Based on what I understand, those that test malware do it in a VM logging and redirecting all queries to external domains, in order to identify possible command and control hosts.
As a response, malware writers add checks for nonexistent domains. If, say, 5 domains known to be fake suddenly start replying, then the malware assumes that it's being executed inside a VM and stops doing anything, in order not to give researchers any clues. This malware just happened to check a single domain.
As I could easily run it in a VM and not redirect any traffic
https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
Does someone have more info on this? I didn't know VMs do this?
Nobody is smart at everything 100% of the time.
The meth dealer two houses down who serves people out his front window probably isn't thinking straight. What we're dealing with here is a different category of thinking.
It's not like someone will sue for copyright infringement.
https://www.reddit.com/r/Bitcoin/comments/6axuzs/wannacry_wc...
Was it ever released how they found and imaged his server though?