11 ms·
WannaCry – New Variants Detected
- nthcolumn 9y agoHow does 'Patient A' get wcry2? Phishing? Via internet facing open 445/3389?
- Nacraile 9y agoFrom what I've read, initial attack vector is still not known for sure. Spear phishing seems to be the current best hypothesis. I don't think anyone's seen a mass phishing campaign. See: https://arstechnica.com/security/2017/05/an-nsa-derived-ransomware-worm-is-shutting-down-computers-worldwide/ https://arstechnica.com/security/2017/05/an-nsa-derived-rans...
- Nrsolis 9y agoThe initial attack vector is via an email attachment. Once it's infected a host, the SMB scanning for vulnerable hosts is launched and secondary infections begin with no further user action required.
- draugadrotten 9y ago> The initial attack vector is via an email attachment. So far it seems an hypothesis and nobody has shown such an email attachment, which is strange considering all the systems out there which save and archive attachments. Especially hospitals and gov't sites saves it all.
- arkaine 9y agoThe Jaff waves and the massive amount of threats make it really hard to identify. Wannacrytor may not be found directly attached in the mail, only a downloader for it (like office docs/pdfs/js) might be.
- Nrsolis 9y agoThis might help: http://researchcenter.paloaltonetworks.com/2017/05/palo-alto-networks-protections-wanacrypt0r-attacks/ http://researchcenter.paloaltonetworks.com/2017/05/palo-alto...
- technion 9y agoWe quarantine a few hundred attachments a day containing Word macros. I don't know if any are WannaCry, but nearly all are some form of ransomware. It continues to be a very common attack method and I'd be surprised if it wasn't leveraged again.
- ethbro 9y agoGiven that the primary targets seem to be running unpatched Windows (at least to latest), I'd guess there's a substantial amount of internet-accessible SMB ports. If so, you wouldn't need a very high phish:total infected hosts ratio to explain the numbers. And given that whoever was originally phished didn't know it was an illegitimate email... not betting we'll see many examples of the initial vector.
- nthcolumn 9y agoWhy isn't the internet alive with the email subject line then? The email would be multi-lingual too?
- rickdg 9y agoSpear phishing is now a lot more effective.
- Scoundreller 9y agoMy guess is this is why we're seeing multiple bitcoin addresses: The original authors first released it with their own bitcoin address. It then spreads p2p around the world wherever it can to front-facing PCs. Then 3rd-party spearfishers are sending it to corporate networks with their own bitcoin address so they can get the credit for getting past/through firewalls.
- matthewbauer 9y agoThat's possible but wouldn't there be evidence of this kind of arrangement? Authors need to document how to do it, I think.
- ytpete 9y agoIf the payment goes to them instead of the original authors, how could the new hijackers of the virus offer to decrypt the data? I'd assume only the original authors have access to the private keys needed for that. If someone was really clever they could change the Tor addresses it talks to for command & control and write their own complete replacement backend, but at that point it seems like you'd be looking at people capable enough to just write their own malware from scratch anyway...
- Scoundreller 9y agoIt could be one back-end, with the malware authors paying a cut to the spearfishers. The spearfishers could monitor the bitcoin address to ensure they get the right cut. Some level of trust would be involved. I think the spearfishing industry and the malware writing industry aren't one and the same. The former is the marketing department, the latter is the tech department.
- desas 9y agoThey can offer, they can accept payment. Doesn't mean they will actually decrypt the files.
- thewarrior 9y agoWho is doing this knowing fully well that GHCQ , FBI and possibly even the NSA are hard at work trying to get them ? These people are going down . No doubt about it.
- ben_jones 9y agoUnless it was the FSB. Then its 'aw shucks the russian hackers did it again'.
- spydum 9y agoI think you vastly overstate this. While I can't speak to GHCQ, I really don't think NSA has a charter to pursue justice. The FBI may be, but I'm just not convinced they will move quick enough to matter (they do move, but only against a large established organization).
