Garacesh Posted May 16, 2017 Posted May 16, 2017 Kill switch for WeCry 3.0 ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com Seems to be a bit of a taunt with the 'lmao' in there. As mentioned, working theory that this is nation state ransomware created by the DPKR. I recognise 'ayy lmao' as one o' them internet maymay's and asdf is clearly padding, but I have no idea what 'tjhsst' is. Google tells me that it's the Thomas Jefferson High School for Science and Technology in Alexandria, Virginia. Tinfoil hat time!
Geoff Posted May 16, 2017 Posted May 16, 2017 More fuel for the conspiracy fire. The WinXP patches Microsoft created were built in February. https://www.theregister.co.uk/2017/05/16/microsoft_stockpiling_flaws_too/
mullet_man Posted May 16, 2017 Posted May 16, 2017 This might be useful for some. Configuration Manager and Custom Reports for Configuration Manager: WannaCry Patch Compliance Report Use SCCM to report compliance of patches for Wannacry. 1
DJ-1701 Posted May 16, 2017 Posted May 16, 2017 More fuel for the conspiracy fire. The WinXP patches Microsoft created were built in February. https://www.theregister.co.uk/2017/05/16/microsoft_stockpiling_flaws_too/ I assume these were created for anyone that still pays for extended support for XP, or 2003.
Garacesh Posted May 16, 2017 Posted May 16, 2017 More fuel for the conspiracy fire. The WinXP patches Microsoft created were built in February. https://www.theregister.co.uk/2017/05/16/microsoft_stockpiling_flaws_too/ I assume these were created for anyone that still pays for extended support for XP, or 2003. Well yeah, probably. If they fixed it for 7/8.1/10 back in March, it makes sense that they'd make a fix for XP since they're still supporting some XP users. 1
psydii Posted May 16, 2017 Posted May 16, 2017 If any of us had to cancel or postpone maintenance because of lessons or revision sessions, that is an example of management failure. Lessons and Revision sessions should be known in advance and planned around. A member of SLT (probably the business manager) should have control of teacher's access to resources, and be able to ring fence time for maintenance. This might not quite be when the Network Manager wanted, but scheduling access to resources is critical to managing them. Management failure. (I've had to cancel maintenance this year for exactly the above, before anyone thinks I live in an ivory tower. Improvements to management process are being implemented... we shall see what happens next time.) If an NHS Trust does not treat the scheduling of IT works with the same care and attention it gives other maintenance works, it is their fault that important things don't get done.
enbiggen Posted May 16, 2017 Posted May 16, 2017 Sorry if this has already been mentioned, but there seems to be an nmap script to test for this vulnerability now - which should indicated whether you've been successful in your patching? Use NMAP to Scan network for WCRY or WannaCry Ransomware vulnerability | CompuDay
psydii Posted May 16, 2017 Posted May 16, 2017 Well yeah, probably. If they fixed it for 7/8.1/10 back in March, it makes sense that they'd make a fix for XP since they're still supporting some XP users. MS have been begging people to get off SMBv1 for several years. They *know* it is wide open to attack. They probably don't want to look too hard because they'd end up having to back port to XP and put it on general release, as they did for this one. I wouldn't be surprised if some of those who pay for extended support include organisations who might have seen this exploited before the NSA tools were leaked, hence the February date on the XP hotfix, a month before the 7+ Security Updates. Also interesting that Vista's final (so far) update patched it.
GuyJD Posted May 16, 2017 Posted May 16, 2017 I read that it had effected less than 300,000 computers worldwide, that doesn't seem very many.
psydii Posted May 16, 2017 Posted May 16, 2017 Given that it seems that its primary method for spreading was SMBv1 it requires local LAN access, so spreading was limited to broadcast domains, and then to devices that moved between broadcast domains, the physical spread of humans and their VPNs. From what I have read in the mainstream tech media, no evidence of website/mail distribution has been seen. If they'd managed to get an initial delivery mechanism via the web that could dodge traditional AV it would probably have hit a greater number of users. It was only spreading for a few hours before the kill switch was activated. It could have been much worse.
Geoff Posted May 16, 2017 Posted May 16, 2017 Sorry if this has already been mentioned, but there seems to be an nmap script to test for this vulnerability now - which should indicated whether you've been successful in your patching? Use NMAP to Scan network for WCRY or WannaCry Ransomware vulnerability | CompuDay Can't get this to work.
