4 ms·
I like how this malware writer/researcher claims he "found" the address and "miraculously saved" everyone by grabbing the domain. Not sure why everyone says he
by Traytorz 9y ago
I like how this malware writer/researcher claims he "found" the address and "miraculously saved" everyone by grabbing the domain.
Not sure why everyone says he isn't the malware writer. What proof do you have that he didn't write it? Maybe he left a trail that you missed.
- tankenmate 9y agoAn extraordinary claim requires an extraordinary proof.
- madez 9y agoYou don't need to proof anything to raise questions. The comment didn't claim anything, it was just a sceptical one. We should cheer those.
- celticninja 9y agoHe found the address in the source code of the ransomware, any researcher could have found it. He even said himself that when he found it in the source code and saw it was unregistered he registered it to see what would happen. As it turned out it stopped infections from occurring. Not to say that he isnt the malware writer but your use of quote marks makes me think you have no idea about what happened and havent looked into it, just made some "wild assumptions".
- Avery3R 9y agoPretty sure it was in disassembled machine code, not source code.
- jtl999 9y agoI have taken the liberty to download a sample of WannaCry and I can see the "killswitch" domain just running strings on the binary. $ strings Downloads/24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c.bin |grep .com __p__commode http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
- scrapbird 9y agoThe firm he works for literally pays him to track size and scale of malware outbreaks. Whats the best way to do that? Look for domains the malware attempts to communicate with and register them, pointing them at the firm's sinkhole server. From there the server can generate reports on how many connections it gets and from where. He did what he would of done to any malware once he found an unregistered domain, he registered it. He didn't realise the malware was using that domain as a killswitch.