WannaCry – New Variants Detected
blog.comae.io
blog.comae.io
It would be simple to rename this link (or perform a referer check or something else to stop automated downloads), at least temporarily.
Yes, the malware authors will release an update with the different URL (or another hosting site entirely, or embedded), but at least it would provide time for vulnerable users to install patches. Especially now that Microsoft has released a patch for XP.
(I'm basing this URL info on the breakdown found at https://www.bleepingcomputer.com/news/security/wannacry-wana...)
So why now? What's so special now?
Did they just manage to craft so really persuasive emails this time?
This is incorrect or at least misleading.
Any machine still running Windows XP, is by any reasonable definition, an "old Windows machine." Windows XP was first released in 2001, and actively supported with updates for 12 years. Windows XP hasn't been supported with critical security patches for over 3 years.
Windows Server 2012 is under active support until Oct. 10, 2023, and was patched against this vulnerability in MS17-010. See the middle of the page here: https://technet.microsoft.com/en-us/library/security/ms17-01... If your Windows Server 2012 machine fell victim to this ransomware, it was for the same reason as those running the newer Windows Server 2016 (also vulnerable to WannaCry): because someone didn't apply security patches in a timely manner.
This ransomware was particularly damaging because of it's unusually wormable nature. (Ring 0, commonly enabled networking protocol, no user interaction required.)
I replied to your comment because the "old" Windows XP having no patch available was significant here, and I read your comment as saying "old" windows versions were not proportionally more responsible for WannaCry's rapid spread.
Windows XP is still the third largest version of Windows by current installed base (after Windows 10 and Windows 7).
The fact that Windows XP remained unpatched was significant, as there is notable overlap between Windows machines that aren't getting new security updates (at least within a month or two of their release) and Windows machines still running Windows XP.
This vulnerability was, in fact, unusually dangerous, relative to other Windows XP vulnerabilities that have come to light in the last 5 years, and the install base of the "older" Windows XP machines made a big difference in the ransomware's ability to spread.
I addressed that it wasn't "old" Windows because there is a crazy belief out there that this only hit XP.
Can you elaborate on this?
This worm targets older Windows versions that are installed (and use the exploited protocol) in a lot of critical infrastructure, and the worm was hoarded by the NSA all packaged up and ready to deploy (because it can propagate through SMB and therefore would be perfect for a future Stuxnet-like operation). So of course some criminals get their hands on it, and hey look it works. It's an absolutely bonkers story.
Win 10 is vulnerable without the patch that came out in march.
Edit: I'm dumb, misread the above comment as saying "Win10 was affected even with the patch in March."
Microsoft clearly disputes this in their own posts on the subject.
https://blogs.technet.microsoft.com/msrc/2017/05/12/customer...
"Customers running Windows 10 were not targeted by the attack today."
What's your source?
"Customers who are running supported versions of the operating system (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012, Windows 10, Windows Server 2012 R2, Windows Server 2016) will have received the security update MS17-010 in March. If customers have automatic updates enabled or have installed the update, they are protected. For other customers, we encourage them to install the update as soon as possible."
If you don't have the update, you are not protected, you are vulnerable.
Laws must be passed to:
* Force the US government to report vulnerabilities to vendors
* Create a regulatory body to monitor the use of vulnerabilities in clandestine operations and ensure that mandatory reporting is upheld
I cannot see anything less working.
Get that through US and EU governments, and you'll likely have the vast majority of vulnerabilities being reported and patched.
Of course this is akin to asking the US and Russia to convert their nuclear stockpile into reactor fuel.
Nobody seems to be talking about this, but we can only guess that a lot of stuff has been compromised and still is.
What really worries me is the huge amount of non-patched computers that have not fallen with this specific WannaCry issue and are sitting idly waiting for their glory day.
I think it's because it's cool to use the word "cyber" now in the news. It makes news outlets appear edgy and with it. Infact these cyber attacks are nothing new, and have been an ongoing problem for organizations like the NHS, the only difference being there is a remarkable uptick in the scale of the attack. The reason it stands out is because it's a cluster, instead of a slow, trickling problem for the NHS and other organizations.
> What's so special now?
The sophistication and worm capabilities. Were it not for the Shadowbrokers leak, small time malware authors had to use tired old strains of malware to spread. Now they can draw upon the vast arsenal of the Shadowbrokers leak and appear like state actors, which they are not.
If anything, the leaks were a blessing, because now we can mitigate against such attacks. NSA's mantra 'NOBUS' (No-one-but-us) does not apply here.
Or a domain in a TLD that allows only second level TLDs (such as some of the commonwealth countries).
Yep, that's the way to do it.
And is superior to hardcoding.
The domain check is there to detect whether the infection is running in a sandbox environment. If the domain check succeeds, it assumes it's being analyzed and aborts.
Or at least that's the prevailing theory.
<quote> In certain sandbox environments traffic is intercepted by replying to all URL lookups with an IP address belonging to the sandbox rather than the real IP address the URL points to, a side effect of this is if an unregistered domain is queried it will respond as it it were registered (which should never happen).
I believe they were trying to query an intentionally unregistered domain which would appear registered in certain sandbox environments, then once they see the domain responding, they know they’re in a sandbox the malware exits to prevent further analysis. This technique isn’t unprecedented and is actually used by the Necurs trojan (they will query 5 totally random domains and if they all return the same IP, it will exit); however, because WannaCrypt used a single hardcoded domain, my registration of it caused all infections globally to believe they were inside a sandbox and exit... thus we initially unintentionally prevented the spread and further ransoming of computers infected with this malware. Of course now that we are aware of this, we will continue to host the domain to prevent any further infections from this sample. </quote>
On the face of it, that sounds like amateur hour. At the end of the day virtual environments can be configured to fool the malware in whatever fashion is required.
