Jump to content

[3rd Update]WCry ransomwsre has possible links to Lazarus Group & PRNK

Master Disaster

Oh OK, didn't know this was possible.

 

Desktop: 7800x3d @ stock, 64gb ddr4 @ 6000, 3080Ti, x670 Asus Strix

 

Laptop: Dell G3 15 - i7-8750h @ stock, 16gb ddr4 @ 2666, 1050Ti 

Link to comment
Share on other sites

Link to post
Share on other sites

22 minutes ago, Raskolnikov said:

Oh OK, didn't know this was possible.

 

True or not, this is the exact kind of thing people point to when they say "macs (and linux) don't get viruses" (aside from the simple fact there are just less of them in total of course).  Any system can get infected if you intentionally download and install one, but these kind of exploits that just pwn you uncontrollably, that's where it comes down to system design quality

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

30 minutes ago, LAwLz said:

Hell, even Windows XP was patched.

Was it?  I heard they didn't...

30 minutes ago, LAwLz said:

It uses several different methods and for different parts of the malicious code, but it heavily relies on an exploit in SMBv1.

It's not a Trojan though. From what I can tell, simply being connected to someone on the same network, or being reachable with SMB over the Internet can get you infected. No user input necessary.

 

Quote from Talos:

Alright, thanks, that's pretty much what I thought was going on, but no one had clearly spelled it out until now :P 

30 minutes ago, LAwLz said:

I doubt it. The exploit is not in SMB by itself, but rather how SMBv1 is handled by Windows.

That's what I figured too

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Ryan_Vickers said:

-Snip-

How is Canadia holding up after this?  Any reports? 

 

Things are going crazy on local news, Telecommunication authority didn't register any incident, yet.

|EVGA 850 P2| |1440p PG279Q| |X570 Aorus Extreme| |Ryzen 9 3950x WC| |FE 2080Ti WC|TridentZ Neo 64GB| |Samsung 970 EVO M.2 1TB x3

 |Logitech G900|K70 Cherry MX Speed|  |Logitech Z906 |  |HD650|  |CaseLabs SMA8 (one of the last ones made)

 

Link to comment
Share on other sites

Link to post
Share on other sites

39 minutes ago, Raskolnikov said:

Oh OK, didn't know this was possible.

 

Yeah, its basically a very specific set of circumstances here...

 

A remote code execution exploit was leaked (it was zero day as ms had no prior knowledge of it), the hackers used the exploit to create a worm that basically sniffs every IP it has access to (locally or externally) looking for other vulnerable machines, when it finds another machine it zips itself up and sends itself to the other machine then uses the zero day to execute itself on the new machine infecting it, the new machine then also starts sniffing and the whole thing turns into a snowball, the more machines get infected the more become infected.

 

MS did patch the exploit in March but in the case of large corporations updates aren't generally pushed as frequently as in the consumer market, most businesses have internal infrastructure to handle updating OSes and it can be months or even years before updates get pushed. Also a large amount of infected machines were running XP which was never patched. MS have now issued patches for XP and Server 2K3 plus Win 8.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Foxxer said:

How is Canadia holding up after this?  Any reports? 

 

Things are going crazy on local news, Telecommunication authority didn't register any incident, yet.

I haven't heard anything bad happening here yet

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

I've just realised something, MS have patched XP, Server 2K3 and Win 8 but ignored Vista?

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Master Disaster said:

I've just realised something, MS have patched XP, Server 2K3 and Win 8 but ignored Vista?

What?  Where are you people getting this? :P  

I'm going based on this: https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

which seems to show (only) Vista and newer are patched

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, Master Disaster said:

I've just realised something, MS have patched XP, Server 2K3 and Win 8 but ignored Vista?

Vista was a bad OS anyway

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Ryan_Vickers said:

What?  Where are you people getting this? :P  

I'm going based on this: https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

which seems to show (only) Vista and newer are patched

https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

23 minutes ago, Master Disaster said:

A remote code execution exploit was leaked (it was zero day as ms had no prior knowledge of it)

It was not a zero day. Like you said, they had a patch for it out in March.

 

20 minutes ago, Master Disaster said:

I've just realised something, MS have patched XP, Server 2K3 and Win 8 but ignored Vista?

They patched Vista too.

 

9 minutes ago, Ryan_Vickers said:

What?  Where are you people getting this? :P  

I'm going based on this: https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

which seems to show (only) Vista and newer are patched

Here are download links for it.

As you can see, it's the same KB number as mentioned in the document you posted.

