Jump to content

[3rd Update]WCry ransomwsre has possible links to Lazarus Group & PRNK

Master Disaster
1 hour ago, TheReal1980 said:

This is the problem with Windows. Because so many use them they are more likely to get problems like this. This is one of many reasons why I use Macs for my business as I want to minimize the risks and the "Apple Tax" is fine as I gladly pay it.

That is a pretty strange business decision to say the least, and one that could be viewed in more ways than one. What if I said to you that you could be viewed to less at risk, as these kind of vulnerabilities could take much longer to be discovered on MacOS because less people use them? Meaning you could be at risk for much longer.

 

Not saying this is the case, but saying there is two sides to the coin.

System/Server Administrator - Networking - Storage - Virtualization - Scripting - Applications

Link to comment
Share on other sites

Link to post
Share on other sites

"Why don't you submit your work on time?"
"Ransomware attack sir...."


Anyway I just did system backup, f*ck me.

Where I hang out: The Garage - Car Enthusiast Club

My cars: 2006 Mazda RX-8 (MT) | 2014 Mazda 6 (AT) | 2009 Honda Jazz (AT)


PC Specs

Indonesia

CPU: i5-4690 | Motherboard: MSI B85-G43 | Memory: Corsair Vengeance 2x4GB | Power Supply: Corsair CX500 | Video Card: MSI GTX 970

Storage: Kingston V300 120GB & WD Blue 1TB | Network Card: ASUS PCE-AC56 | Peripherals: Microsoft Wired 600 & Logitech G29 + Shifter

 

Australia 

CPU: Ryzen 3 2200G | Motherboard: MSI - B450 Tomahawk | Memory: Mushkin - 8GB (1 x 8GB) | Storage: Mushkin 250GB & Western Digital - Caviar Blue 1TB
Video Card: GIGABYTE - RX 580 8GB | Case: Corsair - 100R ATX Mid Tower | Power Supply: Avolv 550W 80+ Gold

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, leadeater said:

Well Microsoft seems rather pissed off at the NSA/CIA, this is from the President and Chief Legal Officer of Microsoft.

 

https://blogs.microsoft.com/on-the-issues/2017/05/14/need-urgent-collective-action-keep-people-safe-online-lessons-last-weeks-cyberattack/

Fool me once, shame on you, fool me twice shame on me. You really hate black theme users. Can't deny it. 

The ability to google properly is a skill of its own. 

Link to comment
Share on other sites

Link to post
Share on other sites

I'm starting to think that Microsoft is making all this so they could push creators update.

|EVGA 850 P2| |1440p PG279Q| |X570 Aorus Extreme| |Ryzen 9 3950x WC| |FE 2080Ti WC|TridentZ Neo 64GB| |Samsung 970 EVO M.2 1TB x3

 |Logitech G900|K70 Cherry MX Speed|  |Logitech Z906 |  |HD650|  |CaseLabs SMA8 (one of the last ones made)

 

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, Foxxer said:

I'm starting to think that Microsoft is making all this so they could push creators update.

that would be stupid, this is damaging trust in the platform not building it. 

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, vorticalbox said:

that would be stupid, this is damaging trust in the platform not building it. 

 Lost trust in those who didn't have trust and confidence in Microsoft with updates? Our didn't have Trust in Microsoft's decision to dump old OS's? Considering the vulnerability had already been patched in W10, i don't really blame Microsoft.

 

I'm not a business owner so I cannot say exactly how any trust has been lost from businesses; however, the company work for hasn't been rocked. We were proactive in fixing vulnerabilities. Yes, upgrading servers can be a pain in the butt; however,  the alternative isn't much better.

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, vorticalbox said:

that would be stupid, this is damaging trust in the platform not building it. 

Well it would be if MS weren't basically pointing a giant arrow at the NSA HQ right now.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, vorticalbox said:

that would be stupid, this is damaging trust in the platform not building it. 

You still trust in MS? Bad choice...

