Worldwide ransomware worm attack general - part 4

Worldwide ransomware worm attack general - part 4
>what is happening
some kid wrote a self-spreading ransomware and it got out of control
>who got hit?
russian government, english NHS, FedEX, and many more
>how to defend myself?
Run windows update. Exploit it uses to spread got patched ages ago
>I don't want windows updates
then at least close port 445 on your firewall
>any more details?
blog.malwarebytes.com/threat-analysis/2017/05/the-worm-that-spreads-wanacrypt0r/

Other urls found in this thread:

bbc.com/news/technology-39901382
technet.microsoft.com/en-us/library/security/ms17-010.aspx
gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168
www102.zippyshare.com/v/FGsn4AUy/file.html
support.microsoft.com/hr-hr/help/2696547/how-to-enable-and-disable-smbv1,-smbv2,-and-smbv3-in-windows-vista,-windows-server-2008,-windows-7,-windows-server-2008-r2,-windows-8,-and-windows-server-2012
twitter.com/SFWRedditImages

>yfw the Rothschild banks get infected

Rothschilds don't have bitcoin banks though

what would happen if comcast got this? would everyone using their internet service be vulnerable too? that would be crazy

SO IF I'M ON 7 BUT ALWAYS UPDATING LIKE A GOOD GOY I'M SAFE?
C'MON YOU FUCKS JUST GIVE ME A REPLY

>UPDATE UPDATE UPDATE

>"Unlike many other malicious programs, this one has the ability to move around a network by itself. Most others rely on humans to spread by tricking them into clicking on an attachment harbouring the attack code.

>By contrast, once WannaCry is inside an organisation it will hunt down vulnerable machines and infect them too. This perhaps explains why its impact is so public - because large numbers of machines at each victim organisation are being compromised."

bbc.com/news/technology-39901382

HOLY FUCKING SHIT.

General reminder that you need at least KB4012212 for windows 7 KB4012216 for windows 8.1 and KB4013429 for windows 10.
You can download the patches from Microsoft's servers by clicking on the OS you have in the table which will take you a download page for it.
technet.microsoft.com/en-us/library/security/ms17-010.aspx
It is also acceptable to install the later cumulative security updates which contain the older fixes.
If you don't want to update at all then you can disable SMB entirely (is enabled by default all windows versions).

WINFAGS BTFO

FUCK TECH ILLITERATE WINBABBIES

Russian h4ck3r here. I made the viruz.
Asks me anything.

>my ISP blocks all my ports because fuck you
>my ISP gets infected anyway
well thanks IT faggots

...

Alright windows update seems to be taking forever. I've disabled SMB1 and port 445. Am I safe?

Well fuck. What are the odds shit will be fine in 7 hours? I just turned my PC off

Just get Linux

yes, you gullible faggot, you are safe, good goy

delete your system32 folder

windows update services have been infected

But Americans made the virus?

Fucking Winniggers BTFO
Linux wins again

gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168

Someone still needs to run it manually in the network you fucktard.

what's your name?

Most press report only around $9000 on bitcoins paid so far. Isn't that stupidly low.
Surely whoever deploys this viruses expect far more.

I'm on the latest update, but I have multiple terabytes of stuff and no means to back them up at the moment. While I'm not infected I'd like to try and protect myself as much as possible.

>hurr install Linux
All my devices except my desktop run non dualbooted Linux Mint, because I need Ableton.

What do

>"Unlike many other malicious programs, this one has the ability to move around a network by itself

Isn't it normal for ransomware to do this? That's why you're not supposed to let the compromised computer touch the network.

How many money/BTC have you made so far?

Idi nahui suka blyat?!

[GO]

why aren't the function names mangled?

You will get caught within the next 24h, and you will spend the next trillion years in prison. Have fun

Americans works for russians.

disconnect from the internet you FUCKING RETARAAAAAAAAAAAAARD

So am I the only person who was keeping current with manual security only updates?

That seems pretty fucking basic.

disable samba v1, block port 445

That's not how any of this works.

stay on mint until this blows over user, and thank god you were smart enough to have mint as dual boot

This is why they have been full botnet with forcing updates in win 10 since your average user doesn't touch them and then gets infected with this shit which infects everyone else.

>some kid wrote

NY Times says that NSA tools got leaked to the skiddies.

dumbposter it's not something new
>getting netsec news from a normie newspaper

Ivan Ivanovitch Ivanov

STOP BING RETARDED FAGGOTS

EVERY HOME ROUTER IS BLOCKING EVERY PORT

SO ONLY IF YOU MANUALLY OPENED PORT 445 YOU CAN GET THIS SHIT

IF YOU DIDNT OPENE PORT 445 YOU DONT HACVE TO DO ANYTHING

only $2052 dollars actually

HOW SERIOUS IS THIS? IS SHIT ACTUALLY GOING DOWN SOMEONE TELL ME HOW BAD THIS IS SHOULD I BE WORRIED AND PREPARE FOR A SHIT STORM OR IS IT NOTHING TO REALLY WORRY ABOUT?

I can't see the ransom so would updating now prevent me from getting infected?
Or will updating now activate the ransomeware?