- nthcolumn 9y agoI'd be surprised if the NSA were just sitting back watching their code fly around the internet.
- nthcolumn 9y agoThis is what happens when spambot skiddies accidentally acquire a treasure-trove of NSA tools via a C2 server they have pwned. They failed to sell ('broker') them as nobody was stupid enough to touch them, they failed to blackmail with them (omg what a bad move), then they failed to weaponise their own gear with them (wcry 1.0 in February), and even though wcry 2.0 is widespread and very disruptive, really they failed again only making 50k out of how many infections? They have only 3 bitcoin addresses making it obvious nobody is getting decrypted (how do they know who has paid?) or there is a single master key which will be found soon, their sandbox detector is a killswitch. Larry, Moh and Curly have invited a world of pain upon themselves - as well as probably killing people on NHS - they also infected Moscow Police - so FSB too. Definitely, would not like to be them.
- 21 9y ago
- MilnerRoute 9y agoTwo researchers said they found a variant with a kill switch. https://motherboard.vice.com/en_us/article/round-two-wannacry-ransomware-that-struck-the-globe-is-back https://motherboard.vice.com/en_us/article/round-two-wannacr...
- matthewbauer 9y ago*without
- Sir_Cmpwn 9y agoMaybe it would be better to wait until the attackers registered the domain, then sopoeana the registrair for their account info.
- SXX 9y agoDo you seriously expect criminals are dumb enough to leave any useful information there?
- Nrsolis 9y agoYou'd be very surprised at how dumb criminals can be. Nobody is smart at everything 100% of the time.
- Sir_Cmpwn 9y agoDo you seriously expect most criminals are intelligent?
- TheSpiceIsLife 9y agoIn this context criminals are a person or persons who have created ransomware which, in less than three days has infecting more than 230,000 computers in 150 countries, demanding ransom payments in bitcoin in 28 languages. The meth dealer two houses down who serves people out his front window probably isn't thinking straight. What we're dealing with here is a different category of thinking.
- 21 9y agoThe ransom note in 28 languages can be very well taken from other ransomware pieces, just like the ransomware code itself. It's not like someone will sue for copyright infringement.
- sillysaurus3 9y agoFor perspective, they've netted a measly $39,000 / 21 BTC so far. https://www.reddit.com/r/Bitcoin/comments/6axuzs/wannacry_wcry_wannacrypt_bitcoin_addresses/ https://www.reddit.com/r/Bitcoin/comments/6axuzs/wannacry_wc...
- rurban 9y agoThey will get them following the payments soon enough.
- acd 9y agoThese systems would be better of security wise if they would use the latest open source operating system including the embedded code. The damage this will cause to embedded systems is distasteful.
- eriknstr 9y agoI'm am very much in favor of open source always but let's not pretend that embedded systems don't end up with out of date software just because it's open source. In the case of WannaCrypt0r, the vulnerability had already been fixed by Microsoft but those who were hit hadn't patched because as discussed elsewhere applying patches may break things so some postpone or ignore it. Same thing could have happened to a system running Linux.
- Aldo_MX 9y agoThank you for your thoughtful comment... People who get drunk with the Linux cool-aid are really tiresome. They believe they're safe by using Linux, and completely disregard good security practices with their windows-bashing speech.
- taejo 9y agoAIUI they would have been better off if they'd used the latest of any operating system.
- dralley 9y agoIf you're talking about an MRI machine, the proper drivers may not exist for a current operating system. The absolute last thing you want is for an image to show up differently on the new system due to changes to OpenGL or something.
- kps 9y agoIf you're talking about an MRI machine, and you put it on the goddamned internet, $300 is actually a pretty cheap security tutorial.
- alanfalcon 9y agoJust wait until this hits the files of a Russian mob who then take some Americans hostage and fly to China and end up entangled in an islamic terrorist plot. 'Cause then we're in for a very long and drawn out story involving MI6, the CIA, Canadian smuggling routes, and Christian Isolationist 2nd Amendment fanatics.
