I really am a bit puzzeled by the killswitches. Why does WannaCry have this functionality in the first place? It sounds almost ironically like a hollywood villain mistake.
They're more analysis defeaters than killswitches. Some testbeds will respond to all dns lookups as valid. If this is the case the binary assumes its in a testbed and exits to avoid analysis.
WannaCry – New Variants Detected
81–90 of 164 posts
Re: WannaCry – New Variants Detected
#82Earlier quoted context omitted.
If you're talking about an MRI machine, and you put it on the goddamned internet, $300 is actually a pretty cheap security tutorial.
You do not need to put it on the Internet. It only needs to be connected to local network and it will be infected by someone connecting their laptop to it.
Re: WannaCry – New Variants Detected
#83I don't get it: why are the using using many fake but valid domains? Wouldn't a non-existing TLD do exactly the same thing while being impossible to register by anyone trying to stop the malware?
If it's not registerable it's not functional as a kill switch?
The domain check is there to detect whether the infection is running in a sandbox environment. If the domain check succeeds, it assumes it's being analyzed and aborts.
Or at least that's the prevailing theory.
Re: WannaCry – New Variants Detected
#84I don't get it: why are the using using many fake but valid domains? Wouldn't a non-existing TLD do exactly the same thing while being impossible to register by anyone trying to stop the malware?
Re: WannaCry – New Variants Detected
#85What's special about WannaCry that has made this such a widespread thing? I presume there's has been plenty of malware for a while that can propagate itself around a network of unpatched old Windows machines and people have been trying to get users to clicks on emails to infect themselves for years. So why now? What's so special now?
Re: WannaCry – New Variants Detected
#86I really am a bit puzzeled by the killswitches. Why does WannaCry have this functionality in the first place? It sounds almost ironically like a hollywood villain mistake.
It is not a ransomware operation but a counter-intel ooeration against security researchers.
This is starting to look dumb now, maybe researchers will let their guard down and blog even more about internal procedures?
Or maybe there is a hidden payload (Just a crazy idea based on the ovservation that there are multiple versions with corrupted payloads)
Re: WannaCry – New Variants Detected
#87That's just what I heard, but it makes sense. There are far more sane ways to implement a kill switch without using unregistered domains. (For instance, using a registered domain.)
Re: WannaCry – New Variants Detected
#88I don't get it: why are the using using many fake but valid domains? Wouldn't a non-existing TLD do exactly the same thing while being impossible to register by anyone trying to stop the malware?
Or even just sha256(unixtime().rand()).com Or a domain in a TLD that allows only second level TLDs (such as some of the commonwealth countries).
Yep, that's the way to do it.
Re: WannaCry – New Variants Detected
#89What's special about WannaCry that has made this such a widespread thing? I presume there's has been plenty of malware for a while that can propagate itself around a network of unpatched old Windows machines and people have been trying to get users to clicks on emails to infect themselves for years. So why now? What's so special now?
Re: WannaCry – New Variants Detected
#90Earlier quoted context omitted.
Do you seriously expect criminals are dumb enough to leave any useful information there?
Do you seriously expect most criminals are intelligent?