Can someone poz my computer with the virus?

I want its hot, sticky, infected bytes up my harddrive

He probably expected far less. He's probably pissing himself now that his worm infected government computers around the world. If he made even the slightest error in his own security, he's fucked.

www102.zippyshare.com/v/FGsn4AUy/file.html

:^)

because there's no mangling in C
and you can use a plugin to demangle names in ida

And some kid picked them up and created this shitstorms

So this is how Microsoft gets the world to use Windows 10?

>Unlike many other malicious programs, this one has the ability to move around a network by itself.

Basically a worm.

seriously? nice

Yes but many of them tried to do it but sucked at it. This one seems to work better in the wild.

Godadmn wikileaks, why did you leak the goddamn code

AND THEY TOLD ME I WAS CRAZY

AND THEY LAUGHED

WHO IS LAUGHING NOW, EH?

Vladimir

Trillions. We will use them to pay for world warz 3 and pizza

Yes

Prisons work for russians

>literally everyone here uses windows
I thought this was a technology board?

So do these companies allow SMB over the internet for their employees or what?

Well that's somewhat of a relief. So as long as ISP don't get infected themselves everything will be okay?

LMAO

Any other infected anons in here?
I work for a bank, after coming home got a call from my coworkers telling me all the machines started rebooting. Is that the fucking virus or is an unrelated thing?

Why do you think others would care? Stop being a fucking retard.

Maybe if the nsa didn't hoard exploits for themselves to use this shit wouldn't have happened

it is, this is just the Sup Forumsfags getting weeded out

>Meanwhile wallets for the digital cryptocurrency Bitcoin that were seemingly associated with the ransomware were reported to have started filling up with cash

i feel bad for whatever skid made this worm, they're going to be in for a world of pain WHEN (not if) they get found.

I'm reading a lot of posts saying that this malware made just 2K. Wouldn't it use thousands of bitcoin addresses though? How are you guys monitoring them all?

see pic. Wait until someone disclose nuclear industry is also affected and they cannot shutdown the reactor.

If you're a kid or some NEET, don't worry too much. If you work in an organization that uses Windows and your job actually matters (meaning you have important documents on the job's server) or you connect your own computer to your job's network, then you could possibly get your ass fucked

Enterprise don't have to update. Also it can brake things especially with updating to a shitty version of driver, so don't justify their shit.

What would you do if you were the scriptkiddie user who just wanted a few extra buttcoins from normie internet users to fund your anime figurine collecting hobby and wound up being the target of a multination manhunt after destroying critical and life-or-death infrastructure in the world's most powerful countries?

ISP routers come with all ports open to incoming. Given that everyone here uses wangblows, chances are they use whatever router their ISP gave them and never bothered to configure.

Companies get infected by idiots employees responding to spam and idiot admins not having port security, patch management, and letting users run on admin accounts.

They probably expected people to actually update their shit and maybe catch out a few people who didn't update over the past 2 months. Seems lots of people are ignoring security updates.

Woah, every user on Sup Forums is in here? Amazing.

The Linux users don't need to post; just laugh

linux spergs are a loud minority

>the person who let this get out of control will spend the rest of their life in prison when they just wanted to fuck over a handful of people
kek

Sup Forumsfags i'm scared...

but I torrent my animu from port 445!!

*laughs in russian*

Trillions of thousands

This fag that wrote this is probably hiding somewhere in the montains now

his shit fucked up hospitals in UK and people will probably die because of this, so im guessing the goverments are
already using military tier shit to find this faggot

how to disable smb1 on w7?

>blaming the malware
>not the government for using wangblows in the current year to handle critical patient information

So on a scale of 1 to 10 how fucked will the creator be?

My Retina MacBook doesn't have this problem.

>debian with preinstalled steam
why

It was patched in March though lol.

If your boss has you on an annual update schedule get a new job.

420 FAGGOT

Which bank subsidiaries are owned by the Rothschilds? Isn't Goldman Sachs one of them?

Skazhi pozhalusta comrade, why are you so mean to UK hospitals?

There's not just one address being used...

It doesn't, the retard that made this virus uses the same three addresses which makes it impossible to confirm payments.
It's a broken piece of script kiddie shit.

turn off wifi
unplug ethernet cable

>mfw winfags pretend they use windows because they have "actual jobs"
>mfw "actual jobs" are getting BTFO for using an insecure unprofessional piece of shit
>tech illiterates getting btfo left and right
feels good man

support.microsoft.com/hr-hr/help/2696547/how-to-enable-and-disable-smbv1,-smbv2,-and-smbv3-in-windows-vista,-windows-server-2008,-windows-7,-windows-server-2008-r2,-windows-8,-and-windows-server-2012

>get utterly fucked by GCHQ

it was probably GCHQ who wrote this worm

This really makes your almonds flare.

This is precisely why, although extremely annoying and intrusive, the new windows update system for W10 was not made like that because they are assholes.

Shit users ruin everything for everyone as usual.

Yes

>gnome
ew

Over the three addresses they've earned a bit more. Still fuck all for the shitstorm they've found themselves in.