Link to comment
Share on other sites

Link to post
Share on other sites

23 hours ago, jagdtigger said:

You still trust in MS? Bad choice...

No one does, but trying to blame them is stupid. If they wanted to abandon win 7 and XP completely, then they wouldn't have given it an emergency patch. What your saying has no proof and is pure conspiracy. 

Please quote our replys so we get a notification and can reply easily. Never cheap out on a PSU, or I will come to watch the fireworks. 

PSU Tier List

 

My specs

Spoiler

PC:

CPU: Intel Core i5-6600K @4.8GHz
CPU Cooler: Noctua NH-U14S 
Motherboard:  ASUS Maximus VIII Hero 
GPU: Zotac AMP Extreme 1070 @ 2114Mhz
Memory: Corsair Vengeance LPX 16GB (2 x 8GB) DDR4-2400 
Storage: Samsung 850 EVO-Series 500GB 
Storage: Western Digital Caviar Blue 1TB
Case: Cooler Master MasterCase Pro 5 
Power Supply: EVGA 750W G2

 

Peripherals 

Keyboard: Corsair K70 LUX Browns
Mouse: Logitech G502 
Headphones: Kingston HyperX Cloud Revolver 

Monitor: U2713M @ 75Hz

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Bouzoo said:

Fool me once, shame on you, fool me once shame on me. You really hate black theme users. Can't deny it. 

Hate would imply intent, I just don't think about that at all ;).

Link to comment
Share on other sites

Link to post
Share on other sites

if you want to annoy me, then join my teamspeak server ts.benja.cc

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, vorticalbox said:

that would be stupid, this is damaging trust in the platform not building it. 

MS = Transparency much

|EVGA 850 P2| |1440p PG279Q| |X570 Aorus Extreme| |Ryzen 9 3950x WC| |FE 2080Ti WC|TridentZ Neo 64GB| |Samsung 970 EVO M.2 1TB x3

 |Logitech G900|K70 Cherry MX Speed|  |Logitech Z906 |  |HD650|  |CaseLabs SMA8 (one of the last ones made)

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, TheReal1980 said:

This is the problem with Windows. Because so many use them they are more likely to get problems like this. This is one of many reasons why I use Macs for my business as I want to minimize the risks and the "Apple Tax" is fine as I gladly pay it.

you do realize ransomware affects Macs too right?....Paying more doesnt protect you.

 

This is not an argument of windows vs mac. This is about people keeping their shit up to date. 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, mynameisjuan said:

you do realize ransomware affects Macs too right?....Paying more doesnt protect you.

 

This is not an argument of windows vs mac. This is about people keeping their shit up to date. 

macOS is susceptible to malware and ransomware as well, however his point is that there is less of it due to Windows exploits being more profitable.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, mynameisjuan said:

you do realize ransomware affects Macs too right?....Paying more doesnt protect you.

 

This is not an argument of windows vs mac. This is about people keeping their shit up to date. 

 

I second this. It is still possible for developers to create this on OSX it's just that majority of the market are on windows so when people are making it they mostly prioritise it for windows. But the developers who want to get everyone would even create a Linux version

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

Can someone answer this question:

 

Can your system get infected "just sitting there" on its own, or does someone on your network have to get compromised first thru email / whatever?  No article I've read explains whether you need to be worried if you know all the computers on your network.

Workstation:  14700nonK || Asus Z790 ProArt Creator || MSI Gaming Trio 4090 Shunt || Crucial Pro Overclocking 32GB @ 5600 || Corsair AX1600i@240V || whole-house loop.

LANRig/GuestGamingBox: 13700K @ Stock || MSI Z690 DDR4 || ASUS TUF 3090 650W shunt || Corsair SF600 || CPU+GPU watercooled 280 rad pull only || whole-house loop.

