, a further distinction could be made between entities which create value, and those which transfer it.
Hospitals just happened to be disproportionately affected by this attack because a lot of them have ineffective IT departments/mangement and never applied the MS17-010 patch.
Of course, these people are still felons and are likely responsible for millions of lost family photos, work and school documents, etc. They just aren't going out of their way to target hospitals.
This means that they knowingly or with reckless negligence unleashed such an attack on the world. If they had been more "scrupulous" criminals, they would have more narrowly tailored their attack on targets they believed deserved to be extorted or where such extortion would not interfere with life critical systems.
I'm not a lawyer, but if they were a nation state, I believe they would have violated the Geneva Convention's prohibition on attacking hospitals.
That said, I think this attack gives more weight to NSA critics that contend that their exploit research should be focused more on defense rather than offensive capabilities. Their carelessness combined with another group wanting to embarrass them is what allowed this indiscriminate attack to be inflicted on civilian infrastructure.
Until today, there was nothing to apply if your computers were running XP or 2003. Guess which Windows versions are the most popular in UK hospitals? So I think your sentence should read like "Hospitals just happened to be disproportionately affected by this attack because they were forced to trust Microsoft would never put corporate profit before social responsibility."
But making BTC hard to cash out is a hard problem. Although particular addresses can be blacklisted, mixing services are now mainstream. Some return fresh BTC from miners. Even so, it's problematic to mix humongous quantities. For example, the Sheep Marketplace owner/thief overwhelmed Bitcoin Fog with 10^5 BTC. The trail went dead after that, but he got busted while cashing out. His girlfriend was receiving huge international wire transfers, and could not explain where the money was coming from.
All this means instead of pc plod being unable extradite the perps from eastern Europe to you get the serious players involved.
Similar attacks using other vulns or tooling are inevitable but this is prob much less impactful and the registration probably mitigated a lot of damage
Was it "orchestrated", or did the worm just spread randomly and opportunistically?
By the look and UX of the virus (yes there's a UX there too), they do seem to have a better grasp than most script kiddies, who usually can barely extend whatever script they've got.
The site itself doesn't seem to have enough ads or well placed enough ads to be "income as a goal". So I'm guessing it's a " proof I can do stuff " or "trophy room" blog, which doesn't care (HR and recruiting will happily use worse websites to judge canidate value, or trophy rooms will be put in a room no one else wants/cabin so far from everyone it doesn't have electricity)
Or maybe this story isn't really accurate and there was no accident...
EDIT:
And if it isn't the role of those agencies to defend the public health IT infrastructure, which agencies are responsible, if any?
Then, due to lax controls, the exploit got leaked and used by the ransomware developers.
Their culpability goes back a lot further than not noticing a kill switch.
Even in this case though, you would think the NSA, etc have to do less analysis of the payload since they got to inspect and play with it for much longer than anyone else. Therefore they could waste less time on that and more quickly focus on the rest of the issue.
There are some three-letter agencies that do work on fighting malware, often by partnering with relevant companies like Microsoft (who was a major anti-malware player here too). I know the FBI does so publicly, and some government groups invite large companies to low-secrecy briefings on security.
But I've never heard a mention of the NSA 'fighting' malware that isn't obviously governmental. Even if they knew about the exploit, used the exploit instead of disclosing it, and are well-placed to fight it, I think that's just filed under 'not my department'.
Right now looking at how the election scandals went they are there at prosecution and have access that they are given willingly.
If anything they will learn to automatically disable any nodes that are clearly operating out of a public office building.
...see the problem?
Win 7 is rising again for months
Win10 and WinXP are shrinking
If you are suggesting that developers, regardless whether they develop mobile apps or ransomware, will start relying less on DNS, I respectfully disagree.
Someone else in this thread commented how reliance on DNS makes systems "fragile". With that I strongly agree.
The same old assumptions will continue to be made, such as the one that DNS, specifcally, ICANN DNS, is always going to be used.
How to break unwanted software? Do not follow the assumptions.
