Ransom meme - Part 6

Kloss calls her top coders to shut it down edition

>what is happening
some kid wrote a self-spreading ransomware and it got out of control
>who got hit?
russian government, english NHS, FedEX, and many more
>how to defend myself?
Run windows update. Exploit it uses to spread got patched ages ago
>I don't want windows updates
then at least close port 445 on your firewall
>any more details?
blog.malwarebytes.com/threat-analysis/2017/05/the-worm-that-spreads-wanacrypt0r/

pin this shit mods

Other urls found in this thread:

intel.malwaretech.com/pewpew.html
vimeo.com/75534042
theguardian.com/technology/2017/may/13/accidental-hero-finds-kill-switch-to-stop-spread-of-ransomware-cyber-attack
gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168
twitter.com/NSFWRedditImage

IF YOU GET INFECTED YOU ARE A GENUINE RETARD LOL

Got more pics of her? This ass is worth dying for

FUCK RUSSIA AND FUCK RUSSIAN """"PEOPLE""""

intel.malwaretech.com/pewpew.html

YOU JUST SHOULD UPDATE!

How about stop linking to previous threads and keep up with the pace, newfag. Lurk moar.

post yfw this ransomware is gonna purge Sup Forums of phone shilling pajeets and graphic card Sup Forumsirgin threads

You can't get infected just by being connected to the internet. Anyone who tells you otherwise is a moron.

That is still underwear, what is the context of this?

How do I make a ransomware and get rich?

Fucking betamale.

vimeo.com/75534042

>board filled with newfags
>commies can't stop spamming "USE LE LINUX PLS PLS PLS"
good day

fucking chinks

no thanks bill

that pic is older than the internet bro

THIS A FALSE FLAG from MS to force win7 user to move to Botnet 10.

Degenerate 3D whore posters still remain so it's all in vain.

>how to defend myself?
install gentoo

>update windows
It's almost as if they hire a malware maker to spread fear so that people update into the newer harder-to-disable telemetry features they tear into every dll file in various places.

theguardian.com/technology/2017/may/13/accidental-hero-finds-kill-switch-to-stop-spread-of-ransomware-cyber-attack

Lol

you actually can, if you are an even bigger moron

Update or just INSTALL GENTOO!

How nice it affects Win10, including the Creators Update
The patch was released a week later

Are you going to blame trump and putin boogeyman next?

Sup Forums is not and never will be weebfaggot territory

moot is dead

You ask Russians to do that for you.

windows 10 is worse than any ransomeware

fact

I don't speak Russian.

Retard here, I installed the update in the bulletin for windows 7, should I still block port 445?

Also, is there a tard's guide to understanding this stuff? most of it is over my head but I'd like to know more

Fuck off, Daiz.

How the fuck do you even get this? Like where do you have to go on the Internet to get this shit?

The security patch that fixes this ransomware was rolled out in March tho
And it's almost impossible to stop your Win10 machine from updating
gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168

You don't have to.

...

I was say to UPDATE THE FUCKING WINDOWS 7.

Except Russian hacker were always the leading force in creation of malware aimed at general public.

No one knows yet tbqh

>moot is dead
moot didn't even like anime anymore in 2012
Doesn't mean it's not an anime site
>And it's almost impossible to stop your Win10 machine from updating
Windows Update shits itself as much as it does on Win7 and Win8 on Win10
Most of the affected machines are machines that couldn't update without a clean install

just to add to "not disabling those shits right away"
apparently there is another exploit that works in the same way over RDP (Remote Desktop)

What the fuck did you just try to say just now?

...nah

Why would a Russian who can code ransomware make it for someone else to make money off of instead of doing it himself?

>turn auto updates off before even windows 10 happened
>never update again in fear of force upgrade
>this shit happens
I have 2 fucking things accessing 445 now and I can't fucking stop it

tl;dr

Animu torrents and trap porn sites.
So 95% of Sup Forums is infected.

you could.... turn it off?

It's less dangerous, you still have to infect computers and that's a whole different thing and you can always sell or lend it.

Kill switch in malware if it can connect to a domain, random guy registered it making it live.

No new infections will happen if the code isn't changed.

welcome to the botnet

>Windows 7 SP1 no updates
>Did all the hardening involving EternalBlue back when the memebrokers nsa tools got released months ago
>We even had several threads about this
>Everything still safe and sound
>$300k starting

>grr microsoft I will NEVER UPDATE
>gets fucking hacked

Autists BTFO

i'm sure you have good recent backups of all your data

remove 5 lines and ship it back out

get fucked

How scared should the malware creators be now? Did they even expect it to get this big?