- huhtenberg 9y agoPsst, downvoters - https://en.wikipedia.org/wiki/Reamde https://en.wikipedia.org/wiki/Reamde
- spitfire 9y agoCould I purchase the movie rights to that? Could seriously make a good mini-series if done seriously. Ala John Le Carré.
- kps 9y agoI did get the impression when reading Reamde that it was written with a miniseries adaptation in mind.
- Animats 9y agoIf they attach this to a new exploit, instead of an old one that targets Windows XP, there's going to be a real problem.
- boomboomsubban 9y agoThe exploit hit everything pre Windows 10, but yes if they find a completely unknown exploit this could be worse?
- nthcolumn 9y agoAnyone got XP infections? It is being touted around as XP (for various reasons) but wcry 2.0 affects newer versions of Windows.
- theincredulousk 9y agoWhy would they keep releasing it, and release it in the first place, with such a simple kill-switch. Doesn't make much sense. Reminds me of the Archer episode where Cyril plants the computer virus and was going to be the hero by "fixing" it.
- celticninja 9y agoIt's possible that people are taking the code, modifying it to add in a new kill switch address, change the bitcoin address and leave every thing else as it is. Usually because they don't understand the code but can do a ctrl+f, delete and replace with the necessary info. Script kiddies of the malware world.
- deleted 9y ago[deleted]
- blaqkangel 9y agoWe were warned this would happen but it's interesting to me that we have detected new variants that include the same type of naive kill switch. I'm not well versed in information security, so my question is whether this means attackers tried another wave by simply changing the kill switch domain or were there several variants used for the initial attack?
- sinaa 9y agoAre these new variants new compiles? Is it possible that multiple variants with randomly-generated kill-switches are being automatically generated?
- excalibur 9y ago> A new variant with no kill-switch recovered by Kaspersky as a virustotal.com upload — not detected in the Wild. Uploaded to virustotal MEANS found in the wild. That's what admins do when they discover things.
- phaus 9y agoI don't know if this one was detected in the wild or not (99% chance it was), however, malware authors occasionally use Virustotal too.
- svens_ 9y agoThere are virustotal clones that don't send back results to the vendors. This is specifically done to prevent that kind of problem.
- thunderrabbit 9y agoMaybe it was only caught by honeypots and turned in from there.
- j_s 9y agoA lot of stuff is uploaded to VirusTotal by automated systems ("in the wild") so it is often a case of "If a tree falls in a forest and no one is around to hear it, does it make a sound?"
- sonium 9y agoI really am a bit puzzeled by the killswitches. Why does WannaCry have this functionality in the first place? It sounds almost ironically like a hollywood villain mistake.
- mattmanser 9y agoIn this thread or another someone said it was a kill switch for testing it in a sandbox, probably used while developing the code.
- bcjordan 9y agoSomeone said it was to avoid behavior analysis by security researchers
- codedokode 9y agoOr analysis by antiviruses that have can run programs in sandboxes too.
- Thrillington 9y agoThey're more analysis defeaters than killswitches. Some testbeds will respond to all dns lookups as valid. If this is the case the binary assumes its in a testbed and exits to avoid analysis.
- ckaygusu 9y agoI understand that it serves to defeat analysis, but... it sounds like it could be trivially circumvented. Why bother in the first place?
- fian 9y agoWhich makes me think there might be utility in always running Windows (or other OSes) in a VM. If the malware assumes VMs are bad and self exit in response, then it should be safer to run everthing in a VM. A side benefit would be you can perform snapshot backups and easily migrate your main environment to new hardware.
- rnhmjoj 9y agoI don't get it: why are the using using many fake but valid domains? Wouldn't a non-existing TLD do exactly the same thing while being impossible to register by anyone trying to stop the malware?
- mef 9y agoshh
- kuschku 9y agoOr even just sha256(unixtime().rand()).com Or a domain in a TLD that allows only second level TLDs (such as some of the commonwealth countries).
