Live data from Hacker News

WannaCry – New Variants Detected

blog.comae.io

111–120 of 164 posts

Re: WannaCry – New Variants Detected

#112
post #13

Earlier quoted context omitted.

The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.

> The initial attack vector is via an email attachment. So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.

This might help:

http://researchcenter.paloaltonetworks.com/2017/05/palo-alto...

Re: WannaCry – New Variants Detected

#113

Could the 51% "bug" in bitcoin actually be used to an advantage here? A 51% vote to invalidate all these transactions? I assume it doesn't work like that but figured I would ask.

No, no one will agree to reverse transactions in bitcoin. When half a billion dollars got lost in MtGox no one agreed either.

Re: WannaCry – New Variants Detected

#114

Could the 51% "bug" in bitcoin actually be used to an advantage here? A 51% vote to invalidate all these transactions? I assume it doesn't work like that but figured I would ask.

It's a feat that could be leveraged, but the likelihood and work to do so would outweigh actually pulling it off.

If this attack occurred against, for example, the CN government, they may step in and force miners to invalidate.

This scale is world-wide, there's no loss of public image and the amount of BTC is very small in the scheme of things.

Re: WannaCry – New Variants Detected

#115
post #93

Earlier quoted context omitted.

"older Windows versions" Win 10 is vulnerable without the patch that came out in march.

>Win 10 is vulnerable without the patch that came out in march Microsoft clearly disputes this in their own posts on the subject. https://blogs.technet.microsoft.com/msrc/2017/05/12/customer... "Customers running Windows 10 were not targeted by the attack today." What's your source?

WannaCry ("the attack") didn't target Windows 10 installations (probably since most Win10 users have updates enabled), but Windows 10 is still vulnerable without the patch.

Re: WannaCry – New Variants Detected

#116

I think it's hilarious how these "kill switches" are supposedly meant to detect sandboxes, to make it harder for security researchers to analyze the malware. While actually making it easy for security researchers to completely disable all installations around the entire world. That's just what I heard, but it makes sense. There are far more sane ways to implement a kill switch without using unregistered domains. (For…

The point of the killswitch is to detect if the worm is running inside a sandbox. Some sandboxes will resolve any domain you try to ping, so an easy way to detect this is to ping a non-existent domain name. I'm not totally sure how pinging an existing domain would give you the same behavior, but doing something like checking a handful of random non-existent domains from a large list could do the trick.

From the sounds of it, it seems like the researchers didn't expect the killswitch to disable the malware outside of the sandbox any more than the author of the malware did[0].

[0]: https://www.malwaretech.com/2017/05/how-to-accidentally-stop...

Re: WannaCry – New Variants Detected

#117

Earlier quoted context omitted.

An XP computer is old, Windows 8.1 is one generation back. Both are vulnerable to this exploit. Yes, patches have been available for supported versions, I don't know how that makes anything I said wrong or misleading.

We agree about it being not JUST old Windows versions being affected. I replied to your comment because the "old" Windows XP having no patch available was significant here, and I read your comment as saying "old" windows versions were not proportionally more responsible for WannaCry's rapid spread. Windows XP is still the third largest version of Windows by current installed base (after Windows 10 and Windows 7). The…

The resources I see don't show XP as third, though I'm sceptical of anything based on user agent. And I can't find anything about how responsible they would be for the spread.

I addressed that it wasn't "old" Windows because there is a crazy belief out there that this only hit XP.

Re: WannaCry – New Variants Detected

#118

Earlier quoted context omitted.

Hasn't that been a common thing in bitlocker malware for ages too? Did they just manage to craft so really persuasive emails this time?

WannaCry is a worm. It does not require people to click on anything in emails to be infected. It scans for vulnerable computers and infects them directly over the network.

[deleted]

Re: WannaCry – New Variants Detected

#119
post #13

Earlier quoted context omitted.

The initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.

> The initial attack vector is via an email attachment. So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.

We quarantine a few hundred attachments a day containing Word macros. I don't know if any are WannaCry, but nearly all are some form of ransomware.

It continues to be a very common attack method and I'd be surprised if it wasn't leveraged again.

Re: WannaCry – New Variants Detected

#120

Earlier quoted context omitted.

>Win 10 is vulnerable without the patch that came out in march Microsoft clearly disputes this in their own posts on the subject. https://blogs.technet.microsoft.com/msrc/2017/05/12/customer... "Customers running Windows 10 were not targeted by the attack today." What's your source?

WannaCry ("the attack") didn't target Windows 10 installations (probably since most Win10 users have updates enabled), but Windows 10 is still vulnerable without the patch.

Again, where is the source? I seriously doubt that the worm author would let go such a profitable target if they can infect Windows 10. According to this: https://www.netmarketshare.com/operating-system-market-share... Windows 10 has almost 4 times users than XP (and supposedly the gap is growing larger)
Post reply on HN