However, I can see that method buying small amounts of time for the worm to continue infecting targets, which I suppose has utility.
It is not a ransomware operation but a counter-intel ooeration against security researchers.
This is starting to look dumb now, maybe researchers will let their guard down and blog even more about internal procedures?
Or maybe there is a hidden payload (Just a crazy idea based on the ovservation that there are multiple versions with corrupted payloads)
Uploaded to virustotal MEANS found in the wild. That's what admins do when they discover things.
Considering you're using a vulnerability to forcefully inoculate systems, and you gained admin if not Ring0 privileges, you could trivially "reboot" the box by just crashing it, no APIs required. You could even be nice and check if there are applications with open files, or schedule it only when the user has been idle for a while, and only do it during the usual hours of inactivity (Windows 10 even has a control panel section to choose them).
Or, you could just open a dialog box, masquerade as a legitimate update and ask for user consent. You are an important security update after all, just a fairly unconventional one.
shutdown -f -r -t 60
force reboot in 60 seconds. A very well documented windows command available for more than 15 years.Bonus: Also works remotely, there is a flag to give a remote computer name.
"but I meant good "is totally going to save you then.
In the case of WannaCrypt0r, the vulnerability had already been fixed by Microsoft but those who were hit hadn't patched because as discussed elsewhere applying patches may break things so some postpone or ignore it. Same thing could have happened to a system running Linux.
1. A doctor opens an email on an office computer. Infection entrypoint from the internet.
2. The office computer worms it to a patient record server.
3. The patient record computer worms it to an MRI tech computer.
4. The tech computer worms it to the MRI itself. (If it's even hitting MRIs and not just tech computers.)
Each of the machines has a reason it needs to share files/data with the two layers it connects to, and there's no "bad" direct link. The worm exploited the filesharing mechanism.
A high security situation would probably implement a one-way upload from the MRI subsystem (machine + tech computer), but c'mon, lots of us work on networks with filesharing zigzags to penetrate deep in to them.
See: https://arstechnica.com/security/2017/05/an-nsa-derived-rans...
Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.
http://researchcenter.paloaltonetworks.com/2017/05/palo-alto...
It continues to be a very common attack method and I'd be surprised if it wasn't leveraged again.
If so, you wouldn't need a very high phish:total infected hosts ratio to explain the numbers. And given that whoever was originally phished didn't know it was an illegitimate email... not betting we'll see many examples of the initial vector.
The original authors first released it with their own bitcoin address. It then spreads p2p around the world wherever it can to front-facing PCs.
Then 3rd-party spearfishers are sending it to corporate networks with their own bitcoin address so they can get the credit for getting past/through firewalls.
If someone was really clever they could change the Tor addresses it talks to for command & control and write their own complete replacement backend, but at that point it seems like you'd be looking at people capable enough to just write their own malware from scratch anyway...
Some level of trust would be involved.
I think the spearfishing industry and the malware writing industry aren't one and the same. The former is the marketing department, the latter is the tech department.
If this attack occurred against, for example, the CN government, they may step in and force miners to invalidate.
This scale is world-wide, there's no loss of public image and the amount of BTC is very small in the scheme of things.
That's just what I heard, but it makes sense. There are far more sane ways to implement a kill switch without using unregistered domains. (For instance, using a registered domain.)
From the sounds of it, it seems like the researchers didn't expect the killswitch to disable the malware outside of the sandbox any more than the author of the malware did[0].
[0]: https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
https://motherboard.vice.com/en_us/article/round-two-wannacr...
Reminds me of the Archer episode where Cyril plants the computer virus and was going to be the hero by "fixing" it.
No, by design that's not allowed as part of the protocol for bitcoin. Every transaction must be signed by the private key for that address in order to be valid. You could in theory do it if you can get a majority of the miners to agree to the change in the protocol but it wouldn't happen since it'd require forking the whole blockchain to insert new transactions without the private key. And then you'd have to get everyone to agree on where those would go.
Is it possible that multiple variants with randomly-generated kill-switches are being automatically generated?
Is it possible instead of patching the OS, to release a patch which patches the malware binary to no-op the payment switch?
These people are going down . No doubt about it.
Definitely, would not like to be them.
Of course, if you were a nation state and you wanted to attack an adversary but you knew that if you did you would get blowback, you might "lose" some tools that you knew some script kiddies would be able to weaponize.
Interesting times indeed.
The sweet spot for an attack is welll below the level where you wake up national LE, especially in such a public way.
Remember when LulzSec was hacking everything in sight with daily press coverage. If I remember correctly all but one were arrested in under 1 year.
The reason is there is no good press to be gotten by announcing they caught these people...all that does is draw attention to the fact they were breached/bamboozled/whatever in the first place. In their eyes, this story and any public interest cannot die quickly enough.
Seriously, this cat's already out of the ba. There's nothing to be gained by trying to bury it, and making the consequences clear might reduce the likelihood of a repeat.
Nobody is smart at everything 100% of the time.
The meth dealer two houses down who serves people out his front window probably isn't thinking straight. What we're dealing with here is a different category of thinking.
It's not like someone will sue for copyright infringement.
https://www.reddit.com/r/Bitcoin/comments/6axuzs/wannacry_wc...
Was it ever released how they found and imaged his server though?
Based on what I understand, those that test malware do it in a VM logging and redirecting all queries to external domains, in order to identify possible command and control hosts.
As a response, malware writers add checks for nonexistent domains. If, say, 5 domains known to be fake suddenly start replying, then the malware assumes that it's being executed inside a VM and stops doing anything, in order not to give researchers any clues. This malware just happened to check a single domain.
As I could easily run it in a VM and not redirect any traffic
https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
Does someone have more info on this? I didn't know VMs do this?