Live data from Hacker News

WanaCrypt0r Ransomworm

baesystemsai.blogspot.com

1–10 of 71 posts

Re: WanaCrypt0r Ransomworm

#2
Quote: "The initial infection vector is still unknown. Reports by some of phishing emails have been dismissed by other researchers as relevant only to a different (unrelated) ransomware campaign, called Jaff."

Would it be easy to find it if the initial attack vector uses some semi-obscure torrent? Would people find out quickly?

Re: WanaCrypt0r Ransomworm

#3
according to the article, the balances of the bitcoin addresses collecting the ransoms are

15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361

Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

Re: WanaCrypt0r Ransomworm

#4
> The initial infection vector is still unknown. Reports by some of phishing emails have been dismissed by other researchers as relevant only to a different (unrelated) ransomware campaign, called Jaff. There is also a working theory that initial compromise may have come from SMB shares exposed to the public internet. Results from Shodan show over 1.5 million devices with port 445 open – the attacker could have infected those shares directly.

I think this is an important take-away. I found it strange that so many media outlets and IT departments were jumping on the "do not open suspicious emails" bandwagon even although there hasn't been a lot of evidence of such phishing emails. That is: screenshots of infected devices have been popping up all across the world, but almost no examples of a particular entry email have been shown.

Of course, it might be easier for an IT dep. to state: "it must have been unleashed by someone clicking on some email they got" rather than "oops, we still had unpatched Windows machines exposed to the public internet". Why go through the trouble of sending out emails when your worm already contains a replication/infection mechanism. Just use a botnet to scan those 1 million IPs and see if SMB is open.

That being said, it does not surprise me to see yet again an issue in SMB. This has been a particularly weak point in Windows for decades now. I remember "hacking tutorials" from 15 years ago where you'd just go out and nmap public IP ranges to see if you could access hidden shares (e.g. like so: http://www.madirish.net/59). Also there was this issue of Windows keeping weak NetBIOS password hashes around which could be trivially unhashed (https://vuldb.com/?id.13824), years ago.

Re: WanaCrypt0r Ransomworm

#5

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

Did you check the transactions?

They could have already moved a part of the coins to an exchange.

Re: WanaCrypt0r Ransomworm

#6

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

Earlier reports I'd heard said that this group was unprepared or poorly prepared to handle the incoming ransom. Many of these ransomware campaigns use a fully automated mechanism to deliver keys upon payment, this group did not.

Re: WanaCrypt0r Ransomworm

#7

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

I think this venn diagram explain part of the problem:

https://www.trustar.co/wp-content/uploads/2017/05/WannaCryVe...

Re: WanaCrypt0r Ransomworm

#8
I always say that visual studio 6 was the best version they ever made. At least somebody out there agrees with me.

"As noted in our attribution post last year, use of Visual Studio 6.0 is not a significant observation on its own – however, this development environment dates from 1998 and is rarely used by malware coders. Nonetheless, it has been seen repeatedly with Lazarus attacks."

Re: WanaCrypt0r Ransomworm

#9

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

It's easy to find out the total. There's even a twitter bot[1] reporting it. At the moment the total is 44.98BTC = $80,925. I'd argue ofc it's more because there are some variations of the worm that's not being accounted by many yet.

[1]: https://twitter.com/ransomtracker

Re: WanaCrypt0r Ransomworm

#10

according to the article, the balances of the bitcoin addresses collecting the ransoms are 15.13562354 BTC = $26410 13.78022431 BTC = $24045 5.98851225 BTC = $17361 Assuming $300 per ransom, this works out to a total of 226 victims who paid. this seems a little low compared to the huge amount of infected devices.

Did you check the transactions? They could have already moved a part of the coins to an exchange.

Last time I checked none of the coins were ever moved and in general ransomware earnings are not moved. They're just waiting for fungibility on Bitcoin.
Post reply on HN