copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe
Why append a random number to a copy of certutil.exe other than to change the file signature?
401–410 of 514 posts
copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe
Why append a random number to a copy of certutil.exe other than to change the file signature?
Earlier quoted context omitted.
Holy hell... no wonder they snuffed it out in the media. I live in Eastern Europe. A local city with a population of 300-400k was hit with a near total ransomware attack. The hackers asked for 400 bitcoin. The mayor answered to them on TV "You fools, we still do most things on paper here ! We'll just spend the week-end installing windows and word and F** Y* !!!" I sometime find wisdom in the approach from olden times…
> Holy hell... no wonder they snuffed it out in the media. The OPM hack wasn’t ‘snuffed out’ by any means - it was fairly well covered for a cyber attack of it’s era. Perhaps it wasn’t covered much in your part of Eastern Europe, but it was definitely not covered up. The fact that some people have forgotten about it is a completely different issue.
This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware…
There is also allegedly a reciprocal agreement to allow extradition and prosecution for cyber attacks. So we'll see if that comes to pass or if it's just a little fake glad handing until you actually try to take them up on it.
What are those VSA tools used for in practice? Can anyone in IT who uses them tell us. I don't mean what is sold as I mean what it is used in reality, actual operations performed.
I used to run a small security consultancy and nearly got into this business to expand our operations and get some of that sweet sweet recurring revenue. The problem I found at the time was that none of the software companies selling products that I would use were building in a security posture that I was even remotely (hur dur) comfortable with.
Working through the IoC, I see these lines copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe Why append a random number to a copy of certutil.exe other than to change the file signature?
Oddly explosive headline, considering: > It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details. So why "colossal"? > "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency. The BBC is going with "colossal" in their headline simply because the gu…
Earlier quoted context omitted.
I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)
That's an accurate interpretation of what I'm saying. I don't think it's particularly bold. I don't have any hard evidence but I'm sure you could find some. I certainly don't remember ransomware attacks being very prevalent prior to last decade. They all seem to request cryptocurrencies (I can tell you're a coin head because you refer to them simply as crypto). Without cryptocurrencies ransomeware would largely go aw…
I remember that Walmart or the govt or both made some change where these didn’t work the same way and lost their shine for ransom payments.
Thin on details but the as I recall the options for paying ransoms easily prior to crypto were tightening up.
That said, I’m 100% against the idea of fighting crypto to solve this problem. The liberty of humanity needs anonymous cash despite the risks that come with it. Better to address these problems on the data security and resiliency front.
Working through the IoC, I see these lines copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe Why append a random number to a copy of certutil.exe other than to change the file signature?
Making a copy with a new random name defeats this detection logic.
Earlier quoted context omitted.
I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)
These attacks didn't exist before crypto.
After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…
Nothing will change until government regulates it. Same with auto, airlines and rail. They did not make their products and services safer by choice, they were regulated to do so.