WanaCrypt0r Ransomworm
baesystemsai.blogspot.com
baesystemsai.blogspot.com
I think this is an important take-away. I found it strange that so many media outlets and IT departments were jumping on the "do not open suspicious emails" bandwagon even although there hasn't been a lot of evidence of such phishing emails. That is: screenshots of infected devices have been popping up all across the world, but almost no examples of a particular entry email have been shown.
Of course, it might be easier for an IT dep. to state: "it must have been unleashed by someone clicking on some email they got" rather than "oops, we still had unpatched Windows machines exposed to the public internet". Why go through the trouble of sending out emails when your worm already contains a replication/infection mechanism. Just use a botnet to scan those 1 million IPs and see if SMB is open.
That being said, it does not surprise me to see yet again an issue in SMB. This has been a particularly weak point in Windows for decades now. I remember "hacking tutorials" from 15 years ago where you'd just go out and nmap public IP ranges to see if you could access hidden shares (e.g. like so: http://www.madirish.net/59). Also there was this issue of Windows keeping weak NetBIOS password hashes around which could be trivially unhashed (https://vuldb.com/?id.13824), years ago.
It's not like 'stop clicking random shit in emails' is bad advice.
Yes, it would help - but do you see fewer people clicking random shit? Me neither: "Ugg click attachment for dancing hampsters, now Ugg virus, halp!" is still the prevalent vector, two decades later.
It's a friggin email and data transfer for crying out loud.
Stop blaming users.
Being aware that both are high risk activities is the point, methinks.
PDF/Office macros are a whole other topic though.
Funny how that works. You want all the power but none of the responsibility. This is like saying "Why can't I drink bleach, stop criticizing me doctors!"
>It's a friggin email and data transfer
and guns are just tubes which throw lead around, but I certainly don't want to be on the receiving end of one. What's your point? Its incredible to me how many people refuse to believe we live in a world of risk when it comes to information technology and its not all fun and games.
So, the big mistake was to use a real world analog in naming e-mail. We should have called it:
"Russian roulette with packages* anonymously tossed by strangers in your direction".
The analogy is broken and creates cognitive dissonance in users.
* Re: data vs. executable: the analogy could be for letter vs. package. A box is big enough to contain a mechanism for action unlike most letters.
(Apologies to the Russians for that idiom.)
However, I see some hope in https://www.qubes-os.org/ - alas, setting it up is not quite as convenient as "meh, open everything everywhere to everyone."
I guess they want to make sure the decryption process will work without any issue so that the victim will be more likely to pay other ransoms or spread word of mouth that it does actually work.
I wish all software devs were as thorough as these people...
1. New address per machine (easier to detect payments made, hides profit total.)
2. Deterministic wallet stores all profit in a simple 12 word seed "password."
3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.)
4. Phone number to tech support company that bills your credit card to walk you through paying the ransom.
5. Delayed symptoms. Secretly encrypt backups (windows efs might be able to do it nonobviously) Then once all your backups are secretly encrypted, it encrypts the key, and now you can't use backups to save yourself.
6. Advertise affiliated antivirus (I hear this is what cloudflare does by hosting bad actors, they inflate their demand from protection from bad actors, just a rumor though.)
7. Infect a friend. Get a discount on your ransom if you infect a friend and they pay.
It doesn't seem reasonable that 300k infections= less than 1 in 1000 payments. Are peoples files really so worthless, or bitcoin really so hard, or people so untrusting of unencrypt. I imagine they could have sold their 0 day idea for more money to a whitehat perhaps? Maybe more generalized bug bounties could be deployed to offer financial incentive to harden systems and be non evil.
I sometimes fix friends & older family members computers as a favor and I've noticed that they usually don't really have any files anyway. I always make a backup before reformatting them and usually it includes their bookmarks and maybe 2-3 random files scattered in their 'Documents' folder, none of which are important. Their machines are more like just gateways to the internet than anything.
Through machines moves over the years I'm sure I have multiple copies of the most important ones anyway (keys, etc). If not oh well, life goes on. Shoulda made backups in the first place if they were that important to me.
I've been in the same boat and how absolutely right you are. Generally everything they do online is tied to their webmail-based, ISP-supplied email address too, making for a total nightmare when they want/need to change ISP.
