Live data from Hacker News

WanaCrypt0r Ransomworm

baesystemsai.blogspot.com

11–20 of 71 posts

Re: WanaCrypt0r Ransomworm

#11

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

Did you check the transactions? They could have already moved a part of the coins to an exchange.

According to blockchain.info, no coins have been moved from the addresses in the article.

Re: WanaCrypt0r Ransomworm

#12

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

Did you check the transactions? They could have already moved a part of the coins to an exchange.

[deleted]

Re: WanaCrypt0r Ransomworm

#13

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

I was listening to an NPR report on this and their explanation for the low amount was that the group wasn't handing over the keys after payment. Which I guess implies people who get infected are first researching what to do before paying.

Re: WanaCrypt0r Ransomworm

#15
post #4

> The initial infection vector is still unknown. Reports by some of phishing emails have been dismissed by other researchers as relevant only to a different (unrelated) ransomware campaign, called Jaff. There is also a working theory that initial compromise may have come from SMB shares exposed to the public internet. Results from Shodan show over 1.5 million devices with port 445 open – the attacker could have infec…

A fair amount of ransomware is distributed via email, so it's not such a bad idea when this issue is front and centre and all over the news to reinforce good behaviour amongst users.

It's not like 'stop clicking random shit in emails' is bad advice.

Re: WanaCrypt0r Ransomworm

#16
post #8

I always say that visual studio 6 was the best version they ever made. At least somebody out there agrees with me. "As noted in our attribution post last year, use of Visual Studio 6.0 is not a significant observation on its own – however, this development environment dates from 1998 and is rarely used by malware coders. Nonetheless, it has been seen repeatedly with Lazarus attacks."

Agreed. Visual J++ was unbelievably easy to use "Java"

Re: WanaCrypt0r Ransomworm

#17
post #8

I always say that visual studio 6 was the best version they ever made. At least somebody out there agrees with me. "As noted in our attribution post last year, use of Visual Studio 6.0 is not a significant observation on its own – however, this development environment dates from 1998 and is rarely used by malware coders. Nonetheless, it has been seen repeatedly with Lazarus attacks."

[deleted]

Re: WanaCrypt0r Ransomworm

#19
Evil Ransomware improvements we may see:

1. New address per machine (easier to detect payments made, hides profit total.)

2. Deterministic wallet stores all profit in a simple 12 word seed "password."

3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.)

4. Phone number to tech support company that bills your credit card to walk you through paying the ransom.

5. Delayed symptoms. Secretly encrypt backups (windows efs might be able to do it nonobviously) Then once all your backups are secretly encrypted, it encrypts the key, and now you can't use backups to save yourself.

6. Advertise affiliated antivirus (I hear this is what cloudflare does by hosting bad actors, they inflate their demand from protection from bad actors, just a rumor though.)

7. Infect a friend. Get a discount on your ransom if you infect a friend and they pay.

It doesn't seem reasonable that 300k infections= less than 1 in 1000 payments. Are peoples files really so worthless, or bitcoin really so hard, or people so untrusting of unencrypt. I imagine they could have sold their 0 day idea for more money to a whitehat perhaps? Maybe more generalized bug bounties could be deployed to offer financial incentive to harden systems and be non evil.

Re: WanaCrypt0r Ransomworm

#20
post #6

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

Earlier reports I'd heard said that this group was unprepared or poorly prepared to handle the incoming ransom. Many of these ransomware campaigns use a fully automated mechanism to deliver keys upon payment, this group did not.

How does that work in practice? Do the decryption keys get stored in the block chain as well or out of band?
Post reply on HN