Link to comment
Share on other sites

Link to post
Share on other sites

10 minutes ago, TAHIRMIA said:

Vista was a bad OS anyway

Can you tell me why?

|EVGA 850 P2| |1440p PG279Q| |X570 Aorus Extreme| |Ryzen 9 3950x WC| |FE 2080Ti WC|TridentZ Neo 64GB| |Samsung 970 EVO M.2 1TB x3

 |Logitech G900|K70 Cherry MX Speed|  |Logitech Z906 |  |HD650|  |CaseLabs SMA8 (one of the last ones made)

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Master Disaster said:

Hm, so even though these are all dead, they made an exception and rolled out an update for XP, server 2003, and 8 (specifically 8, not 8.1, which anyone with 8 should have had long long ago)

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, LAwLz said:

It was not a zero day. Like you said, they had a patch for it out in March.

It was a zero day when it was leaked though, that's what I meant.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Ryan_Vickers said:

Hm, so even though these are all dead, they made an exception and rolled out an update for XP, server 2003, and 8 (specifically 8, not 8.1, which anyone with 8 should have had long long ago)

Pretty sure they had no real choice, they couldn't expect all the major corps that were hit to upgrade overnight, they either patched it back to XP or risked it all happening again when Wcry V2 is launched without the domain check kill switch.

 

In case you missed it you need to read this - https://www.malwaretech.com/2017/05/how-to-accidentally-stop-a-global-cyber-attacks.html

 

@LAwLz So they have patched Vista too, its just that none of the 20 people still using it have noticed and MS decided to not bother mentioning it.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

22 hours ago, Master Disaster said:

The attack is over, a British expert managed to kill the worm by accident

its not over it's still spreading from infected systems it just isn't delivering it's payload anymore. 

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, vorticalbox said:

its not over it's still spreading from infected systems it just isn't delivering it's payload anymore. 

Not to mention they could release a new one that can't be killed in the same way at any moment and I fully expect they will

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, vorticalbox said:

its not over it's still spreading from infected systems it just isn't delivering it's payload anymore. 

Fair point, I'll change the wording.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Ryan_Vickers said:

Not to mention they could release a new one that can't be killed in the same way at any moment and I fully expect they will

all they need to change is the url check to random pick letters as a url and any unpatched system will be hit but my guess is that they are laying low until it all blows over before coming back for round 2. 

                     ¸„»°'´¸„»°'´ Vorticalbox `'°«„¸`'°«„¸
`'°«„¸¸„»°'´¸„»°'´`'°«„¸Scientia Potentia est  ¸„»°'´`'°«„¸`'°«„¸¸„»°'´

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, vorticalbox said:

all they need to change is the url check to random pick letters as a url and any unpatched system will be hit but my guess is that they are laying low until it all blows over before coming back for round 2. 

imo they would be wise to do it as soon as possible.  With every day that passes, more and more systems will become protected from this

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Ryan_Vickers said:

imo they would be wise to do it as soon as possible.  With every day that passes, more and more systems will become protected from this

 

1 minute ago, vorticalbox said:

all they need to change is the url check to random pick letters as a url and any unpatched system will be hit but my guess is that they are laying low until it all blows over before coming back for round 2. 

 

I'll get to updating it:PxD

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, vorticalbox said:

all they need to change is the url check to random pick letters as a url and any unpatched system will be hit but my guess is that they are laying low until it all blows over before coming back for round 2. 

The expert said he expected some kind of algorithm built in that randomly changes the domain on a timer. That's a scary thought.

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

31 minutes ago, Foxxer said:

Can you tell me why?

Really slow

was not optimised properly,

RAM HDD usage of the OS was bad

Hello

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, Ryan_Vickers said:

imo they would be wise to do it as soon as possible.  With every day that passes, more and more systems will become protected from this

The problem they have now is round 1 was so effective, all the PCs hit by it will certainly be patched as part of the clean up operation. I'd be considering whether round 2 would be worth it at all.

 

I wonder how many people paid the ransom though?

Main Rig:-

Ryzen 7 3800X | Asus ROG Strix X570-F Gaming | 16GB Team Group Dark Pro 3600Mhz | Corsair MP600 1TB PCIe Gen 4 | Sapphire 5700 XT Pulse | Corsair H115i Platinum | WD Black 1TB | WD Green 4TB | EVGA SuperNOVA G3 650W | Asus TUF GT501 | Samsung C27HG70 1440p 144hz HDR FreeSync 2 | Ubuntu 20.04.2 LTS |

 

Server:-

Intel NUC running Server 2019 + Synology DSM218+ with 2 x 4TB Toshiba NAS Ready HDDs (RAID0)

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Master Disaster said:

The problem they have now is round 1 was so effective, all the PCs hit by it will certainly be patched as part of the clean up operation. I'd be considering whether round 2 would be worth it at all.

 

I wonder how many people paid the ransom though?

Honestly, can't be that many if they only got ~100 bitcoins and each bitcoin is ~3 ransoms

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


×