For example, to break a very large quantity of shellcode change the name or location of the shell to something other than "/bin/sh".[1]
Will shellcoders switch to a "robust statistical model" instead of hard coding "/bin/sh"?
Someone once said that programmers are lazy. Was he joking?
1. Yes, I know it may also break wanted third party software. When I first edited init.c, renamed and moved sh I was seeking to learn about dependencies. I expected things to break. That was the point: an experiment. I wanted to see what would break and what would not.
Even though the POSIX standard says:
> Applications should note that the standard PATH to the shell cannot be assumed to be either /bin/sh or /usr/bin/sh, and should be determined by interrogation of the PATH returned by `getconf PATH`, ensuring that the returned pathname is an absolute pathname and not a shell built-in.
> For example, to determine the location of the standard sh utility:
command −v sh
Wow, +1 Insightful!
However, MalwareTech's sinkhole intervention has bought enough time for patches to be pushed out, so at this point it is absolutely imperative that everyone apply these patches as soon as possible.
Even though this fortunately turned out to be false, what if it had been true? Would the security researcher be held in any way accountable for activating the ransomware? If I were the author, I might be a bit more careful in the future before changing factors in the global environment[1] that have the potential to adversely affect the malware's behavior, but of course I'm not a security researcher, so I really don't know.
[1] I suppose a domain could probably be made to appear unregistered after being registered - depending on the actual check performed - but there are other binary signals (e.g., the existence of a certain address or value in the bitcoin blockchain) that might not be so easy to reverse.
When there's a global infection spreading wildly and crippling essential organizations, you want everyone to act fast, not spend weeks making sure everything is perfect. If you see the malware connecting out to an unregistered domain, you just register it now. Whoever is first gets it, and the attacker could realize their mistake at any time. Even without knowing what this malware does with the connection, odds are 99.9% that the situation is better with the domain controlled by a security researcher than by a malware author. Punishing researchers if something done in good faith turned out badly would incentivize them to overanalyze everything and delay taking any potential beneficial action until it's too late.
So, if connection = successful, then we're being analyzed and don't execute.
If connection = unsuccessful, then we're on a real workstation, execute!
Then the scheme fell apart when someone registered that domain, so all connections = successful and malware will not execute (but machine still infected).
But next they'll likely use more domains, and more expensive ones, so that random security researchers can't just expense the registration on the corporate credit card. I know .ng costs 50k, but .np might be pretty comical to deploy if you're not really worried about a global off switch.
If the motivation is to have a killswitch, you don't want something expensive, because the attackers would then have to pay for it if they want to activate it for whatever reason.
A responsible researcher would have a fully isolated, both from the corp net, and the internet. Then will slowly being to allow connections out as they can confirm that's not how it's spreading...
If you're a bomb enthusiast or researcher, you'd absolutely be liable if you tried to defuse a bomb without being requested to by the police. This is no different because of the potential for massive collateral damage. You want to see what happens when the domain is registered? Resolve the DNS on your own network.
It's only when acting under government direction that you should be immunized from liability.
Why? I 10000% disagree that the Government should be immunized from liability in the first place. This entire mess is a direct result of the NSA not being held accountable and hoarding Vulnerabilities.
Your reliance on government == good, everyone else === bad is alarming to me.
That said, I do not believe neither the government nor a Research should be held liable under the circumstance proposed in the hypothetical we are discussion.
I do believe the NSA should be required by law and policy to alert any and all software vendors to vulnerabilities they discover.
Got all riled up and then saw the username.
Enjoy!
I am curious why you disagree with me, though.
A bit more econo-mathematically stated: we expect more good than bad to come by us if we indemnify them from whatever liability they may have had by accidentally triggering the mechanism. Perhaps because there's more smart people outside the government than inside it, just as there are more smart people outside any corporation than inside it, or anywhere really, because human ingenuity is widely distributed.