I can't 100% say I would, but maybe.
I think that is super small subset. Average people use a ton of cloud software nowadays: google docs, dropbox etc. Let alone use a desktop for anything besides work. The files they super care about (photos) are usually on their device or scattered all over facebook. Work files/computers, well they don't care about, that is some IT's guys job.
So the probability to get paid = [their ability to get bit coin] * [inability to have it already backed up] * [value of file[s]]. That does seem like a high bar. I also don't see an IT guy convincing a corporate attorney / accountant that wiring money to obtain bitcoin as an easy feat.
You don't want the seed distributed to all victims. There is risk it will be reverse engineered.
There is a way to ge
This is great lol
"As noted in our attribution post last year, use of Visual Studio 6.0 is not a significant observation on its own – however, this development environment dates from 1998 and is rarely used by malware coders. Nonetheless, it has been seen repeatedly with Lazarus attacks."
True Visual Studio was really great. And like many, one had a VS6 and VB6 install still around. Even if VS6 C++ is really outdated nowadays, it doesn't contain this spy-home feature that shipper with VS 2015 and VCredist 2015 (RTM, patch 1, patch 2). Back in the 1990s MS was a good company.
Umm, isn't that precisely the period when they were charged with antitrust violations? Such a short memory we have.
Also, their antitrust violations was due to the Windows OS and anti-competitive behaviours, if i'm not mistaken? If so, then this is not really relevant to their software or OP's post, but more their business approach of locking out competition, which is a question of legality and economics.
It really wasn't.
15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361
Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.
https://www.trustar.co/wp-content/uploads/2017/05/WannaCryVe...
http://thehackernews.com/2015/10/cryptowall-ransomware.html
That averages out at $800 per infection compared to about $0.30 per infection from WannaCry. I suspect there are other factors at play here (was all the revenue from ransoms? were that target systems different? are people hardening in their resolve not to pay these ransoms?).
They could have already moved a part of the coins to an exchange.
Is it the job of NSA and all the global security services with their overarching reach, resources and power to warn, track and disable these activities or is to spy on citizens?
Half or more of these activities are used by agencies to shut down or sabotage unfriendly interests and I suspect that's the only reason these shady figures are allowed to exist, treated with kid gloves, operate with near impunity and rarely see consequences. They serve as 'assets' to provide cover. Without consequences these activities will spiral.
Things like ddos ultimately benefit companies like cloudflare. And the preponderance of these kind of worms force people to move their data to the cloud or give up more control to large companies who promise security. This is a subtle form of extortion. We don't know the extortionists but we do know the beneficiaries.
This slowly but surely disempowers individuals and takes control away and shifts it to large companies.
Holding a hospital ransom whatever its security policies is a serious crime and treating it as just another hack rather than extreme criminality and blaming the victims is an extremely self serving technical perspective.
It's a very classic and widespread law enforcement problem: They catch those who are easiest to catch. There's an anecdote that so beautifully displays this fallacy.
A police officer sees a drunken man intently searching the ground near a lamppost and asks him the goal of his quest. The inebriate replies that he is looking for his car keys, and the officer helps for a few minutes without success then he asks whether the man is certain that he dropped the keys near the lamppost.
“No,” is the reply, “I lost the keys somewhere across the street.” “Why look here?” asks the surprised and irritated officer. “The light is much better here,” the intoxicated man responds with aplomb.
Isn't it curious that people who are known to the authorities are arrested, whereas persons unknown are not? That's your question?
Is this site legitimate?
Would it be easy to find it if the initial attack vector uses some semi-obscure torrent? Would people find out quickly?
Anyway, how is the difference significant?
A localhost cache can point at a custom root.zone. The user can make her own authoritative nameserver assignments for any given zone or domain. Zone files can contain wildcards.
Responses can also be rewritten on the fly.
The end user can exercise full control over what is and is not a "valid" domain name. She can prevent her applications from ever receiving an "NXDOMAIN" response.
Maybe I am missing something but this "test" seems brittle; it only tests ICANN DNS.
I hope many people have understood to not have public windows servers at least. It could most probably affect their business in the long run (Not saying that GNU/Linux is safe. But it is safer).