ZeroHour Posted May 16, 2017 Posted May 16, 2017 Our article has been updated with the KB numbers for WSUS and a link to the SCCM compliance report tutorial. Thanks all.
Dos_Box Posted May 16, 2017 Posted May 16, 2017 (edited) MS have been begging people to get off SMBv1 for several years. They *know* it is wide open to attack. They probably don't want to look too hard because they'd end up having to back port to XP and put it on general release, as they did for this one. I wouldn't be surprised if some of those who pay for extended support include organisations who might have seen this exploited before the NSA tools were leaked, hence the February date on the XP hotfix, a month before the 7+ Security Updates. Also interesting that Vista's final (so far) update patched it. In mitigation, they know that it has issues however, there are still customers out there running legacy hardware/systems which may rely on it. Lets face it, there is more than one post on here where people are running legacy OS's to support expensive CNC and other machines in their schools. They have been warning customers for quite some time, but I suppose there is a division between having to run it and deciding wether to remove/disable it by the end users. And who here was still running it when they didn't have to even though they knew there were issues? It's been a lesson learnt by everyone this past few days. And it will happen again down the line with some other hole being found and exploited. Edited May 16, 2017 by Dos_Box
Garacesh Posted May 16, 2017 Posted May 16, 2017 (edited) From what I have read in the mainstream tech media, no evidence of website/mail distribution has been seen. So how did it begin, then? Do we have any solid indication of how 'patient zero' was initially infected? Lets face it, there is more than one post on here where people are running legacy OS's to support expensive CNC and other machines in their schools. Is true. Our laser cutter/engraver is powered by an XP laptop. But because we're unable to adequately secure it, it's airgapped. Edited May 16, 2017 by Garacesh
enbiggen Posted May 16, 2017 Posted May 16, 2017 Can't get this to work. Unfortunately I'm not an expert on nmap - it worked for me when scanning clients. (It didn't work for my servers, but I know they're all up-to-date - there was a message about not being able to access IPC or some such). Sorry.
Geoff Posted May 16, 2017 Posted May 16, 2017 Unfortunately I'm not an expert on nmap - it worked for me when scanning clients. (It didn't work for my servers, but I know they're all up-to-date - there was a message about not being able to access IPC or some such). Sorry. It appears to randomly barf on IPC$ unavailable, Guest account being disabled or SMB signing not being valid depending on the host involved.
cygnes Posted May 16, 2017 Posted May 16, 2017 seems that they removed it ??? https://steemit.com/shadowbrokers/@t...na-cry-edition
Garacesh Posted May 16, 2017 Posted May 16, 2017 (edited) seems that they removed it ??? https://steemit.com/shadowbrokers/@t...na-cry-edition Nah, your link is wrong. It's truncated. @t...na steemit.com/shadowbrokers/@theshadowbrokers/oh-lordy-comey-wanna-cry-edition Edited May 16, 2017 by Garacesh
FN-GM Posted May 16, 2017 Posted May 16, 2017 More fuel for the conspiracy fire. The WinXP patches Microsoft created were built in February. https://www.theregister.co.uk/2017/05/16/microsoft_stockpiling_flaws_too/ Well yeah, probably. If they fixed it for 7/8.1/10 back in March, it makes sense that they'd make a fix for XP since they're still supporting some XP users. Windows XP POS 2009 is still supported so might well have been.
ZeroHour Posted May 16, 2017 Posted May 16, 2017 Windows XP POS 2009 is still supported so might well have been. And you can still pay for support for XP at escalating rates each year I believe which according to the article the NHS stopped paying for after year 1 to save money.
Popular Post Stuajnht Posted May 16, 2017 Popular Post Posted May 16, 2017 There ought to be a website that scrapes the bitcoin values off these 3 pages, adds them up, scrapes the bitcoin dollars/pounds conversion rate. Displays the total value on a page and a graph of value over time. That's a website that could attract a significant amount of traffic. I'd make it myself but I don't have time at the moment. Free idea to anyone who wants to. Thought I'd take your idea and run with it... https://www.howmuchhasbeensent.com/ It's been thrown together very quickly, already needs to be rewritten as version 2, but it should at least provide an overall figure and current currency conversion (no graphs yet - they're difficult to do). Please play nice with it everyone. 9
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now