- nathan_f77 9y ago> sha256(unixtime().rand()).com Yep, that's the way to do it.
- kijin 9y agoThat gives you 64 characters to the left of the dot. The maximum number of characters allowed in any single component of a domain name is 63. Some systems might react in unexpected ways if you try to resolve an invalid domain name, making your check unreliable. Better use md5 or sha1.
- kuschku 9y agoWell, that'd be an implementation detail, but the general concept stays the same. And is superior to hardcoding.
- TylerE 9y agoIf it's not registerable it's not functional as a kill switch?
- tjohns 9y ago
- rhubarbcustard 9y agoWhat's special about WannaCry that has made this such a widespread thing? I presume there's has been plenty of malware for a while that can propagate itself around a network of unpatched old Windows machines and people have been trying to get users to clicks on emails to infect themselves for years. So why now? What's so special now?
- pishpash 9y agoThis time you have to pay money. That perks people up.
- rhubarbcustard 9y agoHasn't that been a common thing in bitlocker malware for ages too? Did they just manage to craft so really persuasive emails this time?
- CydeWeys 9y agoWannaCry is a worm. It does not require people to click on anything in emails to be infected. It scans for vulnerable computers and infects them directly over the network.
- deleted 9y ago[deleted]
- toyg 9y agoMost vulnerabilities are limited to old releases or new releases, whereas "EternalBlue" affected all Windows versions across the board. The patches are less than two months old, so there was a chance to exploit old machines and newer ones that slow IT might have left vulnerable. This is why someone invested a bit in making the exploit wormable and unleashed it, the potential pool of victims was bigger than usual.
- boomboomsubban 9y agoIt's not "old Windows machines," it's XP to Server 2012. It also isn't clear that it came from e-mails yet. It's widespread, easy to propagate, and is hitting the places most affected by Windows 10's advanced telemetry and hidden update.
- nathan_f77 9y agoI think it's hilarious how these "kill switches" are supposedly meant to detect sandboxes, to make it harder for security researchers to analyze the malware. While actually making it easy for security researchers to completely disable all installations around the entire world. That's just what I heard, but it makes sense. There are far more sane ways to implement a kill switch without using unregistered domains. (For instance, using a registered domain.)
- bichiliad 9y agoThe point of the killswitch is to detect if the worm is running inside a sandbox. Some sandboxes will resolve any domain you try to ping, so an easy way to detect this is to ping a non-existent domain name. I'm not totally sure how pinging an existing domain would give you the same behavior, but doing something like checking a handful of random non-existent domains from a large list could do the trick. From the sounds of it, it seems like the researchers didn't expect the killswitch to disable the malware outside of the sandbox any more than the author of the malware did[0]. [0]: https://www.malwaretech.com/2017/05/how-to-accidentally-stop-a-global-cyber-attacks.html https://www.malwaretech.com/2017/05/how-to-accidentally-stop...
- sengork 9y agoI would like to know whether the decrypted data can be trusted again in case the contents have been somewhat changed. Then again it is much better than not having any data at all in some cases...
- daxfohl 9y agoCould the 51% "bug" in bitcoin actually be used to an advantage here? A 51% vote to invalidate all these transactions? I assume it doesn't work like that but figured I would ask.
- HappyTypist 9y agoNo, no one will agree to reverse transactions in bitcoin. When half a billion dollars got lost in MtGox no one agreed either.
- Mandatum 9y agoIt's a feat that could be leveraged, but the likelihood and work to do so would outweigh actually pulling it off. If this attack occurred against, for example, the CN government, they may step in and force miners to invalidate. This scale is world-wide, there's no loss of public image and the amount of BTC is very small in the scheme of things.
- nebula 9y agoI am trying to understand impact of crypto currency. Sorry for my ignorance, and or impertinence. 1. Is it possible to run such large scale ransom demands without cryptocurrency? 2. Do we know if the attacker is using a single BTC wallet, or if ransoms are being collected in a distributed fashion. 3. Is it possible for BTC n/w to hijack BTCs going to the ransom wallet(s). That is to say collectively overwrite/override the transactions and may be reroute the coins to some non-profit wallet? I know it will be a very bad precedent, but I am trying to understand if it is technically possible.
