Live data from Hacker News

WanaCrypt0r Ransomworm

baesystemsai.blogspot.com

21–30 of 71 posts

Re: WanaCrypt0r Ransomworm

#21
post #15
post #4

> The initial infection vector is still unknown. Reports by some of phishing emails have been dismissed by other researchers as relevant only to a different (unrelated) ransomware campaign, called Jaff. There is also a working theory that initial compromise may have come from SMB shares exposed to the public internet. Results from Shodan show over 1.5 million devices with port 445 open – the attacker could have infec…

A fair amount of ransomware is distributed via email, so it's not such a bad idea when this issue is front and centre and all over the news to reinforce good behaviour amongst users. It's not like 'stop clicking random shit in emails' is bad advice.

I do remember when ILOVEYOU was making the rounds...and to paraphrase, it's not like 'stop clicking random shit in emails' is useful advice.

Yes, it would help - but do you see fewer people clicking random shit? Me neither: "Ugg click attachment for dancing hampsters, now Ugg virus, halp!" is still the prevalent vector, two decades later.

Re: WanaCrypt0r Ransomworm

#22
Did these happenings had any effect on windows market share? Hope somebody will blog on that too.

I hope many people have understood to not have public windows servers at least. It could most probably affect their business in the long run (Not saying that GNU/Linux is safe. But it is safer).

Re: WanaCrypt0r Ransomworm

#23
post #8

I always say that visual studio 6 was the best version they ever made. At least somebody out there agrees with me. "As noted in our attribution post last year, use of Visual Studio 6.0 is not a significant observation on its own – however, this development environment dates from 1998 and is rarely used by malware coders. Nonetheless, it has been seen repeatedly with Lazarus attacks."

1998 was still a great year in Windows world. In 1999 the DotNet vision made lot's of things kind of legacy - kind of, because despite all odds Win32 and shell32/Explorer are still thriving where as DotNet Framework is now officially legacy tech. And UWP hasn't caught on, as mobile is dead end for MS and their Store is incredible bad.

True Visual Studio was really great. And like many, one had a VS6 and VB6 install still around. Even if VS6 C++ is really outdated nowadays, it doesn't contain this spy-home feature that shipper with VS 2015 and VCredist 2015 (RTM, patch 1, patch 2). Back in the 1990s MS was a good company.

Re: WanaCrypt0r Ransomworm

#24

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

I don't know a single person who would pay upwards of $300 to get their files back if they got hit with ransomware. Hell, I've got something like 10 years of personal files on my machine and I wouldn't pay that much for them. I would bet a lot more people would be willing to pay if the fee was more like $50. That takes it out of the category of 'a lot of money for computer files' for a lot of people and puts it in the category of 'minor inconvenience'.

I sometimes fix friends & older family members computers as a favor and I've noticed that they usually don't really have any files anyway. I always make a backup before reformatting them and usually it includes their bookmarks and maybe 2-3 random files scattered in their 'Documents' folder, none of which are important. Their machines are more like just gateways to the internet than anything.

Through machines moves over the years I'm sure I have multiple copies of the most important ones anyway (keys, etc). If not oh well, life goes on. Shoulda made backups in the first place if they were that important to me.

Re: WanaCrypt0r Ransomworm

#25
I'm surprised by how carefully the worm seems to be coded. They make sure they have an internet connection, they check for disk space in order not to run out while encrypting, they save a backup copy of the "tasksched" executable before replacing it, they shutdown databases (I assume in order to prevent corruption?) etc...

I guess they want to make sure the decryption process will work without any issue so that the victim will be more likely to pay other ransoms or spread word of mouth that it does actually work.

I wish all software devs were as thorough as these people...

Re: WanaCrypt0r Ransomworm

#26

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

"Are peoples files really so worthless, or bitcoin really so hard, or people so untrusting of unencrypt."

I think that is super small subset. Average people use a ton of cloud software nowadays: google docs, dropbox etc. Let alone use a desktop for anything besides work. The files they super care about (photos) are usually on their device or scattered all over facebook. Work files/computers, well they don't care about, that is some IT's guys job.

So the probability to get paid = [their ability to get bit coin] * [inability to have it already backed up] * [value of file[s]]. That does seem like a high bar. I also don't see an IT guy convincing a corporate attorney / accountant that wiring money to obtain bitcoin as an easy feat.

Re: WanaCrypt0r Ransomworm

#27
post #15
post #4

> The initial infection vector is still unknown. Reports by some of phishing emails have been dismissed by other researchers as relevant only to a different (unrelated) ransomware campaign, called Jaff. There is also a working theory that initial compromise may have come from SMB shares exposed to the public internet. Results from Shodan show over 1.5 million devices with port 445 open – the attacker could have infec…

A fair amount of ransomware is distributed via email, so it's not such a bad idea when this issue is front and centre and all over the news to reinforce good behaviour amongst users. It's not like 'stop clicking random shit in emails' is bad advice.

Why the hell can't I click shit in random emails?

It's a friggin email and data transfer for crying out loud.

Stop blaming users.

Re: WanaCrypt0r Ransomworm

#28
post #23
post #8

I always say that visual studio 6 was the best version they ever made. At least somebody out there agrees with me. "As noted in our attribution post last year, use of Visual Studio 6.0 is not a significant observation on its own – however, this development environment dates from 1998 and is rarely used by malware coders. Nonetheless, it has been seen repeatedly with Lazarus attacks."

1998 was still a great year in Windows world. In 1999 the DotNet vision made lot's of things kind of legacy - kind of, because despite all odds Win32 and shell32/Explorer are still thriving where as DotNet Framework is now officially legacy tech. And UWP hasn't caught on, as mobile is dead end for MS and their Store is incredible bad. True Visual Studio was really great. And like many, one had a VS6 and VB6 install s…

"Back in the 1990s MS was a good company."

Umm, isn't that precisely the period when they were charged with antitrust violations? Such a short memory we have.

Re: WanaCrypt0r Ransomworm

#29
post #15

Earlier quoted context omitted.

A fair amount of ransomware is distributed via email, so it's not such a bad idea when this issue is front and centre and all over the news to reinforce good behaviour amongst users. It's not like 'stop clicking random shit in emails' is bad advice.

Why the hell can't I click shit in random emails? It's a friggin email and data transfer for crying out loud. Stop blaming users.

Oh, you can. Just like you can inject any random substance given to you by a stranger.

Being aware that both are high risk activities is the point, methinks.

Re: WanaCrypt0r Ransomworm

#30
post #24

Evil Ransomware improvements we may see: 1. New address per machine (easier to detect payments made, hides profit total.) 2. Deterministic wallet stores all profit in a simple 12 word seed "password." 3. Phone numbers directly to bitcoin vendors. (people running insecure systems love phones.) 4. Phone number to tech support company that bills your credit card to walk you through paying the ransom. 5. Delayed symptoms…

I don't know a single person who would pay upwards of $300 to get their files back if they got hit with ransomware. Hell, I've got something like 10 years of personal files on my machine and I wouldn't pay that much for them. I would bet a lot more people would be willing to pay if the fee was more like $50. That takes it out of the category of 'a lot of money for computer files' for a lot of people and puts it in th…

Sounds like it would be more profitable to just lock out the device than encrypt the files, for its internet browsing value may exceed its file storage value.
Post reply on HN