Live data from Hacker News

Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

motherboard.vice.com

251–260 of 268 posts

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#251

Earlier quoted context omitted.

> This is all easily verifiable with google and archive.org. Yes. And I've had a hostile fellow once upon a time put my RL info in the whois and post a bunch of shit on it. I generally give people the benefit of the doubt when its random online public stuff until they are convicted. The internet "evidence" is way too flimsy to be considered reasonable standards of proof imho.

Okay, never fear! In that case I will provide you with irrefutable proof. Navigate to: https://web.archive.org/web/20131031200609/https://twitter.c... Pick any of the tweets, copy the direct link to that tweet. You'll end up with something like this: https://web.archive.org/web/20131031200609/https://twitter.c... Now remove the archive.org part from the beginning: https://twitter.com/TouchMyMalware/status/39586278660…

> Now remove the archive.org part from the beginning: https://twitter.com/TouchMyMalware/status/395862786602827776

> Click on the link and boom you're suddenly redirected to https://twitter.com/MalwareTechBlog/status/39586278660282777....

> Okay, never fear! In that case I will provide you with irrefutable proof.

> Happy?

https://twitter.com/TouchMyMalware/status/893243147580473344

You proved he is Donald Trump?

I'm not trying to pick a fight here so just chill and move on. We aren't going to agree.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#252
post #76

Earlier quoted context omitted.

Was it him or BetaMonkey running this? If I recall correctly BM owned voidptr but both had admin access there? EDIT: Ah, found some old logs on google: http://www.exposedbotnets.com/2013/05/hf-elite-coding-team.h... [08:08] if i still owned this irc [08:09] i would shut it down and start over

BetaMonkey/TouchMe was in fact the person I was referring to who was providing support for his botnet drone builder until he dissapeared with no trace at a later date. Just could not recall the nick at the time of making my original post.

Betamonkey was someone different. The reason he disappeared without a trace was that he was so bad at PHP that people got sent to prison (his support site was owned by a whitehat and all the customer information was harvested and distributed to law enforcement)[0].

Touchme/Marcus was a close friend of his though, one of his first articles on the site that eventually became malwaretech.com was an attempt to disprove the claim that betamonkey's malware was banking malware. This had gotten him banned from selling on hackforums, his main source of customers at the time. You have to read the article on the way back machine, for some reason he deleted it from his site later on [1].

If I were betamonkey I would be sweating pretty hard right now, his malware is also still being used and Marcus will be looking hard for someone else to drag under the bus.

[0] http://www.xylibox.com/2015/04/betabot-retrospective.html [1] https://web-beta.archive.org/web/20130625172146/http://touch... (halfway down the page)

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#253

Earlier quoted context omitted.

Okay, never fear! In that case I will provide you with irrefutable proof. Navigate to: https://web.archive.org/web/20131031200609/https://twitter.c... Pick any of the tweets, copy the direct link to that tweet. You'll end up with something like this: https://web.archive.org/web/20131031200609/https://twitter.c... Now remove the archive.org part from the beginning: https://twitter.com/TouchMyMalware/status/39586278660…

> Now remove the archive.org part from the beginning: https://twitter.com/TouchMyMalware/status/395862786602827776 > Click on the link and boom you're suddenly redirected to https://twitter.com/MalwareTechBlog/status/39586278660282777... . > Okay, never fear! In that case I will provide you with irrefutable proof. > Happy? https://twitter.com/TouchMyMalware/status/893243147580473344 You proved he is Donald Trump? I'm…

>I'm not trying to pick a fight here so just chill and move on. We aren't going to agree.

Yes, I'm sorry I didn't immediately realize that you were just trolling. If not, you might want to look at the parts of my post you decided not to quote.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#254

Earlier quoted context omitted.

> This is all easily verifiable with google and archive.org. Yes. And I've had a hostile fellow once upon a time put my RL info in the whois and post a bunch of shit on it. I generally give people the benefit of the doubt when its random online public stuff until they are convicted. The internet "evidence" is way too flimsy to be considered reasonable standards of proof imho.

Okay, never fear! In that case I will provide you with irrefutable proof. Navigate to: https://web.archive.org/web/20131031200609/https://twitter.c... Pick any of the tweets, copy the direct link to that tweet. You'll end up with something like this: https://web.archive.org/web/20131031200609/https://twitter.c... Now remove the archive.org part from the beginning: https://twitter.com/TouchMyMalware/status/39586278660…

Even better -- Here's someone @'ing TouchMyMalware and then MalwareTechBlog replying "Thanks for the tweet, also my new twitter handle is @MalwareTechBlog"

https://twitter.com/MalwareTechBlog/status/40533646447018393...

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#255

Earlier quoted context omitted.

He found the address in the source code of the ransomware, any researcher could have found it. He even said himself that when he found it in the source code and saw it was unregistered he registered it to see what would happen. As it turned out it stopped infections from occurring. Not to say that he isnt the malware writer but your use of quote marks makes me think you have no idea about what happened and havent loo…

Pretty sure it was in disassembled machine code, not source code.

I have taken the liberty to download a sample of WannaCry and I can see the "killswitch" domain just running strings on the binary.

    $ strings Downloads/24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c.bin |grep .com
   __p__commode
   http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#257

I like how this malware writer/researcher claims he "found" the address and "miraculously saved" everyone by grabbing the domain. Not sure why everyone says he isn't the malware writer. What proof do you have that he didn't write it? Maybe he left a trail that you missed.

The firm he works for literally pays him to track size and scale of malware outbreaks. Whats the best way to do that? Look for domains the malware attempts to communicate with and register them, pointing them at the firm's sinkhole server. From there the server can generate reports on how many connections it gets and from where.

He did what he would of done to any malware once he found an unregistered domain, he registered it. He didn't realise the malware was using that domain as a killswitch.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#258
post #225

Since https://news.ycombinator.com/item?id=14922563 adds significant new information (or at least I assume it does), the discussion can shift there now.

I'm more than happy to discuss this issue here.

In my opinion, Marcus Hutchins will spend the next 10 years of his life working for the NSA and reverse engineering malware built by the Chinese. Unless MI5 has other plans.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#259

Earlier quoted context omitted.

Where have you been? In the US, they can do whatever they want to you.

This is by all appearances a lawful and routine arrest.

That's what's even more worrying. People getting accustomed to such "routine" arrests.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#260
post #137

This reminds me of Kevin Mitnick: https://en.wikipedia.org/wiki/Kevin_Mitnick#Arrest.2C_convic... Do we need to create some "Free Marcus" bumper stickers?

Mitnick was actually a criminal. He was living off stolen credit cards.

I completely agree with you. I'm pretty sure Marcus isn't either from the sound of it. Just a bit freaked out by our government's tactics and sharing a memory.
Post reply on HN