Good Samaritan laws only apply to emergency care rendered to people in need of it (and only if they don't refuse). You wouldn't even be covered if you grabbed someone's broken arm and tried to set it without permission. (That would actually be assault, for which you'd be liable.) You definitely wouldn't be covered if you unilaterally released a protein in to the atmosphere because you suspected it would stop the flu. You'd probably get charged with using a WMD if it backfired and people got sick.
I think people who are arguing that it's a good Samaritan situation are simply being selfish, because they don't want to have to consider how their actions might impact others or act with restraint and professionalism.
There are plenty of ways to proceed with getting help from security consultants even if there is liability -- eg, confining their actions to a single network and being indemnified by the owner.
Globally poking a widespread infection without a care in what the infected prefer is emphatically not what Good Samaritan laws are meant to protect and should carry global liability.
Ed: To address the question under me, since I'm "posting too fast" --
My problem is that many of these FBI programs exist in a legal limbo -- the researchers are working with the government, but I'm not sure they have the kinds of immunization agreements that government contractors usually get (eg, that you have to sue the government not the contractor since the actions are taken under government authority because you're working for the government) nor that they have to observe the restrictions placed on government actions. Too much of cyber security exists in these (intentionally) gray areas.
I dislike this Wild West state of affairs and want the matter of liability and restrictions/accountability to be directly addressed, even if it's just making de jure the de facto situation. I think cybersecurity, as currently practiced, is probably ripe for some nasty lawsuits if a researcher screws up a situation like this.
Does anyone believe that if the registering the DNS address had bricked the NHS systems, the NCSC would've taken the fall?
Imagine a person in a locked building with ticking bomb, authorities are nowhere in sight. People, including loved ones, are vulnerable.
Should that person just wait and do nothing for the fear of you, sir, SomeStupidPoint, had created a law that holds that person accountable if something goes wrong?
Its her life and your law doesn't mean a thing, if not downright unethical and tormenting. She has every right to try to defuse or shield the bomb.
Should the IT departments of fortune 500 companies not try to respond and save their assets or should they just wait for Authorities?
You think a ticking time bomb is a crime scene, I think of it as a self-defense situation that hasn't played out completely yet. She has full right to self-defense, successful or not.
Look, ma, words on paper, that must stop bad things from happening right? Ma? Maaaa?
> It's only when acting under government direction that you should be immunized from liability.
I also thought that you meant it as a satire.
Anticipating your next question, can I ask what kind of internet police he should have asked?
I don't think globally releasing changes meant to tweak malware is a good idea, because of jurisdictional issues and liability. Down thread, I suggest confining changes to a network and indemnification from network owners (who may in turn be indemnified by network subscribers).
In practice, this would look like trapping malware DNS queries to security researcher controlled servers at the Comcast network DNS level, rather than registering a global name for it, with the researchers being indemnified by Comcast (who likely is indemnified as part of your subscription agreement).
This has well tread liability law behind it and moves us out of the situation where every random group feels free to potentially cause harm to hundreds of thousands or millions of computers across the globe because they're "good guys" and shoot from the hip.
I expect that network operates would quickly establish industry groups and a certification process for getting researchers to help protect their networks, and we would quickly be back to mostly the same situation, sans questionable legality. (They likely would be liable for occasional collateral damage and pay that out of industry membership dues to the group.)
I think that would be the equivalent of an arsonist also leaving a water activated chemical at the scene of the fire, and then blaming the firemen for using water to put out the fire when it made the situation worse.
From the Talos Intelligence blog:
>The above subroutine attempts an HTTP GET to this domain, and if it fails, continues to carry out the infection. However if it succeeds, the subroutine exits.
It's not clear if the subroutine being shown is the main entry point in which case return 0 exits (which is good for us), or if it's part of a larger framework that would be doing stuff later on (which is potentially bad for everyone because it could decide to do other things if it finds that domain sinkholed?)
The blog author checked on whether or not the domain name changes, but didn't specify any details about anything going on higher in the stack:
>All this code is doing is attempting to connect to the domain we registered and if the connection is not successful it ransoms the system, if it is successful the malware exits (this was not clear to me at first from the screenshot as I lacked the context of what the parent function may be doing with the results).