Server Router (Untangle): 13600k @ Stock || ASRock Z690 ITX || All 10Gbe || 2x8GB 3200 || PicoPSU 150W 24pin + AX1200i on CPU|| whole-house loop

Server Compute/Storage: 10850K @ 5.1Ghz || Gigabyte Z490 Ultra || EVGA FTW3 3090 1000W || LSI 9280i-24 port || 4TB Samsung 860 Evo, 5x10TB Seagate Enterprise Raid 6, 4x8TB Seagate Archive Backup ||  whole-house loop.

Laptop: HP Elitebook 840 G8 (Intel 1185G7) + 3060 RTX Thunderbolt Dock, Razer Blade Stealth 13" 2017 (Intel 8550U)

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, AnonymousGuy said:

Can someone answer this question:

 

Can your system get infected "just sitting there" on its own, or does someone on your network have to get compromised first thru email / whatever?  No article I've read explains whether you need to be worried if you know all the computers on your network.

If there is no system exposed to the internet for SMB (tcp 445) then you would need that initial infection point triggered by human error, after that it will spread across the network.

 

Edit:

This is why you should NEVER port forward SMB ever, use a VPN or RDP or anything just never expose SMB to the internet.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, AnonymousGuy said:

Can someone answer this question:

 

Can your system get infected "just sitting there" on its own, or does someone on your network have to get compromised first thru email / whatever?  No article I've read explains whether you need to be worried if you know all the computers on your network.

 

AFAIK it just searches for anything connected to the internet with the EnternalBlue exploit and then it tries to exploit it.

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, djdwosk97 said:

macOS is susceptible to malware and ransomware as well, however his point is that there is less of it due to Windows exploits being more profitable.

Actually if you are not logged in as a admin (like unix), keep your system up to date and have AV (or atleast keep defender up to date and running), windows is pretty close to as safe and secure. Most infections are from out of date pcs running full admin access. But since people dont follow basic security rules, yeah it happens way more on windows. 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, leadeater said:

If there is no system exposed to the internet for SMB (tcp 445) then you would need that initial infection point triggered by human error, after that it will spread across the network.

 

Edit:

This is why you should NEVER port forward SMB ever, use a VPN or RDP or anything just never expose SMB to the internet.

My ISP looks like they don't pass thru port 445 anyways.  We're good.

Workstation:  14700nonK || Asus Z790 ProArt Creator || MSI Gaming Trio 4090 Shunt || Crucial Pro Overclocking 32GB @ 5600 || Corsair AX1600i@240V || whole-house loop.

LANRig/GuestGamingBox: 13700K @ Stock || MSI Z690 DDR4 || ASUS TUF 3090 650W shunt || Corsair SF600 || CPU+GPU watercooled 280 rad pull only || whole-house loop.

Server Router (Untangle): 13600k @ Stock || ASRock Z690 ITX || All 10Gbe || 2x8GB 3200 || PicoPSU 150W 24pin + AX1200i on CPU|| whole-house loop

Server Compute/Storage: 10850K @ 5.1Ghz || Gigabyte Z490 Ultra || EVGA FTW3 3090 1000W || LSI 9280i-24 port || 4TB Samsung 860 Evo, 5x10TB Seagate Enterprise Raid 6, 4x8TB Seagate Archive Backup ||  whole-house loop.

Laptop: HP Elitebook 840 G8 (Intel 1185G7) + 3060 RTX Thunderbolt Dock, Razer Blade Stealth 13" 2017 (Intel 8550U)

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, mynameisjuan said:

Actually if you are not logged in as a admin (like unix), keep your system up to date and have AV (or atleast keep defender up to date and running), windows is pretty close to as safe and secure. Most infections are from out of date pcs running full admin access. But since people dont follow basic security rules, yeah it happens way more on windows. 

 

 

I'm not even commenting on the security of either platform (and neither was @TheReal1980)......Less people use macOS. Less businesses use macOS. Developing an attack against macOS is less profitable. Therefore there are less attacks against macOS.

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

In the interest of security, I shall sacrifice a couple GB of my data plan and update my systems.   :(

 

 

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×