Jump to content

[3rd Update]WCry ransomwsre has possible links to Lazarus Group & PRNK

Master Disaster
18 hours ago, ashypanda said:

pulling the power cord might not work just as the systems affected would be on UPS's, pouring gas on them and torching them might be more effective.

But they have a fire retardant coating, so fire won't work. Best way is to just use a EMP.

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, DeadEyePsycho said:

It actually depends on the user account that got infected since ransomware really only use exploits for the initial infection onto a network (the grand majority at least, especially non-targeted ones). Whatever the user has write access to, the virus will encrypt. 

This is why on my network no one user has complete access to everything. And the admin accounts dont have any access to networked directories. Limits what can get hit. 

CPU: Amd 7800X3D | GPU: AMD 7900XTX

Link to comment
Share on other sites

Link to post
Share on other sites

Glad I updated my backup, not as though my systems are on the Internet much. 

 

How much data do updates require nowadays. My systems are behind by a number of months, and will have to use my mobile data plan to do the updates (which is why they're so far behind btw). 

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

40 minutes ago, Master Disaster said:

When would you say would be the right time for MS to do the "still think forced updates are a bad idea" press conference?

They really wouldn't be so bad if they didn't go through the whole process of notifying you of an update and then restarting your computer so damn quickly. Case in point, yesterday I was using my computer as normal, got up to go take a piss, came back 2 minutes later and my computer was in the middle of restarting/updating, with me having no notification prior. Luckily I wasn't in the middle of a project (had just finished) or I would've been very, very pissed off right now. If they had an option that said something like, "Don't bother me until [Date+Time]" that would be helpful, but they don't, and "Active Hours" are completely useless. Not having any choice when your computer updates/restarts whatsoever makes people forced to just turn updates off entirely, leading to (or at least not helping prevent) a lot of these problems we're currently seeing.

Link to comment
Share on other sites

Link to post
Share on other sites

That BBC article got the name wrong. It's WanaCrypt0r, not wannacryptor.

 

Below is the name for deceyptor

 

Ransomware-2.png

 

 

 

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, NumLock21 said:

That would be indeed scray, but most backup should be done on tape drives not SSD or HDD

Knowing the public sector in the UK it is probably done on punch cards

40 minutes ago, ESPImperium said:

This is freaking scary. My dad is getting his second blood test results on Monday and if our doctors are hit, we may not get them.

 

However, as someone who works for a major UK supermarket, our systems have venerability in them, we run with Windows 2000 and 7 32bit across 2 server systems. I am worried that one day we will be affected and will have to shut for unknown lengths of time.

 

I have spent most of the night explaining to my Dad what things mean, and will do so tomorrow at work I think to the folk who don't know computer speak.

I noticed the other day while one was rebooting the self-service checkouts in my local Sainsbury's run XP.

 

I guess updating hardware for a large organisation is horrendously expensive, and will be a tough sell until it's too late for some.

Link to comment
Share on other sites

Link to post
Share on other sites

So how far is this going? I just saw on the news that stuff like government systems have been compromised and all in my country, what world are we living xD

Personal Desktop":

CPU: Intel Core i7 10700K @5ghz |~| Cooling: bq! Dark Rock Pro 4 |~| MOBO: Gigabyte Z490UD ATX|~| RAM: 16gb DDR4 3333mhzCL16 G.Skill Trident Z |~| GPU: RX 6900XT Sapphire Nitro+ |~| PSU: Corsair TX650M 80Plus Gold |~| Boot:  SSD WD Green M.2 2280 240GB |~| Storage: 1x3TB HDD 7200rpm Seagate Barracuda + SanDisk Ultra 3D 1TB |~| Case: Fractal Design Meshify C Mini |~| Display: Toshiba UL7A 4K/60hz |~| OS: Windows 10 Pro.

Luna, the temporary Desktop:

CPU: AMD R9 7950XT  |~| Cooling: bq! Dark Rock 4 Pro |~| MOBO: Gigabyte Aorus Master |~| RAM: 32G Kingston HyperX |~| GPU: AMD Radeon RX 7900XTX (Reference) |~| PSU: Corsair HX1000 80+ Platinum |~| Windows Boot Drive: 2x 512GB (1TB total) Plextor SATA SSD (RAID0 volume) |~| Linux Boot Drive: 500GB Kingston A2000 |~| Storage: 4TB WD Black HDD |~| Case: Cooler Master Silencio S600 |~| Display 1 (leftmost): Eizo (unknown model) 1920x1080 IPS @ 60Hz|~| Display 2 (center): BenQ ZOWIE XL2540 1920x1080 TN @ 240Hz |~| Display 3 (rightmost): Wacom Cintiq Pro 24 3840x2160 IPS @ 60Hz 10-bit |~| OS: Windows 10 Pro (games / art) + Linux (distro: NixOS; programming and daily driver)
Link to comment
Share on other sites

Link to post
Share on other sites

Does anyone know if there is any source code available from anywhere for this?