So my question is how much knowledge did they have of the rest of the code when registering the domain? Would the analysis environment have provided more information if the malware had continue to run after realizing the domain was sinkholed?
Better in the hands of someone like this.
The ransomware prematurely quits if the domain resolves to an IP, and a webserver listens to that IP.
"As of a little while ago (it is around 7:45 PM US Eastern on Mon 15 Sep 2003 as I write this), VeriSign added a wildcard A record to the .COM and .NET TLD DNS zones. The IP address returned is 64.94.110.11, which reverses to sitefinder.verisign.com. What that means in plain English is that most mis-typed domain names that would formerly have resulted in a helpful error message now results in a VeriSign advertising opportunity. For example, if my domain name was 'somecompany.com,' and somebody typed 'soemcompany.com' by mistake, they would get VeriSign's advertising."
I'm not the most diligent follower of security news, but I'm pretty sure that SMB network sharing is riddled with security vulnerabilities, latency issues, etc, and is generally wildly unsuitable for being left wide open to the entire internet. How could any institution with a competent IT department not have had this service firewalled off from the net for years?
1.) What is SMB? And is it easy to remove from systems by simply uninstalling it (like I have done[0])?
2.) Does WannaCry just land on a machine through a simple point-and-click exploit? Do they just enter a vulnerable IP address and they can plant the exploit on the machine and run it?
3.) I am aware that it also gets onto machines by people randomly clicking on shady e-mail attachments, but I am very curious about how it simply lands on computers with very little or no user stupidity at all?
[0] I uninstalled SMB by going to > Add or remove programs > Remove windows features
This exploit worked in two stages. First, there was a massive email campaign. Then, when employees would click on the attachment, the malware would worm its way onto other computers on the local network using an exploit in the SMB file sharing stack (which orignally came from leaked NSA malware). Then it would encrypt the user's files and demand the ransom.
That's quite an high abstraction level programming thing to do to use a domain name registration state as a boolean. Is that a regular thing ?
They could've achieved the same sandbox detection effect by just registering the domain and pointing it at 1.1.1.1 or whatever. The non-sandboxed connections would still fail, and no one else could take the domain.
That would leave a paper trail, potentially revealing who's behind the malware.
* https://mikewest.org/2012/02/chrome-connects-to-three-random...
Each condition is satisfied by a different domain lookup.
The malware could have just as easily used the registration of that domain as a flag to start deleting data, no?
It's probably easier, as you point out, to have the virus delete its keys and wipe itself out. (And has the added benefit of taking some forensic info with it.)
But in a marketing sense, blaming people interfering with your network for the lost data may make you safer, as many victims are likely to prefer you extorting them to the good guys causing data loss by stopping you.
Being a criminal is all about customer service.
Two domains, one defuses the ransomware, the other detonates it.
And one of the domains will be called redwire[randomchars].com, and the other bluewire[randomchars].com. Which one do you sinkhole, the red wire or the blue wire?
The researcher in this case registered the domain right away because he had experience that that creates a positive result. Once that sort of thing starts creating bad results, then researchers will start testing more carefully before grabbing domains.
Although it was only a thought, with what `cesarb` mentioned in mind.
It isn't an either-or proposition, and the psychology of the conflict is important. If you force your opponent consider every possible move to be potentially dangerous, you slow them down by more than just the cost of the game with a domain name. And that's valuable.
Googling for "OODA Loop" might be helpful in thinking about this.
Well, I guess maybe they didn't want things to get too out of hand and now if they want they can be back up soon with that fixed.
And that's exactly what is so wrong about the NSA and others not being good stewards of their own bloody malware. A lot of these criminals would not be able to get their act together at this level without being partially funded by the three letter agencies. Think of it as an advanced form of script kiddies, they can use the tools and wrap them but they could not come up with those tools of their own accord.
