Live data from Hacker News

WannaCry – New Variants Detected

blog.comae.io

41–50 of 164 posts

Re: WannaCry – New Variants Detected

#42
post #23

Earlier quoted context omitted.

How do you mean? Is the malware detecting its in a VM?

And why would they not then use randomly generated domain names, instead of hardcoding domains that could be registered?

Good point, although randomly generated domain names can exist.

Re: WannaCry – New Variants Detected

#43
post #38
post #16

These systems would be better of security wise if they would use the latest open source operating system including the embedded code. The damage this will cause to embedded systems is distasteful.

AIUI they would have been better off if they'd used the latest of any operating system.

If you're talking about an MRI machine, the proper drivers may not exist for a current operating system. The absolute last thing you want is for an image to show up differently on the new system due to changes to OpenGL or something.

Re: WannaCry – New Variants Detected

#44

How does 'Patient A' get wcry2? Phishing? Via internet facing open 445/3389?

My guess is this is why we're seeing multiple bitcoin addresses:

The original authors first released it with their own bitcoin address. It then spreads p2p around the world wherever it can to front-facing PCs.

Then 3rd-party spearfishers are sending it to corporate networks with their own bitcoin address so they can get the credit for getting past/through firewalls.

Re: WannaCry – New Variants Detected

#45
We were warned this would happen but it's interesting to me that we have detected new variants that include the same type of naive kill switch. I'm not well versed in information security, so my question is whether this means attackers tried another wave by simply changing the kill switch domain or were there several variants used for the initial attack?

Re: WannaCry – New Variants Detected

#46

Who is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.

Just from my limited experience of "being alive in the USA for 30-something odd years".. I don't think anyone is hard at work trying to get anyone. If you actually ever get the attention of the NSA/CIA - you don't get "caught" or ever make it to the news(except in gaffe's like snowden/assange, we weren't supposed to find out about them). They want us to forget about you, while you either rot in a dungeon(forever) or…

Disagree: they will hang the idiots responsible for WCry high and publicly, just to make an example pour encourager les autres.

Seriously, this cat's already out of the ba. There's nothing to be gained by trying to bury it, and making the consequences clear might reduce the likelihood of a repeat.

Re: WannaCry – New Variants Detected

#47

Just wait until this hits the files of a Russian mob who then take some Americans hostage and fly to China and end up entangled in an islamic terrorist plot. 'Cause then we're in for a very long and drawn out story involving MI6, the CIA, Canadian smuggling routes, and Christian Isolationist 2nd Amendment fanatics.

Could I purchase the movie rights to that? Could seriously make a good mini-series if done seriously. Ala John Le Carré.

I did get the impression when reading Reamde that it was written with a miniseries adaptation in mind.

Re: WannaCry – New Variants Detected

#48
post #13

Earlier quoted context omitted.

The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.

> The initial attack vector is via an email attachment. So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.

The Jaff waves and the massive amount of threats make it really hard to identify. Wannacrytor may not be found directly attached in the mail, only a downloader for it (like office docs/pdfs/js) might be.

Re: WannaCry – New Variants Detected

#49

Why would they keep releasing it, and release it in the first place, with such a simple kill-switch. Doesn't make much sense. Reminds me of the Archer episode where Cyril plants the computer virus and was going to be the hero by "fixing" it.

It's possible that people are taking the code, modifying it to add in a new kill switch address, change the bitcoin address and leave every thing else as it is. Usually because they don't understand the code but can do a ctrl+f, delete and replace with the necessary info. Script kiddies of the malware world.
Post reply on HN