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, TAHIRMIA said:

Does anyone know if there is any source code available from anywhere for this?

I assume so, since it seems to be in use 

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, goodtofufriday said:

Currently EVERY IT admin in the world (myself included)

 

And when someone gets hit 

 

 

1 hour ago, TAHIRMIA said:

I think they did apparently patch this in march

 

1 hour ago, M.Yurizaki said:

So other than a vulnerability in Windows that was patched last month that was exploited by NSA/CIA malware, is there any thing else we know about that can mitigate infection?

 

2 hours ago, Ryan_Vickers said:

There's lots of things that "should" be done, and if they had been, we wouldn't be talking about this story right now.

 

1 hour ago, Master Disaster said:

 

Yeah they did, I think the main issue is most of the affected systems would come under Microsoft's corporate edition target rather than consumer edition and in these cases updates are normally handled by internal admins anyway. Forced updates wouldn't be relevant.

Bleeping Computers recently put out a fairly detailed article on how this attack is working as well as what it's targeting.

 

https://www.bleepingcomputer.com/news/security/wana-decryptor-wanacrypt0r-technical-nose-dive/

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Ryan_Vickers said:

I assume so, since it seems to be in use 

I can't seem to find it anywhere. Only places I can think of are torrenting sites.

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, TAHIRMIA said:

I can't seem to find it anywhere. Only places I can think of are torrenting sites.

Probably on the deep web or something :P :ph34r:

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Master Disaster said:

Yeah but Donald Trump wasn't in charge of the USA when those other things happened. Both the USA & UK governments have shown their distain towards internet freedom in the past few years, this might just be the excuse they need to finally do something about it.

Little late to the party but we're also hosting another election here in the UK next month, no doubt some of the "policies" the parties will then try to introduce will be involving internet security and this incident.

PC - CPU Ryzen 5 1600 - GPU Power Color Radeon 5700XT- Motherboard Gigabyte GA-AB350 Gaming - RAM 16GB Corsair Vengeance RGB - Storage 525GB Crucial MX300 SSD + 120GB Kingston SSD   PSU Corsair CX750M - Cooling Stock - Case White NZXT S340

 

Peripherals - Mouse Logitech G502 Wireless - Keyboard Logitech G915 TKL  Headset Razer Kraken Pro V2's - Displays 2x Acer 24" GF246(1080p, 75hz, Freesync) Steering Wheel & Pedals Logitech G29 & Shifter

 

         

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Princess Cadence said:

So how far is this going? I just saw on the news that stuff like government systems have been compromised and all in my country, what world are we living xD

You are currently living in the 21st century, under the 3rd millennium. Year is 2017.

 

Future events

  • Quote

     

    • April 27, 2109 – A time capsule placed under the floor boards of the Old Queens Building at Rutgers University, in New Jersey, United States buried on April 27, 2009, is scheduled to be opened on April 27, 2109.[7]
    • 2968 – The Helium Centennial Time Columns Monument in Amarillo, Texas, contains four separate time capsules, the last of which is intended to be opened 1,000 years after the Time Columns Monument was locked in 1968.
    • October 27, 2088 – Mercury occults Jupiter, the first time since 1708, but very close to the Sun and impossible to view with the naked eye
    • The LongPlayer is set to restart on December 31, 2999, after it's been playing for non-stop without any repetition when it began playing on January 1st, 2000.
    • Riddle for Trials Evolutions, will finally be solved on August 1, 2113. 1 of the 5 keys found by the players using actual geographic coordinates, will unlock a box placed underneath the Eiffel Tower.
    • In 2252, the planetoid Orcus will have completed one orbit of the Sun since its discovery in 2004, based upon current orbital measurements which give it a period of 248 Earth years.
    • In 2288, the planetoid Quaoar will have completed one orbit of the Sun since its discovery in 2002, which, based upon current orbital measurements, gives it a period of 286 Earth years.
    • Sunday, August 28, 2287 – Closest approach between Mars and Earth since Wednesday, August 27, 2003.
    • FAT file systems theoretically support dates up to December 31, 2107 (though officially only up to December 31, 2099).
    • The Year type in MySQL supports dates up to December 31, 2155.
    • The One Hundred Year Study on Artificial Intelligence (AI100) initiated by Stanford University will be concluded in 2115.
    • 3183: The time pyramid, a public art work at Wemding, Germany, is scheduled for completion.
    • In the year 6939, the Westinghouse Time Capsules from the years 1939 and 1964 are scheduled to be opened after 5,000 years.
    • In the year 6970, the Expo'70 Time Capsule from the year 1970, buried under a monument near Osaka Castle, Japan, is scheduled to be opened after 5,000 years.
    • The Crypt of Civilization, a time capsule located at Oglethorpe University in Atlanta, Georgia, is scheduled to be unsealed on May 28, 8113.

     

     

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, GamingMemeKing said:

I wonder if this worldwide event will influence the value of the BTC (Bitcoin)...