They were clever enough to execute this attack, collect over £160k according to the last estimate I've seen (likely way more now), and achieve that in one day. You seem to underestimate them including assumptions that this was simply missed. There are many potential scenarios where this is beneficial to the authors.
This guy is sort of a hero, IMO. Given that this is affecting healthcare systems, he might very well have actually saved a bunch of lives! I hope he slept well, totally deserved it :)
Uh, no. Here's an archived copy:
EDIT: After looking explicitly for it I found www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com.
Despite Jones being the stereotypical name for people in Wales, the old Welsh language, Cymraeg, doesn't have a J, nor have Z, K, V, X (IIRC). Jones is an English loanword, brought over apparently with the Norman conquest (though derived from Hebrew).
The modern language of Wales is of course British English with a ~100% use rate; Cymraeg still has an approx 8% (but falling) of the population who say when surveyed that they can speak it fluently, however.
Yeah, I'm terrible at parties.
- insurance company which provides legal protection
The map is populating much faster now, maybe they integrated it with the URL?
Edit: I'm not so sure now. The whois record seems to suggest recent activity:
Domain Name: GWEA.COM
Registrar: 22NET, INC.
Sponsoring Registrar IANA ID: 1555
Whois Server: whois.22.cn
Referral URL: http://www.22.cn
Name Server: PK3.22.CN
Name Server: PK4.22.CN
Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Updated Date: 18-mar-2017
Creation Date: 17-mar-1999
Expiration Date: 17-mar-2018The hacker, though, didn’t register the gwea.com domain name. On Friday morning, a 22-year-old UK security researcher known online as MalwareTech noticed the address in WannaCry’s code and found that it was still available. “I saw it wasn’t registered and thought, ‘I think I’ll have that,’” he says. He purchased it at NameCheap.com for $10.69, and [...] [1]
If it is, it seems to contradict the whois record.
[1]: http://www.thedailybeast.com/articles/2017/05/12/stolen-nsa-...
> a dot-com address consisting of a long string of gobbledygook letters and numbers ending in “gwea.com”
jstoja mentions it above: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
(A very important point at the bottom of the article)
I was wondering why they didn't just do a simple variant:
1) Instead of relying on DNS, which anyone can create, why not make a user account on some well known forum site. Like HN or Reddit.
2) Open the site, look for the user's page, and check his message titles by hashing them against some hash that can be in your code.
3) Detonate if you don't see the code, or the user account doesn't exist.
This would have the useful characteristic that you could start/stop the attack using just an internet browser, anywhere. And the code word that you are after would be crypto hashed, so the defenders would have to find your keyword somehow from the hash. Heck, you could confound everyone by turning the thing on or off according to location, time of day, and so on.
For extra points make it a blockchain thing. They're already using that for payment, right?
[0] https://www.intego.com/mac-security-blog/iworm-botnet-uses-r...
Several of London’s largest banks are looking to stockpile bitcoins in order to pay off cyber criminals who threaten to bring down their critical IT systems.
https://www.theguardian.com/technology/2016/oct/22/city-bank...
The may be some truth in there, but this is a popular tech post. I'd look for more details than the guardian provides.
Can you provide some references for the positions you have stated in this discussion?
Anyway, regardless of the merits of the strategy, it appears to be an established fact in some cases.
Also btc price is a bit unpredictable. Would you really risk buying it ahead of time, not knowing if you'll ever need it? What if the price goes down and you need to buy extra anyway? Apart from very specific situations it just isn't a great investment.
Then, the onus would once again be on the legitimate ransomware developers to prove their ability to do business, and some sort of Ethereum based automated contract might be an ideal tool for that.
The attacks work on those who didn't have protection and lost valuable data. Just sticking a "decryption guaranteed by Ethereum contract" will likely have the same effect on them.
