Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

121–130 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#121

Earlier quoted context omitted.

I sent my first packet-of-death to an unprotected Windows machine in 1996, so...

1997 here :-) hat was that XP xploit app from back then... I cant recall what it was called...

back orifice? subseven?

Re: Another Ransomware Outbreak Is Going Global

#122
post #69
post #65

Earlier quoted context omitted.

Maybe I'm missing something, but is there any evidence that this is actually a 0day attack? I didn't study the last outbreak that closely, but it seemed like it was a vulnerability that had been patched, but affected computers that weren't patched. Maybe I'm wrong though. But 0days or no, there will always exist some number of computers that have not been properly kept up-to-date and thus will be vulnerable to securi…

No, it's probably not a 0-day this time. But this exploit used to be a NSA 0-day before it became public. Everything that's happening now is the "lite" version of what the NSA is capable of.

Yeah, and the Department of Defense is capable of nuking major cities. And it's about as relevant to this discussion.

Re: Another Ransomware Outbreak Is Going Global

#123
post #50

This is even more proof how powerful a 0-day in the wrong hands can be. All of the affected companies' should be considered compromised by the NSA. Actually, every single Windows PC with an internet connection that has been used before March 14 should be considered irrevocably compromised. Ransomware is much more visible than spyware. Think about all the spyware-infected PCs/networks that nobody knows about.

Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.

You're paranoid.

Re: Another Ransomware Outbreak Is Going Global

#125

Earlier quoted context omitted.

Why do you think it a mistake?

Because now we can watch those funds and know how much money they made, we can watch them to see if they make a mistake. If every address was different we'd have no idea how much money they're making and only funds paid by people who also reported them would be tainted by the long eyeball of the law.

It does not seem like something wrong directly. I also think showing off might be intention.

Re: Another Ransomware Outbreak Is Going Global

#126
post #85
post #59

Earlier quoted context omitted.

Probably via their smart phones

So a smartphone is not a computer anymore? The world we live in..

It may be, but it is not in hardware or software lated to the major "desktop" platforms. And they are by design far more locked down than your average laptop or desktop (just wish said locked state didn't leave the OEM so much in control).

Re: Another Ransomware Outbreak Is Going Global

#127
Does anyone know if any tools exist on Linux which can be used for early detection of ransomeware?

Something that monitors file access, disk activity, etc. for suspicious behavior and can trigger some action or alert?

I think I remember some discussion about using a 'canary file' - some innocent looking file with known contents which should never be modified. If a modification is detected, you know something fishy is going on.

Re: Another Ransomware Outbreak Is Going Global

#128
post #59

Earlier quoted context omitted.

How do they plan on contacting the employees en masse if the computer is off?

Probably via their smart phones

Is it common to have a list of every employee's mobile phone? I would guess a lot of firms just have informal lists of phone numbers held by managers and colleagues.

Plus if there was a list, wouldn't it be on a computer that's currently off?

Re: Another Ransomware Outbreak Is Going Global

#129
post #94

Earlier quoted context omitted.

There are indications that this new version uses a number of ways to spread. Where attacker == the ransomware executable: First is the EternalBlue exploit developed by and leaked from the NSA. EternalBlue exploits a flaw in Windows systems on port 445 TCP that can be used to take complete control of an unpatched system. So if an attacker can connect to a vulnerable Windows machine on port 445 tcp they can take contro…

Actually, I believe phishing / malicious attachment was debunked as the infection vector. Subsequent research found that WC starts scanning hosts and IP's on port 445 to try to find other machines to infect. Source: https://www.us-cert.gov/ncas/alerts/TA17-132A "Once the malware starts as a service named mssecsvc2.0, the dropper attempts to create and scan a list of IP ranges on the local network and attempts to conn…

That only happens after the initial infection into the network. Notice that it says it scans the "local network".

Re: Another Ransomware Outbreak Is Going Global

#130

Earlier quoted context omitted.

Call me paranoid but I consider even a clean, freshly installed and fully updated Windows PC already compromised by the NSA.

This is absurd nonsense, but my viewpoint is a lonely one on HackerNews.

Very lonely, seeing as how it's been proven time and time again that NSA stockpiles Windows 0days. You're delusional.
Post reply on HN