Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.
Do you seriously expect criminals are dumb enough to leave any useful information there?
WannaCry – New Variants Detected
31–40 of 164 posts
Re: WannaCry – New Variants Detected
#32Earlier quoted context omitted.
They never would. It's just a naive test to see if the software is running in a VM. Researchers usually resolve all DNS queries inside their test VMs.
How do you mean? Is the malware detecting its in a VM?
Re: WannaCry – New Variants Detected
#33Earlier quoted context omitted.
From what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a mass phishing campaign. See: https://arstechnica.com/security/2017/05/an-nsa-derived-rans...
The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
Re: WannaCry – New Variants Detected
#34Earlier quoted context omitted.
Do you seriously expect most criminals are intelligent?
In this context criminals are a person or persons who have created ransomware which, in less than three days has infecting more than 230,000 computers in 150 countries, demanding ransom payments in bitcoin in 28 languages. The meth dealer two houses down who serves people out his front window probably isn't thinking straight. What we're dealing with here is a different category of thinking.
It's not like someone will sue for copyright infringement.
Re: WannaCry – New Variants Detected
#35Earlier quoted context omitted.
They never would. It's just a naive test to see if the software is running in a VM. Researchers usually resolve all DNS queries inside their test VMs.
How do you mean? Is the malware detecting its in a VM?
Based on what I understand, those that test malware do it in a VM logging and redirecting all queries to external domains, in order to identify possible command and control hosts.
As a response, malware writers add checks for nonexistent domains. If, say, 5 domains known to be fake suddenly start replying, then the malware assumes that it's being executed inside a VM and stops doing anything, in order not to give researchers any clues. This malware just happened to check a single domain.
Re: WannaCry – New Variants Detected
#36Earlier quoted context omitted.
Do you seriously expect criminals are dumb enough to leave any useful information there?
Remember the guy which created Silk Road. People talked about him in mythical terms, that he probably has the op-sec of God, but afterwards facts pointed to major mistakes, like connecting identities to his real name, and suddenly everybody was like "how can he be so stupid, doing this while being the owner of a $100 mil criminal empire"
Re: WannaCry – New Variants Detected
#37Earlier quoted context omitted.
How do you mean? Is the malware detecting its in a VM?
Exactly. Based on what I understand, those that test malware do it in a VM logging and redirecting all queries to external domains, in order to identify possible command and control hosts. As a response, malware writers add checks for nonexistent domains. If, say, 5 domains known to be fake suddenly start replying, then the malware assumes that it's being executed inside a VM and stops doing anything, in order not to…
As I could easily run it in a VM and not redirect any traffic
Re: WannaCry – New Variants Detected
#38These systems would be better of security wise if they would use the latest open source operating system including the embedded code. The damage this will cause to embedded systems is distasteful.
Re: WannaCry – New Variants Detected
#39If they attach this to a new exploit, instead of an old one that targets Windows XP, there's going to be a real problem.
Re: WannaCry – New Variants Detected
#40Earlier quoted context omitted.
Remember the guy which created Silk Road. People talked about him in mythical terms, that he probably has the op-sec of God, but afterwards facts pointed to major mistakes, like connecting identities to his real name, and suddenly everybody was like "how can he be so stupid, doing this while being the owner of a $100 mil criminal empire"
Yet as far as I remember he leaked his identify long before anyone even knew Silk Road is even a thing. And someone behind this botnet certainly knew what scale it's going to have before they started it.