Create a demand. The wallet wouldn't even ever have to be tapped. $300 is small fry, but an overall inflation on a strongly-leveraged BTC investment could allow an disconnected cashout.
sudo ufw deny out to any port 445
Aswell as this I am not deferring updates in any way and dutifully patching. I've always hardened Windows in this way and I've never had issues with malware, and if I did, the impact would be minimal because I've compartmentalized my files in such a way that even the worst malware would only encrypt some of my files and not all of them.I store all my critical files in an offline environment (sandbox) so the only files that are going to be encrypted are replaceable (non important) and disposable. For example, I wouldn't cry if my C.V got encrypted because a copy of it exists in about 50 locations either offline and online.
Unfortunately I need Windows because my colleagues like to send Windows-only .DOCX files which work best in MS Word, and I don't have a Google account, so I can't open them in Docs. This is a conscious decision to permaban Google from my life, but Windows is staying.
MS collects alot of metrics from your devices, not just G*g.
Not sure I'd be singing his praises if his rash decision had triggered the deletion of the encrypted files.
Use an offline security update.
Is this something VMs do? Does anyone have more info on this?
> Negotiorum gestio (Latin for "management of business") is a form of spontaneous voluntary agency in which an intervenor or intermeddler, the gestor, acts on behalf and for the benefit of a principal (dominus negotii), but without the latter's prior consent. The gestor is only entitled to reimbursement for expenses and not to remuneration, the underlying principle being that negotiorum gestio is intended as an act of generosity and friendship and not to allow the gestor to profit from his intermeddling. This form of intervention is classified as a quasi-contract and found in civil-law jurisdictions and in mixed systems (e.g. Scots, South African, and Philippine laws).
> For example, while you are traveling abroad, a typhoon hits your home town and the roofing of your house is in danger. To avoid the catastrophic situation, your neighbour does something urgently necessary. You are the 'principal' and your neighbour here is the 'gestor', the act of which saved your house is the negotiorum gestio.
The summary gives the example of securing your neighbors roof when a tornado is about to hit. Possible laws to break to do this, are "breaking and entering" or "trespassing".
Note that a lot of these laws state that care must be taken not to break laws unnecessarily. Bricking IOT devices that can be used for DDOS-attacks may be a step too far.
And strictly, in the case of patching a server under negotiorum gestio, you have not broken any laws: It is not unlawful computer intrusion when you have implicit permission of the owner of a device (the same goes for entering your neighbors house when they are on vacation, and have accidentally left a pot of milk to boil on the stove).
But I guess such far-reaching Good Samaritan laws are very foreign to the US, since there, off-duty doctors are sued for performing a painful Heimlich maneuver.
For programmers it's important to be able to - but when you're not coding, running any executable is not required.
It should be that all programs are in /usr/bin & the others. Only root can write there. Users shouldn't be able to run any program that is located anywhere else.
And this would be no problem. Am I wrong?
We already put multiple warning messages when a user decides to execute a suspicious binary, and yet everyone still clicks through any prompt without the second thought ?
What's your suggestion that a). allows any user to have the machine installed and configured as he wants? and b). do not allow random programs from executing ?
Can someone please explain this? I have no idea what was said there.
I know that this sort of data can be valuable - what browser I use, which plugins are there - but I just assumed everyone was doing this in negligible time frames. What more is there to check in a browser?
This story, if true, details a person who profiled this malware and correctly logged the network requests it was making and then correctly identified a fundamental vulnerability in the software. This is not an accident at all - it is rather a profile in supreme competence. We should recognize it as such.
The author registered the domain name without knowing what would happen (the virus might as well have wiped the entire disk) and was surprised to see that he had activated a kill switch. That's the accidental part.
NSA can be held accountable for not disclosing a vulnerability responsibly but this exploit may have been found anyway by the creators of this ransomware. There is no one person/group/institution to blame here. It's multiple vectors that failed. Are there any reports that connect deaths of patients directly to this ransomware attack?
Found it www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
I also wonder if now ransomware developers will leave red-herrings in the code where if the wrong domain is registered, it will do something more destructive.
It's like knowing which wire to cut when you're defusing a bomb!