Live data from Hacker News

WannaCry – New Variants Detected

blog.comae.io

11–20 of 164 posts

Re: WannaCry – New Variants Detected

#11

Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.

They never would. It's just a naive test to see if the software is running in a VM. Researchers usually resolve all DNS queries inside their test VMs.

Re: WannaCry – New Variants Detected

#12
post #9

Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.

Do you seriously expect criminals are dumb enough to leave any useful information there?

You'd be very surprised at how dumb criminals can be.

Nobody is smart at everything 100% of the time.

Re: WannaCry – New Variants Detected

#13
post #4

How does 'Patient A' get wcry2? Phishing? Via internet facing open 445/3389?

From what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a mass phishing campaign. See: https://arstechnica.com/security/2017/05/an-nsa-derived-rans...

The initial attack vector is via an email attachment.

Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.

Re: WannaCry – New Variants Detected

#15

Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.

This is what happens when spambot skiddies accidentally acquire a treasure-trove of NSA tools via a C2 server they have pwned. They failed to sell ('broker') them as nobody was stupid enough to touch them, they failed to blackmail with them (omg what a bad move), then they failed to weaponise their own gear with them (wcry 1.0 in February), and even though wcry 2.0 is widespread and very disruptive, really they failed again only making 50k out of how many infections? They have only 3 bitcoin addresses making it obvious nobody is getting decrypted (how do they know who has paid?) or there is a single master key which will be found soon, their sandbox detector is a killswitch. Larry, Moh and Curly have invited a world of pain upon themselves - as well as probably killing people on NHS - they also infected Moscow Police - so FSB too.

Definitely, would not like to be them.

Re: WannaCry – New Variants Detected

#16
These systems would be better of security wise if they would use the latest open source operating system including the embedded code. The damage this will cause to embedded systems is distasteful.

Re: WannaCry – New Variants Detected

#17
Just wait until this hits the files of a Russian mob who then take some Americans hostage and fly to China and end up entangled in an islamic terrorist plot. 'Cause then we're in for a very long and drawn out story involving MI6, the CIA, Canadian smuggling routes, and Christian Isolationist 2nd Amendment fanatics.

Re: WannaCry – New Variants Detected

#18
post #9

Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.

Do you seriously expect criminals are dumb enough to leave any useful information there?

Do you seriously expect most criminals are intelligent?

Re: WannaCry – New Variants Detected

#19
post #7

Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.

I think you vastly overstate this. While I can't speak to GHCQ, I really don't think NSA has a charter to pursue justice. The FBI may be, but I'm just not convinced they will move quick enough to matter (they do move, but only against a large established organization).

I'd be surprised if the NSA were just sitting back watching their code fly around the internet.

Re: WannaCry – New Variants Detected

#20

Just wait until this hits the files of a Russian mob who then take some Americans hostage and fly to China and end up entangled in an islamic terrorist plot. 'Cause then we're in for a very long and drawn out story involving MI6, the CIA, Canadian smuggling routes, and Christian Isolationist 2nd Amendment fanatics.

Psst, downvoters - https://en.wikipedia.org/wiki/Reamde
Post reply on HN