Earlier quoted context omitted.
I sent my first packet-of-death to an unprotected Windows machine in 1996, so...
1997 here :-) hat was that XP xploit app from back then... I cant recall what it was called...
Another Ransomware Outbreak Is Going Global
121–130 of 435 posts
Re: Another Ransomware Outbreak Is Going Global
#122Earlier quoted context omitted.
Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to securi…
No, it's probably not a 0-day this time. But this exploit used to be a NSA 0-day before it became public. Everything that's happening now is the "lite" version of what the NSA is capable of.
Re: Another Ransomware Outbreak Is Going Global
#123This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.
Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.
Re: Another Ransomware Outbreak Is Going Global
#124https://blockchain.info/tx/9778c698f3f2a2c9b9e9f0fdea3c96e8f...
Is there something special about using numerous senders like that?
Re: Another Ransomware Outbreak Is Going Global
#125Earlier quoted context omitted.
Why do you think it a mistake?
Because now we can watch those funds and know how much money they made, we can watch them to see if they make a mistake. If every address was different we'd have no idea how much money they're making and only funds paid by people who also reported them would be tainted by the long eyeball of the law.
Re: Another Ransomware Outbreak Is Going Global
#126Earlier quoted context omitted.
Probably via their smart phones
So a smartphone is not a computer anymore? The world we live in..
Re: Another Ransomware Outbreak Is Going Global
#127Something that monitors file access, disk activity, etc. for suspicious behavior and can trigger some action or alert?
I think I remember some discussion about using a 'canary file' - some innocent looking file with known contents which should never be modified. If a modification is detected, you know something fishy is going on.
Re: Another Ransomware Outbreak Is Going Global
#128Earlier quoted context omitted.
How do they plan on contacting the employees en masse if the computer is off?
Probably via their smart phones
Plus if there was a list, wouldn't it be on a computer that's currently off?
Re: Another Ransomware Outbreak Is Going Global
#129Earlier quoted context omitted.
There are indications that this new version uses a number of ways to spread. Where attacker == the ransomware executable: First is the EternalBlue exploit developed by and leaked from the NSA. EternalBlue exploits a flaw in Windows systems on port 445 TCP that can be used to take complete control of an unpatched system. So if an attacker can connect to a vulnerable Windows machine on port 445 tcp they can take contro…
Actually, I believe phishing / malicious attachment was debunked as the infection vector. Subsequent research found that WC starts scanning hosts and IP's on port 445 to try to find other machines to infect. Source: https://www.us-cert.gov/ncas/alerts/TA17-132A "Once the malware starts as a service named mssecsvc2.0, the dropper attempts to create and scan a list of IP ranges on the local network and attempts to conn…
Re: Another Ransomware Outbreak Is Going Global
#130Earlier quoted context omitted.
Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.
This is absurd nonsense, but my viewpoint is a lonely one on HackerNews.