HomeSecurityWanaCrypt0r hit the world..

WanaCrypt0r hit worldwide..

WanaCrypt0r: Users and businesses should ensure their systems are up to date with the latest patches to prevent continued infection by the WannaCry ransomware.

Reports of two massive global ransomware attacks dominate the news. As workers in Europe head home for the weekend, the ransomware is shutting down their systems. What do we know so far.WanaCrypt0r

Big Targets
England's National Health Service (NHS) and Telefonica, one of the world's largest telecommunications providers, have issued reports stating that their systems have been targeted by a ransomware that Malwarebytes detects as Ransom.WanaCrypt0r. The ransomware has also been observed at companies in Spain, Russia, Ukraine and Taiwan.

Method
The ransomware spreads (after the user reaches in and opens an email or installs malware by mistake) using a known and patched vulnerability (MS17-010) that came from an NSA leak. Our research shows that the encryption is done with RSA-2048. This means that decryption will be impossible unless the coders have made a mistake that we have not found yet.

Below are snapshots of the pan-European system infections. The first from the University of Milan Bicocca. The second from a computer of the English health service and the third from a schedule announcement screen of the German railways.

WanaCrypt0r

WanaCrypt0r hit worldwide.. WanaCrypt0r hit worldwide..

As seen on the screens, the notification appears after the ransomware manages to encrypt what it can on the system. Then it demands money in the form of bitcoin to decrypt the documents.

INFRASTRUCTURE ANALYSIS

The files that are encrypted by this ransomware have the following formats.

WanaCrypt0r hit worldwide..

In short, they were encrypted from Word documents to songs and images, as well as programming projects.

Our advice is that our systems must always be up to date; at least once a week we should run Windows Update and scan our system. The best solution to avoid problems like these is timely foresight. When our files get encrypted, they become slow.

Cisco researchers observed for the first time requests for one of the WannaCry domains (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea [.] com) starting at 07:24 UTC, then hitting a peak a little over 1,400 almost 10 hours later.

WanaCrypt0r

The composition of the domain appears almost typed by a human, with most characters coming from the rows of a home keyboard.

Communication in this domain can be categorized as a kill switch domain due to its role in the overall execution of the malicious software:

WanaCrypt0r

The above subroutine attempts an HTTP GET to this domain and if it fails, it continues to perform the infection. However, if it succeeds, the subroutine exits. The domain is registered to a well-known sink, effectively causing this sample to terminate its malicious activity.

In short, the one who programmed the ransomware is as if he told the researchers, pay a few dollars, buy that specific domain so that the call is genuine and the ransomware will be disabled! Not even Dan Brown has thought of this yet…

Or it was also a foolish haste of the programmer, who placed a domain that does not exist so that the result would always be false and the ransomware would remain active. Logically, he didn't think anyone would go to the trouble of acquiring it?

Who knows?

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS