Live data from Hacker News

WannaCry – New Variants Detected

blog.comae.io

51–60 of 164 posts

Re: WannaCry – New Variants Detected

#51
post #43
post #38

Earlier quoted context omitted.

AIUI they would have been better off if they'd used the latest of any operating system.

If you're talking about an MRI machine, the proper drivers may not exist for a current operating system. The absolute last thing you want is for an image to show up differently on the new system due to changes to OpenGL or something.

If you're talking about an MRI machine, and you put it on the goddamned internet, $300 is actually a pretty cheap security tutorial.

Re: WannaCry – New Variants Detected

#52
post #27

Earlier quoted context omitted.

This is what happens when spambot skiddies accidentally acquire a treasure-trove of NSA tools via a C2 server they have pwned. They failed to sell ('broker') them as nobody was stupid enough to touch them, they failed to blackmail with them (omg what a bad move), then they failed to weaponise their own gear with them (wcry 1.0 in February), and even though wcry 2.0 is widespread and very disruptive, really they faile…

A bunch of articles, even Snowden, argued that it's very likely that the NSA tools were stolen by the Russians. https://twitter.com/Snowden/status/765514891813945344

And given the indications about how hard various Russian infrastructure was hit, that would be ironic.

Of course, if you were a nation state and you wanted to attack an adversary but you knew that if you did you would get blowback, you might "lose" some tools that you knew some script kiddies would be able to weaponize.

Interesting times indeed.

Re: WannaCry – New Variants Detected

#55
post #23

Earlier quoted context omitted.

How do you mean? Is the malware detecting its in a VM?

And why would they not then use randomly generated domain names, instead of hardcoding domains that could be registered?

The MalwareTech article that documents this best, https://www.malwaretech.com/2017/05/how-to-accidentally-stop... , uses Necurs as an example of a trojan that uses randomly generated domain names, so probably not at technical reason.

Re: WannaCry – New Variants Detected

#56

Just wait until this hits the files of a Russian mob who then take some Americans hostage and fly to China and end up entangled in an islamic terrorist plot. 'Cause then we're in for a very long and drawn out story involving MI6, the CIA, Canadian smuggling routes, and Christian Isolationist 2nd Amendment fanatics.

Psst, downvoters - https://en.wikipedia.org/wiki/Reamde

Downvotes are appropriate. HN isn't the place for in-jokes or pop culture references.

Re: WannaCry – New Variants Detected

#57
post #31
post #9

Earlier quoted context omitted.

Do you seriously expect criminals are dumb enough to leave any useful information there?

Remember the guy which created Silk Road. People talked about him in mythical terms, that he probably has the op-sec of God, but afterwards facts pointed to major mistakes, like connecting identities to his real name, and suddenly everybody was like "how can he be so stupid, doing this while being the owner of a $100 mil criminal empire"

It's a classic asymmetry: the defender needs to defend all the time, the hacker just needs to get in once. Ditto op-sec, the hacker needs to keep their identity protected at all times, the security services only need to connect the dots once.

Re: WannaCry – New Variants Detected

#58

> A new variant with no kill-switch recovered by Kaspersky as a virustotal.com upload — not detected in the Wild. Uploaded to virustotal MEANS found in the wild. That's what admins do when they discover things.

I don't know if this one was detected in the wild or not (99% chance it was), however, malware authors occasionally use Virustotal too.

Re: WannaCry – New Variants Detected

#59
post #51
post #43

Earlier quoted context omitted.

If you're talking about an MRI machine, the proper drivers may not exist for a current operating system. The absolute last thing you want is for an image to show up differently on the new system due to changes to OpenGL or something.

If you're talking about an MRI machine, and you put it on the goddamned internet, $300 is actually a pretty cheap security tutorial.

You do not need to put it on the Internet. It only needs to be connected to local network and it will be infected by someone connecting their laptop to it.

Re: WannaCry – New Variants Detected

#60

Maybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.

I suppose that might be interesting just to see if they're stupid enough to register with traceable info.

The whole point of this "kill switch" is that it’s NOT registered. The malware uses it to detect if it runs in the sandbox, as researchers often make all DNS requests succeed in their sandbox. Checking for an domain known to be unregistered is one way of checking that.
Post reply on HN