 

It would be hilarious if the BTC crashed and went down to something like £1 = 1 Bitcoin.

Not sure if they have separate bitcoin blockchains that they are collecting on, but the three that are hardcoded into the Ransomware appear to have collected about 5.23 bitcoins worth of value...

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, GamingMemeKing said:

Someone earlier in the thread said they collected about 100 bitcoins already?

Yeah, I saw that as well... I'm basing my numbers off of the links to the bitcoin blockchains provided in the Bleeping Computers article on a breakdown of this ransomware:

 

https://www.bleepingcomputer.com/news/security/wana-decryptor-wanacrypt0r-technical-nose-dive/

Quote

There are three hard coded bitcoin addresses in the WanaCrypt0r ransomware. These bitcoin addresses are 13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94, 12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw, and 115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn. Maybe I am missing something, but what I do not understand is if so many people are utilizing the same bitcoin address, how will the ransomware developers be able to differentiate the victims that have paid from those who have not?

Not sure if there are other Bitcoin Blockchains that are being used to receive payments that are not hard coded into the ransomware...

Link to comment
Share on other sites

Link to post
Share on other sites

as a single user, what would be the likley hood of this happening to me?

A. Very High

B. high

C. medium

D. low

E. very low

?

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, KOMTechAndGaming said:

as a single user, what would be the likley hood of this happening to me?

A. Very High

B. high

C. medium

D. low

E. very low

?

If you've kept your Windows version up to date with update MS17-010 and windows defender, then very low to non-existent.   Otherwise, I would place it at medium.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, WMGroomAK said:

If you've kept your Windows version up to date with update MS17-010 and windows defender, then very low to non-existent.   Otherwise, I would place it at medium.

idk, i havent had any updates for a while....

but all the data on my pc can be redownloaded 

ive used this program to stop 'spying' http://www.majorgeeks.com/files/details/destroy_windows_10_spying.html 

im on version 1607,  build 14393.953

 

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
Share on other sites

Link to post
Share on other sites

This is just a tiny taste of what the world would be like if we had backdoors in all our systems.

I want to remind everyone that this could have been avoided if the NSA had shared their discoveries instead of hoarding them and used them for their own gains.

 

Please keep this in mind whenever you think it is acceptable to enforce backdoors into products. This is what happens when the backdoors inevitably gets found by someone with more malicious intentions.

Link to comment
Share on other sites

Link to post
Share on other sites

25 minutes ago, KOMTechAndGaming said:

idk, i havent had any updates for a while....

but all the data on my pc can be redownloaded 

ive used this program to stop 'spying' http://www.majorgeeks.com/files/details/destroy_windows_10_spying.html 

im on version 1607,  build 14393.953

 

You're patched, it was fixed in build 14393.693.

[Out-of-date] Want to learn how to make your own custom Windows 10 image?

 

Desktop: AMD R9 3900X | ASUS ROG Strix X570-F | Radeon RX 5700 XT | EVGA GTX 1080 SC | 32GB Trident Z Neo 3600MHz | 1TB 970 EVO | 256GB 840 EVO | 960GB Corsair Force LE | EVGA G2 850W | Phanteks P400S

Laptop: Intel M-5Y10c | Intel HD Graphics | 8GB RAM | 250GB Micron SSD | Asus UX305FA

Server 01: Intel Xeon D 1541 | ASRock Rack D1541D4I-2L2T | 32GB Hynix ECC DDR4 | 4x8TB Western Digital HDDs | 32TB Raw 16TB Usable

Server 02: Intel i7 7700K | Gigabye Z170N Gaming5 | 16GB Trident Z 3200MHz

Link to comment
Share on other sites

Link to post
Share on other sites

If I have this patche... I should be good, right?

 

http://www.catalog.update.microsoft.com/Search.aspx?q=KB4012212

Intel i7 3770k@4.7GHz delidded NZXT Kraken x62 Asus P8Z77-V PRO/Thunderbolt | G.Skill Ripjaws Z 16GB (2x8GB) 2400Mhz | EVGA GTX 1070 FTW

Phanteks Eclipse P400 Tempered Glass | EVGA SuperNOVA 750W P2 | 840 evo 256gb + HyperX 3k 480gb + 2 HDD (2TB) Asus Essence STX + Sennheiser HD580

AOC G2460PG 144Hz 24" + Asus VH236H 23" | Razer Blackwidow Tournament Edition Stealth | Logitech G703

Windows 10 Pro

 

Pixelbook 2017 (i5, 8GB, 128GB)

Link to comment
Share on other sites

Link to post
Share on other sites

so this only affects windows right? it doesnt spread onto bsd or linux based fileservers?

             ☼

ψ ︿_____︿_ψ_   

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, SCHISCHKA said:

so this only affects windows right? it doesnt spread onto bsd or linux based fileservers?

correct.  And it doesn't even affect any up to date Windows system

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

It does make you wonder if someone will take some of the NSA hacks for Linux etc and use them to distrubute hacks.. >.>

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×