5 ms·
I really am a bit puzzeled by the killswitches. Why does WannaCry have this functionality in the first place? It sounds almost ironically like a hollywood villa
by sonium 9y ago
I really am a bit puzzeled by the killswitches. Why does WannaCry have this functionality in the first place? It sounds almost ironically like a hollywood villain mistake.
- mattmanser 9y agoIn this thread or another someone said it was a kill switch for testing it in a sandbox, probably used while developing the code.
- bcjordan 9y agoSomeone said it was to avoid behavior analysis by security researchers
- codedokode 9y agoOr analysis by antiviruses that have can run programs in sandboxes too.
- Thrillington 9y agoThey're more analysis defeaters than killswitches. Some testbeds will respond to all dns lookups as valid. If this is the case the binary assumes its in a testbed and exits to avoid analysis.
- ckaygusu 9y agoI understand that it serves to defeat analysis, but... it sounds like it could be trivially circumvented. Why bother in the first place?
- fian 9y agoWhich makes me think there might be utility in always running Windows (or other OSes) in a VM. If the malware assumes VMs are bad and self exit in response, then it should be safer to run everthing in a VM. A side benefit would be you can perform snapshot backups and easily migrate your main environment to new hardware.
- kchr 9y agoYou might wanna take a look at Qubes OS, which tries to provide such workflow in a nicely packaged distribution: https://www.qubes-os.org/ https://www.qubes-os.org/
- sowbug 9y agoFrom https://www.malwaretech.com/2017/05/how-to-accidentally-stop-a-global-cyber-attacks.html https://www.malwaretech.com/2017/05/how-to-accidentally-stop..., posted earlier: <quote> In certain sandbox environments traffic is intercepted by replying to all URL lookups with an IP address belonging to the sandbox rather than the real IP address the URL points to, a side effect of this is if an unregistered domain is queried it will respond as it it were registered (which should never happen). I believe they were trying to query an intentionally unregistered domain which would appear registered in certain sandbox environments, then once they see the domain responding, they know they’re in a sandbox the malware exits to prevent further analysis. This technique isn’t unprecedented and is actually used by the Necurs trojan (they will query 5 totally random domains and if they all return the same IP, it will exit); however, because WannaCrypt used a single hardcoded domain, my registration of it caused all infections globally to believe they were inside a sandbox and exit... thus we initially unintentionally prevented the spread and further ransoming of computers infected with this malware. Of course now that we are aware of this, we will continue to host the domain to prevent any further infections from this sample. </quote>
- rl3 9y ago>I believe they were trying to query an intentionally unregistered domain which would appear registered in certain sandbox environments, then once they see the domain responding, they know they’re in a sandbox the malware exits to prevent further analysis. On the face of it, that sounds like amateur hour. At the end of the day virtual environments can be configured to fool the malware in whatever fashion is required. However, I can see that method buying small amounts of time for the worm to continue infecting targets, which I suppose has utility.
- Moru 9y agoAs they say, the guard has to see everything, every time. The burglar only has to succeed once.
- reitanqild 9y ago<tinfoil hat on>: Alternative: It is not a ransomware operation but a counter-intel ooeration against security researchers. This is starting to look dumb now, maybe researchers will let their guard down and blog even more about internal procedures? Or maybe there is a hidden payload (Just a crazy idea based on the ovservation that there are multiple versions with corrupted payloads)