- simcop2387 9y ago> 3. Is it possible for BTC n/w to hijack BTCs going to the ransom wallet(s). No, by design that's not allowed as part of the protocol for bitcoin. Every transaction must be signed by the private key for that address in order to be valid. You could in theory do it if you can get a majority of the miners to agree to the change in the protocol but it wouldn't happen since it'd require forking the whole blockchain to insert new transactions without the private key. And then you'd have to get everyone to agree on where those would go.
- nebula 9y agoThanks for the response. I should have been more explicit, but when I said BTC n/w I meant a consensus sort of thing from users/miners. Thanks for your explanation regarding the need of a fork to achieve this even with consensus.
- kul_ 9y agoIs there analysis on what encryption algorithm was being used? And how the payment confirmation switch works on the malware. Is it possible instead of patching the OS, to release a patch which patches the malware binary to no-op the payment switch?
- btown 9y agoCould a grey hat create a self propagating but non-ransoming variant that inoculated target machines against its more malicious brethren? Seems like something a state actor might want to do.
- ComodoHacker 9y agoYou mean bundle and forcefully install MS patches? This would require reboot which AFAIK can't be done without user's action (if not using undocumented APIs).
- Sunset 9y agoMaybe install itself as a network packet filter and work as temporary firewall until the machine is restarted?
- gruturo 9y ago> You mean bundle and forcefully install MS patches? This would require reboot which AFAIK can't be done without user's action (if not using undocumented APIs). Considering you're using a vulnerability to forcefully inoculate systems, and you gained admin if not Ring0 privileges, you could trivially "reboot" the box by just crashing it, no APIs required. You could even be nice and check if there are applications with open files, or schedule it only when the user has been idle for a while, and only do it during the usual hours of inactivity (Windows 10 even has a control panel section to choose them). Or, you could just open a dialog box, masquerade as a legitimate update and ask for user consent. You are an important security update after all, just a fairly unconventional one.
- user5994461 9y agoshutdown -f -r -t 60 force reboot in 60 seconds. A very well documented windows command available for more than 15 years. Bonus: Also works remotely, there is a flag to give a remote computer name.
- nolok 9y agoYeah then some bugs in your code or unplanned set of conditions amongst the bazillion xp computers out there lead your code to kill someone by failure of some critical NHS equipment, or worse, to lose a lot of money! "but I meant good "is totally going to save you then.
- bubblethink 9y agoThis makes me think of a different kind of a kill-switch. What if the OS itself is required to have a kill-switch that triggers once it goes out of support, and it prevents regular use unless the admin goes through some serious hoops to override. It at least squarely puts the blame on 1) Orgs that willfully override v/s passively ignoring to update 2) OS vendors who have really short support cycles (~1 year for most android phones)
- column 9y agoif you put a killswitch in Windows that can be triggered from Redmond, I guarantee you it will be used by virus of sorts
- yardstick 9y agoAnyone know someone at the Tor Project? Based on a breakdown I read, it downloads the Tor client from https://dist.torproject.org/torbrowser/6.5.1/tor-win32-0.2.9.10.zip https://dist.torproject.org/torbrowser/6.5.1/tor-win32-0.2.9... It would be simple to rename this link (or perform a referer check or something else to stop automated downloads), at least temporarily. Yes, the malware authors will release an update with the different URL (or another hosting site entirely, or embedded), but at least it would provide time for vulnerable users to install patches. Especially now that Microsoft has released a patch for XP. (I'm basing this URL info on the breakdown found at https://www.bleepingcomputer.com/news/security/wannacry-wana-decryptor-wanacrypt0r-technical-nose-dive/ https://www.bleepingcomputer.com/news/security/wannacry-wana...)
- wcfields 9y agoI wondered that exact same thing on Friday; thanks for pointing it out.