Yesterday we reported on the biggest ransomware attack, which, using one of the NSA exploits that were recently leaked by the Shadow Brokers group, the attackers were able to infect computers worldwide with WannaCry (a Windows exploit that originated from the NSA's EternalBlue tool). Microsoft has already released a patch for this vulnerability, but many users and organizations did not bother to update their systems.
The malware infects computers by exploiting a vulnerability in SMB file sharing. Older versions of Windows are most affected by it, especially since Microsoft no longer supports Windows XP or Windows (server) 2003.
It installs Doublepulsar, a backdoor that allows remote control of the infected machine. This is another stolen NSA tool that was leaked alongside Eternalblue. The malware is also controlled via the anonymous Tor network, to receive further commands from its creators.
However, as seen in the malicious software code there was also a kill switch in the form of a kill switch domain.
What does this mean in simple terms? When the malware detects that a specific domain exists, it stops infections. This domain was created (registered) earlier today by a researcherwho noticed the dot-com in the reverse-engineered binary. When the registration was detected by the malware, it immediately stopped the ransomware distribution, and its global spread.
The connections to the magical domain: iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com are being directed to a server in California and the administrators of the infected systems that reach the domain will be notified, reports the researcher.
“The IP addresses have been sent to the FBI and ShadowServer, so the organizations affected should receive a notification soon”, said the researcher, who admitted that he first registered the domain, and then realized it was a kill switch.
Below are some quick links to many more technical details we have gathered:
Cisco's Talos team analyzed the malware, describing its components.
A decrypted sample of the malware is available here.
An exploit for MS17-010 written in Python with example shellcode. It is based on the Eternalblue tool stolen from the NSA and developed by infosec RiskSense. It reveals that the SMB server error is the result of a buffer overflow in Microsoft's code.
You can track infections in real time here. There are at least 104,000 identified infected hosts worldwide.
