14 ms·
> the employee came back with the news that the registration of the domain had triggered the ransomware meaning we’d encrypted everyone’s files... Even though
by dperfect 9y ago
> the employee came back with the news that the registration of the domain had triggered the ransomware meaning we’d encrypted everyone’s files...
Even though this fortunately turned out to be false, what if it had been true? Would the security researcher be held in any way accountable for activating the ransomware? If I were the author, I might be a bit more careful in the future before changing factors in the global environment[1] that have the potential to adversely affect the malware's behavior, but of course I'm not a security researcher, so I really don't know.
[1] I suppose a domain could probably be made to appear unregistered after being registered - depending on the actual check performed - but there are other binary signals (e.g., the existence of a certain address or value in the bitcoin blockchain) that might not be so easy to reverse.
- campuscodi 9y agoThe ransomware was already active for hours by that point. The answer the employee provided did not make any sense. Not now, not the first time I read the blog.
- dangero 9y agoIt's an interesting thought experiment. The closest analogy I can think of is pulling the wrong wire on a bomb.
- FLUX-YOU 9y agoThat's what bugs me about the blog post but it may only be an issue with how it's written or my understanding. From the Talos Intelligence blog: >The above subroutine attempts an HTTP GET to this domain, and if it fails, continues to carry out the infection. However if it succeeds, the subroutine exits. It's not clear if the subroutine being shown is the main entry point in which case return 0 exits (which is good for us), or if it's part of a larger framework that would be doing stuff later on (which is potentially bad for everyone because it could decide to do other things if it finds that domain sinkholed?) The blog author checked on whether or not the domain name changes, but didn't specify any details about anything going on higher in the stack: >All this code is doing is attempting to connect to the domain we registered and if the connection is not successful it ransoms the system, if it is successful the malware exits (this was not clear to me at first from the screenshot as I lacked the context of what the parent function may be doing with the results). So my question is how much knowledge did they have of the rest of the code when registering the domain? Would the analysis environment have provided more information if the malware had continue to run after realizing the domain was sinkholed?
- ufmace 9y agoI would think not. For something bad to happen from registering the domain, there would have to be some kind of weird booby-trap in the malware. What's the motivation for a malware author to do that? If they can do something worse, the incentive is to just do it, rather than wait for a security researcher to do something first that they may or may not ever do. It's not impossible, but it's a little ridiculous and wildly unprecedented in the field of malware analysis. When there's a global infection spreading wildly and crippling essential organizations, you want everyone to act fast, not spend weeks making sure everything is perfect. If you see the malware connecting out to an unregistered domain, you just register it now. Whoever is first gets it, and the attacker could realize their mistake at any time. Even without knowing what this malware does with the connection, odds are 99.9% that the situation is better with the domain controlled by a security researcher than by a malware author. Punishing researchers if something done in good faith turned out badly would incentivize them to overanalyze everything and delay taking any potential beneficial action until it's too late.
- SomeStupidPoint 9y agoSecurity researchers absolutely should have liability for poking malware in the wild on their own initiative. If you're a bomb enthusiast or researcher, you'd absolutely be liable if you tried to defuse a bomb without being requested to by the police. This is no different because of the potential for massive collateral damage. You want to see what happens when the domain is registered? Resolve the DNS on your own network. It's only when acting under government direction that you should be immunized from liability.
- AmIFirstToThink 9y agoWhew, you almost got me. :-) Got all riled up and then saw the username. Enjoy!
- SomeStupidPoint 9y agoI was being serious. I am curious why you disagree with me, though.
- kbenson 9y ago> Would the security researcher be held in any way accountable for activating the ransomware? I think that would be the equivalent of an arsonist also leaving a water activated chemical at the scene of the fire, and then blaming the firemen for using water to put out the fire when it made the situation worse.
- lathiat 9y agoLet's be honest if he didn't someone else malicious or otherwise would have. This is the internet. Better in the hands of someone like this.