First Node.js-Based Ransomware: Nodera
blogs.quickheal.com
blogs.quickheal.com
The article mentions the ransom message with the date March 1 2018. This probably means this malware is two years old?
> ...
> Hard code destruction time of Private Key “March 1 2018”.
Quite possibly. I'm not sure what that language means and they don't provide more analysis of the HTML page that comes from. If it's in development maybe some dude has been sitting on this idea for a few years and their virus scanner just picked it up recently.
https://news.ycombinator.com/item?id=21765389
> There's a problem with the Wayback Machine in specific which can kill your ability to access it quite silently, unless you know how to use the browser's development tools and interpret headers.
> It has to do with cookies: Somehow, the Wayback Machine sets cookies... and sets cookies... and keeps setting cookies, until it overflows its own ability to accept cookies. At that point, your browser tries to access a Wayback Machine page, handing the server all of the cookies it currently has, and the server refuses to deal. It absolutely denies everything, sending an error header and a blank page. You have to clear all web.archive.org cookies to get anything at all, at which point it works perfectly.
> I've completely solved this problem by blacklisting web.archive.org in browser cookie blacklists. I haven't had it happen since then. As far as I'm concerned, the problem is diagnosed and just needs to be solved. At their end.
Edit: I'm also not able to find any other record of it (yet). Everything links to the OP link or analysis on the OP link.
Does someone know a good article from the POV of the maintainer of a packaging system ecosystem that describes the tradeoffs made by different approaches over the past ~30 years?
Oddly enough, that's what it is. It even drops a full 17MB copy of nodejs to run it and just renames the executable.
If you have a million computers mining for you, and you're not paying their electricity, it doesn't really matter how individually efficient they are.
Edit: See https://blog.golang.org/versioning-proposal and related articles at the bottom.
password hackernews. I've set it to the maximum option of 100 downloads so it won't last forerver but should last long enough.
Why is this even possible?
> Why is this even possible?
Well they said "on execution" so that's what made it possible. Now if it could install to that location without being explicitly executed (say on download or via a browser bug) then THAT would be a much bigger deal.