This is good (and not JUST because they call it WannaCry and now me and @malwareunicorn can retire happy http://blog.talosintelligence.com/2017/05/wannacry.html …
-
-
Worth noting - anybody could start it again by.. changing the domain, and moving some infrastructure chess pieces around. So patch SMB.
-
Change it to insert, or replace any character in the domain with, a period
End of conversation
New conversation -
-
-
It was actually quite stupid to do that, it raises questions on who did it and for what purpose. Diversion maybe?
-
Tweet unavailable
-
I doubt it. Sandbox evasion? Who knows. It's pretty shitly done.
End of conversation
New conversation -
-
-
Next release will probably change (or remove) the kill switch and re spread
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
So this is a total novice Q: But why build a kill switch into a virus, tied to a seemingly random domain? What's the point?
-
One possibility: some malware analysis platforms respond to all domain requests to log traffic. Could be poorly executed anti-analysis...
-
Meaning if the malware detected a response to a domain known to not exist, it could mean it was being analyzed and would shut down.
- 1 more reply
New conversation -
-
-
Good tracking map of current status https://intel.malwaretech.com/botnet/wcrypt
@Defensivesec@PaulSpainThanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
yep, its a pause not the end, I believe.
-
yeah, you could just hexedit a new domain. \o/
-
That's what I told a co-worker.
End of conversation
New conversation -
-
-
Noobs.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
This looks like decompiled C, how did you get access ?
End of conversation
New conversation -
-
There is not wake time for that. Were they a direct target by engineering or just a random target? If direct than US hospitals are 24hr too.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
a global DSN redirect to a well forged site ?
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Are those lines part of the NSA's original? If yes, would mean NSA knew how to stop it !
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.