>No new infections will happen if the code isn't changed.
which has probably already happened

Implying most sensible people haven't gone offline after it hit the headlines

>placing a killswitch on fucking malware
Someone explain how a kill switch would help them in any way.

I should

When will this blow over? I'm only sticking to this site and Youtube for now.

>sensible
>using windows

>accidental
How the fuck is it accidental when the guy literally found the switch and deliberately registered the domain to activate it?

Tard from past threads trying to run linux here
>installed in a usb
>tried to boot from my notebook with 7
>runs fine
>try to boot on my xp desktop pc
>doesn't work
Fuck me. Guess it isn't compatible with my hardware?

He was trying to create a live map so he could see how many infections there were. It was accidental.

I guarantee you they are shitting themselves with how far this spread. Even if they're in a non-extradition country, it affected pretty much everywhere relevant, and all the countries that were infected have a lot of pull.

Essentially, the US could, and might, go full retard and declare them terrorists, and France, the UK, and Germany won't say shit. Russia probably wouldn't even complain.

He didn't know it was the kill switch. It was just a domain that was somehow involved.

I'm on night shift at a mental health ward in the UK. Systems are fine here.

I'm on break before anyone accuses me of negligence.

I would take a sledge hammer to my computer and flee the country, get plastic surgery, and work in a bakery for the rest of my life after abandoning all technology

As usual commies going against the trends of freedom and well being of the whole globe.

Easy way to stop if it gets out of hand, which it did
Growing like this it's pure success, unless you're too afraid of getting agencies looking for you
The guys behind this weren't prepared for success

I suspect the SMB bug cannot be thee whole story. You do not reach these remote places via SMB alone.

If I were them I wouldn't even touch the bitcoin generated by this.

it connects computer to computer, not through browser zero days.

Why is NSA hacking British hospitals?
Why is NSA hacking Russia? Is this because Russia stole Trump?
What is FedEx do with this?
Is USA world bad guys?
Please help me understand. Excuse the English.

your initramfs is personalized for your notebook
boot the failsafe option in the boot loader or remove "autodetect" HOOK from your /etc/initramfs.conf
and rebuild your initramfs image

>You do not reach these remote places via SMB alone.
Why?

Is disabling port 445 enough?

It doesn't "think" it just looks for vulnerabilities as it spreads around. It's like a zombie that happened to bite someone who was on their way to an international airport and before you know it the world is infected

Sticking only to certain sites will not help you if your network is compromised.

At the very least, you should make sure that your network is considered 'public' ie untrusted. But you're even better off closing port 445 and/or updating.

Yes. But you should update anyway, cuck.

hows the ward? shits boring to be in, i can't imagine working there is that much better

As I said, I'm a retard. What does that mean?

couldn't you if you A) weren't behind a router (i.e. plugged directly into modem) and B) had default windows functionality (i.e. SMB) turned on?

you'd still have to make yourself a target somehow for something to know you have 445 open

Those places are SAT connected.
No one runs SMB on a SAT line.

>I wasn't around for Techloli/g/y
Filthy dumb newfag scum

its an e-mail "invoice" virus which when installed will do SMB

sems to be mostly x-ray machines are fuXored? - according to the Graun - dunno why specifically those, but, I can see why inability to make one may be problematic for OPs etc. Maybe all less problematic in a nuthouse tho.

I already had port 445 closed before this started. Hopefully that's enough.

NSA isn't doing shit you fucking idiot, some kids just used some outdated NSA code that was leaked months ago.

>No one runs SMB on a SAT line.
In a perfect world yeah.

Being connected directly to the internet is exactly how you get infected and the worst thing you could possibly be doing.

kys weeb fuck

>apparently there is another exploit that works in the same way over RDP (Remote Desktop)

God damnit, I actually use RDP.

yes
"connected" and "connected directly" are very different things.

...

It's enough until the next one comes along.

>Russia probably wouldn't even complain
weren't they hit the worst?

your USB installation isn't a "generic" one, it was tailored for your laptop
by default, most distros places 2 options in it bootloader the default one and a failsafe one, for when these kind of problem happens
i can't help any further for lack of knowledge (i don't know which distro you are trying, and how it behaves by default)

but i gave you a few hints for what search for
>bootloader
>initramfs
>autodetect

sorry, how about BAKA BAKA KAWAII NOTICE ME SENPAI ^__________^

So NSA wrote the virus?
Is this a war act?