Live data from Hacker News

WannaCry – New Variants Detected

blog.comae.io

31–40 of 164 posts

Re: WannaCry – New Variants Detected

#31
post #9

Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.

Do you seriously expect criminals are dumb enough to leave any useful information there?

Remember the guy which created Silk Road. People talked about him in mythical terms, that he probably has the op-sec of God, but afterwards facts pointed to major mistakes, like connecting identities to his real name, and suddenly everybody was like "how can he be so stupid, doing this while being the owner of a $100 mil criminal empire"

Re: WannaCry – New Variants Detected

#32
post #23
post #11

Earlier quoted context omitted.

They never would. It's just a naive test to see if the software is running in a VM. Researchers usually resolve all DNS queries inside their test VMs.

How do you mean? Is the malware detecting its in a VM?

And why would they not then use randomly generated domain names, instead of hardcoding domains that could be registered?

Re: WannaCry – New Variants Detected

#33
post #13
post #4

Earlier quoted context omitted.

From what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a mass phishing campaign. See: https://arstechnica.com/security/2017/05/an-nsa-derived-rans...

The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.

Why isn't the internet alive with the email subject line then? The email would be multi-lingual too?

Re: WannaCry – New Variants Detected

#34

Earlier quoted context omitted.

Do you seriously expect most criminals are intelligent?

In this context criminals are a person or persons who have created ransomware which, in less than three days has infecting more than 230,000 computers in 150 countries, demanding ransom payments in bitcoin in 28 languages. The meth dealer two houses down who serves people out his front window probably isn't thinking straight. What we're dealing with here is a different category of thinking.

The ransom note in 28 languages can be very well taken from other ransomware pieces, just like the ransomware code itself.

It's not like someone will sue for copyright infringement.

Re: WannaCry – New Variants Detected

#35
post #23
post #11

Earlier quoted context omitted.

They never would. It's just a naive test to see if the software is running in a VM. Researchers usually resolve all DNS queries inside their test VMs.

How do you mean? Is the malware detecting its in a VM?

Exactly.

Based on what I understand, those that test malware do it in a VM logging and redirecting all queries to external domains, in order to identify possible command and control hosts.

As a response, malware writers add checks for nonexistent domains. If, say, 5 domains known to be fake suddenly start replying, then the malware assumes that it's being executed inside a VM and stops doing anything, in order not to give researchers any clues. This malware just happened to check a single domain.

Re: WannaCry – New Variants Detected

#36
post #31
post #9

Earlier quoted context omitted.

Do you seriously expect criminals are dumb enough to leave any useful information there?

Remember the guy which created Silk Road. People talked about him in mythical terms, that he probably has the op-sec of God, but afterwards facts pointed to major mistakes, like connecting identities to his real name, and suddenly everybody was like "how can he be so stupid, doing this while being the owner of a $100 mil criminal empire"

Yet as far as I remember he leaked his identify long before anyone even knew Silk Road is even a thing. And someone behind this botnet certainly knew what scale it's going to have before they started it.

Re: WannaCry – New Variants Detected

#37
post #23

Earlier quoted context omitted.

How do you mean? Is the malware detecting its in a VM?

Exactly. Based on what I understand, those that test malware do it in a VM logging and redirecting all queries to external domains, in order to identify possible command and control hosts. As a response, malware writers add checks for nonexistent domains. If, say, 5 domains known to be fake suddenly start replying, then the malware assumes that it's being executed inside a VM and stops doing anything, in order not to…

Oh right, I was under the impression it checked the domains as a kill switch, not as a VM check? I.e if this domain is up and responding don't do anything.

As I could easily run it in a VM and not redirect any traffic

Re: WannaCry – New Variants Detected

#38
post #16

These systems would be better of security wise if they would use the latest open source operating system including the embedded code. The damage this will cause to embedded systems is distasteful.

AIUI they would have been better off if they'd used the latest of any operating system.

Re: WannaCry – New Variants Detected

#40
post #36
post #31

Earlier quoted context omitted.

Remember the guy which created Silk Road. People talked about him in mythical terms, that he probably has the op-sec of God, but afterwards facts pointed to major mistakes, like connecting identities to his real name, and suddenly everybody was like "how can he be so stupid, doing this while being the owner of a $100 mil criminal empire"

Yet as far as I remember he leaked his identify long before anyone even knew Silk Road is even a thing. And someone behind this botnet certainly knew what scale it's going to have before they started it.

In my view that's even more damning. Continuing while knowing that you made basic mistakes in the beginning.
Post reply on HN