Live data from Hacker News

WannaCry – New Variants Detected

blog.comae.io

21–30 of 164 posts

Re: WannaCry – New Variants Detected

#22
post #13
post #4

Earlier quoted context omitted.

From what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a mass phishing campaign. See: https://arstechnica.com/security/2017/05/an-nsa-derived-rans...

The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.

> The initial attack vector is via an email attachment.

So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.

Re: WannaCry – New Variants Detected

#23
post #11

Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.

They never would. It's just a naive test to see if the software is running in a VM. Researchers usually resolve all DNS queries inside their test VMs.

How do you mean? Is the malware detecting its in a VM?

Re: WannaCry – New Variants Detected

#24

Just wait until this hits the files of a Russian mob who then take some Americans hostage and fly to China and end up entangled in an islamic terrorist plot. 'Cause then we're in for a very long and drawn out story involving MI6, the CIA, Canadian smuggling routes, and Christian Isolationist 2nd Amendment fanatics.

Could I purchase the movie rights to that? Could seriously make a good mini-series if done seriously. Ala John Le Carré.

Re: WannaCry – New Variants Detected

#25

Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.

It's very likely the attackers themselves are surprised by the magnitude of this.

The sweet spot for an attack is welll below the level where you wake up national LE, especially in such a public way.

Remember when LulzSec was hacking everything in sight with daily press coverage. If I remember correctly all but one were arrested in under 1 year.

Re: WannaCry – New Variants Detected

#27

Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.

This is what happens when spambot skiddies accidentally acquire a treasure-trove of NSA tools via a C2 server they have pwned. They failed to sell ('broker') them as nobody was stupid enough to touch them, they failed to blackmail with them (omg what a bad move), then they failed to weaponise their own gear with them (wcry 1.0 in February), and even though wcry 2.0 is widespread and very disruptive, really they faile…

A bunch of articles, even Snowden, argued that it's very likely that the NSA tools were stolen by the Russians.

https://twitter.com/Snowden/status/765514891813945344

Re: WannaCry – New Variants Detected

#28

Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.

Just from my limited experience of "being alive in the USA for 30-something odd years".. I don't think anyone is hard at work trying to get anyone. If you actually ever get the attention of the NSA/CIA - you don't get "caught" or ever make it to the news(except in gaffe's like snowden/assange, we weren't supposed to find out about them). They want us to forget about you, while you either rot in a dungeon(forever) or are already buried in a shallow unmarked grave.

The reason is there is no good press to be gotten by announcing they caught these people...all that does is draw attention to the fact they were breached/bamboozled/whatever in the first place. In their eyes, this story and any public interest cannot die quickly enough.

Re: WannaCry – New Variants Detected

#29
post #16

These systems would be better of security wise if they would use the latest open source operating system including the embedded code. The damage this will cause to embedded systems is distasteful.

I'm am very much in favor of open source always but let's not pretend that embedded systems don't end up with out of date software just because it's open source.

In the case of WannaCrypt0r, the vulnerability had already been fixed by Microsoft but those who were hit hadn't patched because as discussed elsewhere applying patches may break things so some postpone or ignore it. Same thing could have happened to a system running Linux.

Re: WannaCry – New Variants Detected

#30
post #9

Earlier quoted context omitted.

Do you seriously expect criminals are dumb enough to leave any useful information there?

Do you seriously expect most criminals are intelligent?

In this context criminals are a person or persons who have created ransomware which, in less than three days has infecting more than 230,000 computers in 150 countries, demanding ransom payments in bitcoin in 28 languages.

The meth dealer two houses down who serves people out his front window probably isn't thinking straight. What we're dealing with here is a different category of thinking.

Post reply on HN